View a markdown version of this page

Actions, resources, and condition keys for AWS Elemental MediaPackage - Service Authorization Reference

Actions, resources, and condition keys for AWS Elemental MediaPackage

AWS Elemental MediaPackage (service prefix: mediapackage) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Elemental MediaPackage

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

ConfigureLogs

mediapackage:UpdateChannel

Write

CreateChannel

mediapackage:CreateChannel

Write

mediapackage:TagResource

Tagging, Write

CreateHarvestJob

mediapackage:CreateHarvestJob

Write

iam:PassRole

iam:PassedToService

mediapackage.amazonaws.com

Write

CreateOriginEndpoint

mediapackage:CreateOriginEndpoint

Write

mediapackage:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

mediapackage.amazonaws.com

Write

DeleteChannel

mediapackage:DeleteChannel

Write

DeleteOriginEndpoint

mediapackage:DeleteOriginEndpoint

Write

DescribeChannel

mediapackage:DescribeChannel

Read

DescribeHarvestJob

mediapackage:DescribeHarvestJob

Read

DescribeOriginEndpoint

mediapackage:DescribeOriginEndpoint

Read

ListChannels

mediapackage:ListChannels

Read

ListHarvestJobs

mediapackage:ListHarvestJobs

Read

ListOriginEndpoints

mediapackage:ListOriginEndpoints

Read

ListTagsForResource

mediapackage:ListTagsForResource

Read

RotateChannelCredentials

mediapackage:RotateChannelCredentials

Write

RotateIngestEndpointCredentials

mediapackage:RotateIngestEndpointCredentials

Write

TagResource

mediapackage:TagResource

Tagging, Write

UntagResource

mediapackage:UntagResource

Tagging, Write

UpdateChannel

mediapackage:UpdateChannel

Write

UpdateOriginEndpoint

mediapackage:UpdateOriginEndpoint

Write

iam:PassRole

iam:PassedToService

mediapackage.amazonaws.com

Write

Actions defined by AWS Elemental MediaPackage

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

ConfigureLogs

Grants permission to configure access logs for a Channel

channels*

aws:ResourceTag/${TagKey}

Write

CreateChannel

Grants permission to create a channel in AWS Elemental MediaPackage

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateHarvestJob

Grants permission to create a harvest job in AWS Elemental MediaPackage

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateOriginEndpoint