Actions, resources, and condition keys for AWS Service Catalog
AWS Service Catalog (service prefix: servicecatalog) provides the following
service-specific operations, resources, actions, and condition keys for use in IAM permission
policies.
References:
-
Learn how to configure this service.
-
View a list of the API operations available for this service.
-
Learn how to secure this service and its resources by using IAM permission policies.
-
View the programmatic service authorization reference
for this service.
Topics
API operations defined by AWS Service Catalog
The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.
| Operation | SDK client | IAM action | Condition key | Possible value(s) | Access level |
|---|---|---|---|---|---|
|
AcceptPortfolioShare |
servicecatalog |
Write |
|||
|
AssociateBudgetWithResource |
servicecatalog |
Write |
|||
|
AssociatePrincipalWithPortfolio |
servicecatalog |
Write |
|||
|
AssociateProductWithPortfolio |
servicecatalog |
Write |
|||
|
AssociateServiceActionWithProvisioningArtifact |
servicecatalog |
servicecatalog:AssociateServiceActionWithProvisioningArtifact |
Write |
||
|
AssociateTagOptionWithResource |
servicecatalog |
Write |
|||
|
BatchAssociateServiceActionWithProvisioningArtifact |
servicecatalog |
servicecatalog:BatchAssociateServiceActionWithProvisioningArtifact |
Write |
||
|
BatchDisassociateServiceActionFromProvisioningArtifact |
servicecatalog |
servicecatalog:BatchDisassociateServiceActionFromProvisioningArtifact |
Write |
||
|
CopyProduct |
servicecatalog |
Write |
|||
|
CreateConstraint |
servicecatalog |
Write |
|||
iam:PassedToService |
servicecatalog.amazonaws.com |
Write |
|||
|
CreatePortfolio |
servicecatalog |
Write |
|||
Tagging, Write |
|||||
|
CreatePortfolioShare |
servicecatalog |
Permissions management, Write |
|||
|
CreateProduct |
servicecatalog |
Write |
|||
Tagging, Write |
|||||
Read |
|||||
|
CreateProvisionedProductPlan |
servicecatalog |
Write |
|||
|
CreateProvisioningArtifact |
servicecatalog |
Write |
|||
|
CreateServiceAction |
servicecatalog |
Write |
|||
iam:PassedToService |
servicecatalog.amazonaws.com |
Write |
|||
|
CreateTagOption |
servicecatalog |
Write |
|||
|
DeleteConstraint |
servicecatalog |
Write |
|||
|
DeletePortfolio |
servicecatalog |
Write |
|||
|
DeletePortfolioShare |
servicecatalog |
Permissions management, Write |
|||
|
DeleteProduct |
servicecatalog |
Write |
|||
|
DeleteProvisionedProductPlan |
servicecatalog |
Write |
|||
|
DeleteProvisioningArtifact |
servicecatalog |
Write |
|||
|
DeleteServiceAction |
servicecatalog |
Write |
|||
|
DeleteTagOption |
servicecatalog |
Write |
|||
|
DescribeConstraint |
servicecatalog |
Read |
|||
|
DescribeCopyProductStatus |
servicecatalog |
Read |
|||
|
DescribePortfolio |
servicecatalog |
Read |
|||
|
DescribePortfolioShareStatus |
servicecatalog |
Read |
|||
|
DescribePortfolioShares |
servicecatalog |
List |
|||
|
DescribeProduct |
servicecatalog |
Read |
|||
|
DescribeProductAsAdmin |
servicecatalog |
Read |
|||
|
DescribeProductView |
servicecatalog |
Read |
|||
|
DescribeProvisionedProduct |
servicecatalog |
Read |
|||
|
DescribeProvisionedProductPlan |
servicecatalog |
Read |
|||
|
DescribeProvisioningArtifact |
servicecatalog |
Read |
|||
|
DescribeProvisioningParameters |
servicecatalog |
Read |
|||
|
DescribeRecord |
servicecatalog |
Read |
|||
|
DescribeServiceAction |
servicecatalog |
Read |
|||
|
DescribeServiceActionExecutionParameters |
servicecatalog |
Read |
|||
|
DescribeTagOption |
servicecatalog |
Read |
|||
|
DisableAWSOrganizationsAccess |
servicecatalog |
Write |
|||
|
DisassociateBudgetFromResource |
servicecatalog |
Write |
|||
|
DisassociatePrincipalFromPortfolio |
servicecatalog |
Write |
|||
|
DisassociateProductFromPortfolio |
servicecatalog |
Write |
|||
|
DisassociateServiceActionFromProvisioningArtifact |
servicecatalog |
servicecatalog:DisassociateServiceActionFromProvisioningArtifact |
Write |
||
|
DisassociateTagOptionFromResource |
servicecatalog |
Write |
|||
|
EnableAWSOrganizationsAccess |
servicecatalog |
Write |
|||
|
ExecuteProvisionedProductPlan |
servicecatalog |
Write |
|||
|
ExecuteProvisionedProductServiceAction |
servicecatalog |
Write |
|||
|
GetAWSOrganizationsAccessStatus |
servicecatalog |
Read |
|||
|
GetProvisionedProductOutputs |
servicecatalog |
Read |
|||
|
ImportAsProvisionedProduct |
servicecatalog |
Write |
|||
|
ListAcceptedPortfolioShares |
servicecatalog |
List |
|||
|
ListBudgetsForResource |
servicecatalog |
List |
|||
|
