View a markdown version of this page

Actions, resources, and condition keys for AWS Fault Injection Service - Service Authorization Reference

Actions, resources, and condition keys for AWS Fault Injection Service

AWS Fault Injection Service (service prefix: fis) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Fault Injection Service

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

CreateExperimentTemplate

fis:CreateExperimentTemplate

Write

fis:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

fis.amazonaws.com

Write

CreateTargetAccountConfiguration

fis:CreateTargetAccountConfiguration

Write

DeleteExperimentTemplate

fis:DeleteExperimentTemplate

Write

DeleteTargetAccountConfiguration

fis:DeleteTargetAccountConfiguration

Write

GetAction

fis:GetAction

Read

GetExperiment

fis:GetExperiment

Read

GetExperimentTargetAccountConfiguration

fis:GetExperimentTargetAccountConfiguration

Read

GetExperimentTemplate

fis:GetExperimentTemplate

Read

GetSafetyLever

fis:GetSafetyLever

Read

GetTargetAccountConfiguration

fis:GetTargetAccountConfiguration

Read

GetTargetResourceType

fis:GetTargetResourceType

Read

ListActions

fis:ListActions

List

ListExperimentResolvedTargets

fis:ListExperimentResolvedTargets

List

ListExperimentTargetAccountConfigurations

fis:ListExperimentTargetAccountConfigurations

List

ListExperimentTemplates

fis:ListExperimentTemplates

List

ListExperiments

fis:ListExperiments

List

ListTagsForResource

fis:ListTagsForResource

Read

ListTargetAccountConfigurations

fis:ListTargetAccountConfigurations

List

ListTargetResourceTypes

fis:ListTargetResourceTypes

List

StartExperiment

fis:StartExperiment

Write

fis:TagResource

Tagging, Write

StopExperiment

fis:StopExperiment

Write

TagResource

fis:TagResource

Tagging, Write

UntagResource

fis:UntagResource

Tagging, Write

UpdateExperimentTemplate

fis:UpdateExperimentTemplate

Write

iam:PassRole

iam:PassedToService

fis.amazonaws.com

Write

UpdateSafetyLeverState

fis:UpdateSafetyLeverState

Write

UpdateTargetAccountConfiguration

fis:UpdateTargetAccountConfiguration

Write

Actions defined by AWS Fault Injection Service

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

CreateExperimentTemplate

Grants permission to create an AWS FIS experiment template

action*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

experiment-template*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

CreateTargetAccountConfiguration

Grants permission to create an AWS FIS target account configuration

experiment-template*

aws:ResourceTag/${TagKey}

Write

DeleteExperimentTemplate

Grants permission to delete the AWS FIS experiment template

experiment-template*

aws:ResourceTag/${TagKey}

Write

DeleteTargetAccountConfiguration

Grants permission to delete an AWS FIS target account configuration

experiment-template*

aws:ResourceTag/${TagKey}

Write

GetAction

Grants permission to retrieve an AWS FIS action

action*

aws:ResourceTag/${TagKey}

Read

GetExperiment

Grants permission to retrieve an AWS FIS experiment

experiment*

aws:ResourceTag/${TagKey}

Read

GetExperimentTargetAccountConfiguration

Grants permission to retrieve an AWS FIS target account configuration for an AWS FIS experiment

experiment*

aws:ResourceTag/${TagKey}

Read

GetExperimentTemplate

Grants permission to retrieve an AWS FIS Experiment Template

experiment-template*

aws:ResourceTag/${TagKey}

Read

GetSafetyLever

Grants permission to get information about the safety lever

safety-lever*

Read

GetTargetAccountConfiguration

Grants permission to retrieve an AWS FIS target account configuration for an AWS FIS experiment template

experiment-template*

aws:ResourceTag/${TagKey}

Read

GetTargetResourceType

Grants permission to get information about the specified resource type

Read

ListActions

Grants permission to list all available AWS FIS actions

List

ListExperimentResolvedTargets

Grants permission to list resolved targets for AWS FIS experiments

experiment*

aws:ResourceTag/${TagKey}

List

ListExperimentTargetAccountConfigurations

Grants permission to list target account configurations for AWS FIS experiments

experiment*

aws:ResourceTag/${TagKey}

List

ListExperimentTemplates

Grants permission to list all available AWS FIS experiment templates

List

ListExperiments

Grants permission to list all available AWS FIS experiments

List

ListTagsForResource

Grants permission to list the tags for an AWS FIS resource

action

aws:ResourceTag/${TagKey}

Read

experiment

aws:ResourceTag/${TagKey}

experiment-template

aws:ResourceTag/${TagKey}

ListTargetAccountConfigurations

Grants permission to list target account configurations for AWS FIS experiment templates

experiment-template*

aws:ResourceTag/${TagKey}

List

ListTargetResourceTypes

Grants permission to list the resource types

List

StartExperiment

Grants permission to run an AWS FIS experiment

experiment*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

experiment-template*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

StopExperiment

Grants permission to stop an AWS FIS experiment

experiment*