View a markdown version of this page

Actions, resources, and condition keys for Amazon Route 53 - Service Authorization Reference

Actions, resources, and condition keys for Amazon Route 53

Amazon Route 53 (service prefix: route53) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by Amazon Route 53

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

ActivateKeySigningKey

route53:ActivateKeySigningKey

Write

AssociateVPCWithHostedZone

route53:AssociateVPCWithHostedZone

Write

ChangeCidrCollection

route53:ChangeCidrCollection

Write

ChangeResourceRecordSets

route53:ChangeResourceRecordSets

Write

ChangeTagsForResource

route53:ChangeTagsForResource

Tagging, Write

CreateCidrCollection

route53:CreateCidrCollection

Write

CreateHealthCheck

route53:CreateHealthCheck

Write

CreateHostedZone

route53:CreateHostedZone

Write

CreateKeySigningKey

route53:CreateKeySigningKey

Write

CreateQueryLoggingConfig

route53:CreateQueryLoggingConfig

Write

CreateReusableDelegationSet

route53:CreateReusableDelegationSet

Write

CreateTrafficPolicy

route53:CreateTrafficPolicy

Write

CreateTrafficPolicyInstance

route53:CreateTrafficPolicyInstance

Write

CreateTrafficPolicyVersion

route53:CreateTrafficPolicyVersion

Write

CreateVPCAssociationAuthorization

route53:CreateVPCAssociationAuthorization

Write

DeactivateKeySigningKey

route53:DeactivateKeySigningKey

Write

DeleteCidrCollection

route53:DeleteCidrCollection

Write

DeleteHealthCheck

route53:DeleteHealthCheck

Write

DeleteHostedZone

route53:DeleteHostedZone

Write

DeleteKeySigningKey

route53:DeleteKeySigningKey

Write

DeleteQueryLoggingConfig

route53:DeleteQueryLoggingConfig

Write

DeleteReusableDelegationSet

route53:DeleteReusableDelegationSet

Write

DeleteTrafficPolicy

route53:DeleteTrafficPolicy

Write

DeleteTrafficPolicyInstance

route53:DeleteTrafficPolicyInstance

Write

DeleteVPCAssociationAuthorization

route53:DeleteVPCAssociationAuthorization

Write

DisableHostedZoneDNSSEC

route53:DisableHostedZoneDNSSEC

Write

DisassociateVPCFromHostedZone

route53:DisassociateVPCFromHostedZone

Write

EnableHostedZoneDNSSEC

route53:EnableHostedZoneDNSSEC

Write

GetAccountLimit

route53:GetAccountLimit

Read

GetChange

route53:GetChange

List

GetCheckerIpRanges

route53:GetCheckerIpRanges

List

GetDNSSEC

route53:GetDNSSEC

Read

GetGeoLocation

route53:GetGeoLocation

List

GetHealthCheck

route53:GetHealthCheck

Read

GetHealthCheckCount

route53:GetHealthCheckCount

List

GetHealthCheckLastFailureReason

route53:GetHealthCheckLastFailureReason

List

GetHealthCheckStatus

route53:GetHealthCheckStatus

List

GetHostedZone

route53:GetHostedZone

List

GetHostedZoneCount

route53:GetHostedZoneCount

List

GetHostedZoneLimit

route53:GetHostedZoneLimit

Read

GetQueryLoggingConfig

route53:GetQueryLoggingConfig

Read

GetReusableDelegationSet

route53:GetReusableDelegationSet

List

GetReusableDelegationSetLimit

route53:GetReusableDelegationSetLimit

Read

GetTrafficPolicy

route53:GetTrafficPolicy

Read

GetTrafficPolicyInstance

route53:GetTrafficPolicyInstance

Read

GetTrafficPolicyInstanceCount

route53:GetTrafficPolicyInstanceCount

Read

ListCidrBlocks

route53:ListCidrBlocks

List

ListCidrCollections

route53:ListCidrCollections

List

ListCidrLocations

route53:ListCidrLocations

List

ListGeoLocations

route53:ListGeoLocations

Read

ListHealthChecks

route53:ListHealthChecks

Read

ListHostedZones

route53:ListHostedZones

List

ListHostedZonesByName

route53:ListHostedZonesByName

List

ListHostedZonesByVPC

route53:ListHostedZonesByVPC

List

ListQueryLoggingConfigs

route53:ListQueryLoggingConfigs

List

ListResourceRecordSets

route53:ListResourceRecordSets

List

ListReusableDelegationSets

route53:ListReusableDelegationSets

Read

ListTagsForResource

route53:ListTagsForResource

Read

ListTagsForResources

route53:ListTagsForResources

Read

ListTrafficPolicies

route53:ListTrafficPolicies

List

ListTrafficPolicyInstances

route53:ListTrafficPolicyInstances

Read

ListTrafficPolicyInstancesByHostedZone

route53:ListTrafficPolicyInstancesByHostedZone

List

ListTrafficPolicyInstancesByPolicy

route53:ListTrafficPolicyInstancesByPolicy

List

ListTrafficPolicyVersions

route53:ListTrafficPolicyVersions

List

ListVPCAssociationAuthorizations

route53:ListVPCAssociationAuthorizations

List

TestDNSAnswer

route53:TestDNSAnswer

Read

UpdateHealthCheck

route53:UpdateHealthCheck

Write

UpdateHostedZoneComment

route53:UpdateHostedZoneComment

Write

UpdateHostedZoneFeatures

route53:UpdateHostedZoneFeatures

Write

UpdateTrafficPolicyComment

route53:UpdateTrafficPolicyComment

Write

UpdateTrafficPolicyInstance

route53:UpdateTrafficPolicyInstance

Write

Actions defined by Amazon Route 53

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

ActivateKeySigningKey

Grants permission to activate a key-signing key so that it can be used for signing by DNSSEC

hostedzone*

Write

AssociateVPCWithHostedZone

Grants permission to associate an additional Amazon VPC with a private hosted zone

hostedzone

route53:VPCs

Write

ChangeCidrCollection

Grants permission to create or delete CIDR blocks within a CIDR collection

cidrcollection*

Write

ChangeResourceRecordSets

Grants permission to create, update, or delete a record, which contains authoritative DNS information for a specified domain or subdomain name

hostedzone*

route53:ChangeResourceRecordSetsActions

route53:ChangeResourceRecordSetsNormalizedRecordNames

route53:ChangeResourceRecordSetsRecordTypes

Write

ChangeTagsForResource

Grants permission to add, edit, or delete tags for a health check or a hosted zone

healthcheck*

Tagging, Write