ListConstraintsForPortfolio |
servicecatalog |
List |
|||
|
ListLaunchPaths |
servicecatalog |
List |
|||
|
ListOrganizationPortfolioAccess |
servicecatalog |
List |
|||
|
ListPortfolioAccess |
servicecatalog |
List |
|||
|
ListPortfolios |
servicecatalog |
List |
|||
|
ListPortfoliosForProduct |
servicecatalog |
List |
|||
|
ListPrincipalsForPortfolio |
servicecatalog |
List |
|||
|
ListProvisionedProductPlans |
servicecatalog |
List |
|||
|
ListProvisioningArtifacts |
servicecatalog |
List |
|||
|
ListProvisioningArtifactsForServiceAction |
servicecatalog |
List |
|||
|
ListRecordHistory |
servicecatalog |
List |
|||
|
ListResourcesForTagOption |
servicecatalog |
List |
|||
|
ListServiceActions |
servicecatalog |
List |
|||
|
ListServiceActionsForProvisioningArtifact |
servicecatalog |
List |
|||
|
ListStackInstancesForProvisionedProduct |
servicecatalog |
List |
|||
|
ListTagOptions |
servicecatalog |
List |
|||
|
NotifyProvisionProductEngineWorkflowResult |
servicecatalog |
Write |
|||
|
NotifyTerminateProvisionedProductEngineWorkflowResult |
servicecatalog |
servicecatalog:NotifyTerminateProvisionedProductEngineWorkflowResult |
Write |
||
|
NotifyUpdateProvisionedProductEngineWorkflowResult |
servicecatalog |
servicecatalog:NotifyUpdateProvisionedProductEngineWorkflowResult |
Write |
||
|
ProvisionProduct |
servicecatalog |
Write |
|||
|
RejectPortfolioShare |
servicecatalog |
Write |
|||
|
ScanProvisionedProducts |
servicecatalog |
List |
|||
|
SearchProducts |
servicecatalog |
List |
|||
|
SearchProductsAsAdmin |
servicecatalog |
List |
|||
|
SearchProvisionedProducts |
servicecatalog |
List |
|||
|
TerminateProvisionedProduct |
servicecatalog |
Write |
|||
|
UpdateConstraint |
servicecatalog |
Write |
|||
iam:PassedToService |
servicecatalog.amazonaws.com |
Write |
|||
|
UpdatePortfolio |
servicecatalog |
Tagging, Write |
|||
Tagging, Write |
|||||
Write |
|||||
|
UpdatePortfolioShare |
servicecatalog |
Permissions management, Write |
|||
|
UpdateProduct |
servicecatalog |
Tagging, Write |
|||
Tagging, Write |
|||||
Write |
|||||
Read |
|||||
|
UpdateProvisionedProduct |
servicecatalog |
Write |
|||
|
UpdateProvisionedProductProperties |
servicecatalog |
Write |
|||
|
UpdateProvisioningArtifact |
servicecatalog |
Write |
|||
|
UpdateServiceAction |
servicecatalog |
Write |
|||
iam:PassedToService |
servicecatalog.amazonaws.com |
Write |
|||
|
UpdateTagOption |
servicecatalog |
Write |
|||
|
AssociateAttributeGroup |
servicecatalog-appregistry |
Write |
|||
|
AssociateResource |
servicecatalog-appregistry |
Write |
|||
|
CreateApplication |
servicecatalog-appregistry |
Write |
|||
Tagging, Write |
|||||
|
CreateAttributeGroup |
servicecatalog-appregistry |
Write |
|||
Tagging, Write |
|||||
|
DeleteApplication |
servicecatalog-appregistry |
Write |
|||
|
DeleteAttributeGroup |
servicecatalog-appregistry |
Write |
|||
|
DisassociateAttributeGroup |
servicecatalog-appregistry |
Write |
|||
|
DisassociateResource |
servicecatalog-appregistry |
Write |
|||
|
GetApplication |
servicecatalog-appregistry |
Read |
|||
|
GetAssociatedResource |
servicecatalog-appregistry |
Read |
|||
|
GetAttributeGroup |
servicecatalog-appregistry |
Read |
|||
|
GetConfiguration |
servicecatalog-appregistry |
Read |
|||
|
ListApplications |
servicecatalog-appregistry |
List |
|||
|
ListAssociatedAttributeGroups |
servicecatalog-appregistry |
List |
|||
|
ListAssociatedResources |
servicecatalog-appregistry |
List |
|||
|
ListAttributeGroups |
servicecatalog-appregistry |
List |
|||
|
ListAttributeGroupsForApplication |
servicecatalog-appregistry |
List |
|||
|
ListTagsForResource |
servicecatalog-appregistry |
Read |
|||
|
PutConfiguration |
servicecatalog-appregistry |
Write |
|||
|
SyncResource |
servicecatalog-appregistry |
Write |
|||
|
TagResource |
servicecatalog-appregistry |
Tagging, Write |
|||
|
UntagResource |
servicecatalog-appregistry |
Tagging, Write |
|||
|
UpdateApplication |
servicecatalog-appregistry |
Write |
|||
|
UpdateAttributeGroup |
servicecatalog-appregistry |
Write |
Actions defined by AWS Service Catalog
You can specify the following actions in the Action element of an IAM
policy statement. Use policies to grant permissions to perform an operation in AWS. When
you use an action in a policy, you usually allow or deny access to the API operation or CLI
command with the same name. However, in some cases, a single action controls access to more
than one operation. Alternatively, some operations require several different actions.
