Skip to content

CI permissions

Jeff Farley edited this page Aug 6, 2021 · 1 revision

Based on an apply => destroy cycle

APIGateway
  CreateBasePathMapping
  CreateDeployment
  CreateDomainName
  CreateResource
  CreateRestApi
  CreateVpcLink
  DeleteBasePathMapping
  DeleteDeployment
  DeleteDomainName
  DeleteIntegration
  DeleteMethod
  DeleteResource
  DeleteRestApi
  DeleteStage
  DeleteVpcLink
  GetBasePathMapping
  GetDeployment
  GetDomainName
  GetIntegration
  GetMethod
  GetResource
  GetResources
  GetRestApi
  GetStage
  GetVpcLink
  PutIntegration
  PutMethod
  TagResource
  UpdateDomainName
  UpdateRestApi
  UpdateVpcLink
Certificate Manager
  DescribeCertificate
  ListCertificates
  ListTagsForCertificate
CloudWatch Logs
  CreateLogGroup
  DeleteLogGroup
  DescribeLogGroups
  ListTagsLogGroup
  PutRetentionPolicy
  TagLogGroup
CloudFront
  CreateDistributionWithTags
  CreateInvalidation
  DeleteDistribution
  GetDistribution
  ListTagsForResource
  TagResource
  UpdateDistribution
EC2
  AssociateRouteTable
  AttachInternetGateway
  AuthorizeSecurityGroupEgress
  AuthorizeSecurityGroupIngress
  CreateInternetGateway
  CreateRoute
  CreateRouteTable
  CreateSecurityGroup
  CreateSubnet
  CreateVpc
  CreateVpcEndpoint
  CreateVpcEndpointServiceConfiguration
  DeleteInternetGateway
  DeleteRouteTable
  DeleteSecurityGroup
  DeleteSubnet
  DeleteVpc
  DeleteVpcEndpoints
  DeleteVpcEndpointServiceConfigurations
  DescribeAccountAttributes
  DescribeInternetGateways
  DescribeNetworkAcls
  DescribeNetworkInterfaces
  DescribePrefixLists
  DescribeRouteTables
  DescribeSecurityGroups
  DescribeSubnets
  DescribeVpcAttribute
  DescribeVpcClassicLink
  DescribeVpcClassicLinkDnsSupport
  DescribeVpcEndpoints
  DescribeVpcEndpointServices
  DescribeVpcs
  DetachInternetGateway
  DisassociateRouteTable
  ModifyVpcAttribute
  ModifyVpcEndpointServicePermissions
  RevokeSecurityGroupEgress
  RevokeSecurityGroupIngress
ELB
  AddTags
  CreateLoadBalancer
  DeleteLoadBalancer
  DescribeLoadBalancerAttributes
  DescribeLoadBalancers
  DescribeTags
  ModifyLoadBalancerAttributes
ELB v2
  AddTags
  CreateListener
  CreateLoadBalancer
  CreateTargetGroup
  DeleteListener
  DeleteLoadBalancer
  DeleteTargetGroup
  DescribeListeners
  DescribeLoadBalancerAttributes
  DescribeLoadBalancers
  DescribeTags
  DescribeTargetGroupAttributes
  DescribeTargetGroups
  ModifyLoadBalancerAttributes
  ModifyTargetGroupAttributes
Elastic Container Registry
  BatchCheckLayerAvailability
  BatchGetImage
  CompleteLayerUpload
  CreateRepository
  DeleteRepository
  DeleteRepositoryPolicy
  DescribeImages
  DescribeRepositories
  GetAuthorizationToken
  GetRepositoryPolicy
  InitiateLayerUpload
  ListTagsForResource
  PutImage
  SetRepositoryPolicy
  TagResource
UploadLayerPart
Elastic Container Service
  CreateCluster
  CreateService
  DeleteCluster
  DeleteService
  DeregisterTaskDefinition
  DescribeClusters
  DescribeServices
  DescribeTaskDefinition
  RegisterTaskDefinition
  TagResource
  UpdateService
IAM
  CreateRole
  CreateServiceLinkedRole
  DeleteRole
  DeleteRolePolicy
  GetRole
  GetRolePolicy
  ListAttachedRolePolicies
  ListInstanceProfilesForRole
  ListRolePolicies
  PassRole
  PutRolePolicy
  TagRole
KMS
  CreateGrant
  Decrypt
  DescribeKey
  GenerateDataKey
Lambda
  AddPermission
  CreateFunction
  DeleteFunction
  GetFunction
  GetPolicy
  ListVersionsByFunction
  RemovePermission
  TagResource
  UpdateFunctionCode
RDS
  AddTagsToResource
  CreateDBInstance
  CreateDBSubnetGroup
  DeleteDBInstance
  DeleteDBSubnetGroup
  DescribeDBInstances
  DescribeDBSubnetGroups
  ListTagsForResource
Route 53
  AssociateVPCWithHostedZone
  ChangeResourceRecordSets
  GetChange
  GetHostedZone
  ListHostedZones
  ListResourceRecordSets
  ListTagsForResource
Secrets Manager
  CreateSecret
  DeleteSecret
  DescribeSecret
  GetResourcePolicy
  GetSecretValue
  PutSecretValue
S3
  CreateBucket
  DeleteBucket
  DeleteBucketPolicy
  GetAccelerateConfiguration
  GetBucketCORS
  GetBucketEncryption
  GetBucketLifecycle
  GetBucketLocation
  GetBucketLogging
  GetBucketObjectLockConfiguration
  GetBucketPolicy
  GetBucketReplication
  GetBucketRequestPayment
  GetBucketTagging
  GetBucketVersioning
  GetBucketWebsite
  GetEncryptionConfiguration
  GetLifecycleConfiguration
  GetReplicationConfiguration
  PutBucketPolicy
  PutBucketTagging
  PutBucketWebsite
STS
  GetCallerIdentity
Clone this wiki locally