View a markdown version of this page

Actions, resources, and condition keys for AWS Migration Hub - Service Authorization Reference

Actions, resources, and condition keys for AWS Migration Hub

AWS Migration Hub (service prefix: mgh) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Migration Hub

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation SDK client IAM action Condition key Possible value(s) Access level

AssociateCreatedArtifact

mgh

mgh:AssociateCreatedArtifact

Write

AssociateDiscoveredResource

mgh

mgh:AssociateDiscoveredResource

Write

AssociateSourceResource

mgh

mgh:AssociateSourceResource

Write

CreateProgressUpdateStream

mgh

mgh:CreateProgressUpdateStream

Write

DeleteProgressUpdateStream

mgh

mgh:DeleteProgressUpdateStream

Write

DescribeApplicationState

mgh

mgh:DescribeApplicationState

Read

DescribeMigrationTask

mgh

mgh:DescribeMigrationTask

Read

DisassociateCreatedArtifact

mgh

mgh:DisassociateCreatedArtifact

Write

DisassociateDiscoveredResource

mgh

mgh:DisassociateDiscoveredResource

Write

DisassociateSourceResource

mgh

mgh:DisassociateSourceResource

Write

ImportMigrationTask

mgh

mgh:ImportMigrationTask

Write

ListApplicationStates

mgh

mgh:ListApplicationStates

List

ListCreatedArtifacts

mgh

mgh:ListCreatedArtifacts

List

ListDiscoveredResources

mgh

mgh:ListDiscoveredResources

List

ListMigrationTaskUpdates

mgh

mgh:ListMigrationTaskUpdates

List

ListMigrationTasks

mgh

mgh:ListMigrationTasks

List

ListProgressUpdateStreams

mgh

mgh:ListProgressUpdateStreams

List

ListSourceResources

mgh

mgh:ListSourceResources

List

NotifyApplicationState

mgh

mgh:NotifyApplicationState

Write

NotifyMigrationTaskState

mgh

mgh:NotifyMigrationTaskState

Write

PutResourceAttributes

mgh

mgh:PutResourceAttributes

Write

CreateHomeRegionControl

migrationhub-config

mgh:CreateHomeRegionControl

Write

DeleteHomeRegionControl

migrationhub-config

mgh:DeleteHomeRegionControl

Write

DescribeHomeRegionControls

migrationhub-config

mgh:DescribeHomeRegionControls

List

GetHomeRegion

migrationhub-config

mgh:GetHomeRegion

Read

Actions defined by AWS Migration Hub

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AcceptConnection

Grants permission to accept a connection

ConnectionResource*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

mgh:ConnectionResourceConnectionArn

Write

AssociateAutomationUnitRole

Grants permission to associate an IAM role to an automation unit

AutomationUnitResource*

mgh:AutomationUnitResourceAutomationUnitArn

Write

AssociateCreatedArtifact

Grants permission to associate a given AWS artifact to a MigrationTask

migrationTask*

Write

AssociateDiscoveredResource

Grants permission to associate a given ADS resource to a MigrationTask

migrationTask*

Write

AssociateSourceResource

Grants permission to associate source resource

migrationTask*

Write

BatchAssociateIamRoleWithConnection

Grants permission to batch-associate IAM roles with a connection