| Actions | Description | Resource types (*required) | Condition keys | Access level |
|---|---|---|---|---|
Grants permission to accept a portfolio that has been shared with you |
Write |
|||
Grants permission to associate an attribute group with an application |
Write |
|||
Grants permission to associate a budget with a resource |
Write |
|||
Grants permission to associate an IAM principal with a portfolio, giving the specified principal access to any products associated with the specified portfolio |
Write |
|||
Grants permission to associate a product with a portfolio |
Write |
|||
Grants permission to associate a resource with an application |
Write |
|||
Grants permission to associate an action with a provisioning artifact |
Write |
|||
Grants permission to associate the specified TagOption with the specified portfolio or product |
Write |
|||
Grants permission to associate multiple self-service actions with provisioning artifacts |
Write |
|||
Grants permission to disassociate a batch of self-service actions from the specified provisioning artifact |
Write |
|||
Grants permission to copy the specified source product to the specified target product or a new product |
Write |
|||
Grants permission to create an application |
Write |
|||
Grants permission to create an attribute group |
Write |
|||
Grants permission to create a constraint on an associated product and portfolio |
Write |
|||
Grants permission to create a portfolio |
Write |
|||
Grants permission to share a portfolio you own with another AWS account |
Permissions management, Write |
|||
Grants permission to create a product and that product's first provisioning artifact |
Write |
|||
Grants permission to add a new provisioned product plan |
Write |
|||
Grants permission to add a new provisioning artifact to an existing product |
Write |
|||
Grants permission to create a self-service action |
Write |
|||
Grants permission to create a TagOption |
Write |
|||
Grants permission to delete an application if all associations have been removed from the application |
Write |
|||
Grants permission to delete an attribute group if all associations have been removed from the attribute group |
Write |
|||
Grants permission to remove and delete an existing constraint from an associated product and portfolio |
Write |
|||
Grants permission to delete a portfolio if all associations and shares have been removed from the portfolio |
Write |
|||
Grants permission to unshare a portfolio you own from an AWS account you previously shared the portfolio with |
Permissions management, Write |
|||
Grants permission to delete a product if all associations have been removed from the product |
Write |
|||
Grants permission to delete a provisioned product plan |
Write |
|||
Grants permission to delete a provisioning artifact from a product |
Write |
|||
Grants permission to delete a self-service action |
Write |
|||
Grants permission to delete the specified TagOption |
Write |
|||
Grants permission to describe a constraint |
Read |
|||
Grants permission to get the status of the specified copy product operation |
Read |
|||
Grants permission to describe a portfolio |
Read |
|||
Grants permission to get the status of the specified portfolio share operation |
Read |
|||
Grants permission to view a summary of each of the portfolio shares that were created for the specified portfolio |
List |
|||
Grants permission to describe a product as an end-user |
Read |
|||
Grants permission to describe a product as an admin |
Read |
|||
Grants permission to describe a product as an end-user |
Read |
|||
Grants permission to describe a provisioned product |
Read |
|||
Grants permission to describe a provisioned product plan |
Read |
|||
Grants permission to describe a provisioning artifact |
Read |
|||
Grants permission to describe the parameters that you need to specify to successfully provision a specified provisioning artifact |
Read |
|||
Grants permission to describe a record and lists any outputs |
Read |
|||
Grants permission to describe a self-service action |
Read |
|||
Grants permission to get the default parameters if you executed the specified Service Action on the specified Provisioned Product |
Read |
|||
Grants permission to get information about the specified TagOption |
Read |
|||
Grants permission to disable portfolio sharing through AWS Organizations feature |
Write |
|||
Grants permission to disassociate an attribute group from an application |
Write |
|||
Grants permission to disassociate a budget from a resource |
Write |
|||
Grants permission to disassociate an IAM principal from a portfolio |
Write |
|||
Grants permission to disassociate a product from a portfolio |
Write |
|||
Grants permission to disassociate a resource from an application |