View a markdown version of this page

Actions, resources, and condition keys for AWS Lake Formation - Service Authorization Reference

Actions, resources, and condition keys for AWS Lake Formation

AWS Lake Formation (service prefix: lakeformation) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Lake Formation

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

BatchGrantPermissions

lakeformation:BatchGrantPermissions

Permissions management, Write

BatchRevokePermissions

lakeformation:BatchRevokePermissions

Permissions management, Write

CreateDataCellsFilter

lakeformation:CreateDataCellsFilter

Write

CreateLFTagExpression

lakeformation:CreateLFTagExpression

Write

CreateLakeFormationIdentityCenterConfiguration

lakeformation:CreateLakeFormationIdentityCenterConfiguration

Write

CreateLakeFormationOptIn

lakeformation:CreateLakeFormationOptIn

Write

DeleteDataCellsFilter

lakeformation:DeleteDataCellsFilter

Write

DeleteLFTagExpression

lakeformation:DeleteLFTagExpression

Write

DeleteLakeFormationIdentityCenterConfiguration

lakeformation:DeleteLakeFormationIdentityCenterConfiguration

Write

DeleteLakeFormationOptIn

lakeformation:DeleteLakeFormationOptIn

Write

DescribeLakeFormationIdentityCenterConfiguration

lakeformation:DescribeLakeFormationIdentityCenterConfiguration

Read

GetDataCellsFilter

lakeformation:GetDataCellsFilter

Read

GetDataLakePrincipal

lakeformation:GetDataLakePrincipal

Read

GetDataLakeSettings

lakeformation:GetDataLakeSettings