Movatterモバイル変換


[0]ホーム

URL:


Actions, resources, and condition keys for Amazon EC2 - Identity and Access Management
DocumentationIdentity and Access ManagementService Authorization Reference
ActionsResource typesCondition keys

Actions, resources, and condition keys for Amazon EC2

Amazon EC2 (service prefix:ec2) provides the following service-specific resources, actions, and condition context keys for use in IAM permission policies.

References:

Actions defined by Amazon EC2

You can specify the following actions in theAction element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

TheAccess level column of the Actions table describes how the action is classified (List, Read, Permissions management, or Tagging). This classification can help you understand the level of access that an action grants when you use it in a policy. For more information about access levels, seeAccess levels in policy summaries.

TheResource types column of the Actions table indicates whether each action supports resource-level permissions. If there is no value for this column, you must specify all resources ("*") to which the policy applies in theResource element of your policy statement. If the column includes a resource type, then you can specify an ARN of that type in a statement with that action. If the action has one or more required resources, the caller must have permission to use the action with those resources. Required resources are indicated in the table with an asterisk (*). If you limit resource access with theResource element in an IAM policy, you must include an ARN or pattern for each required resource type. Some actions support multiple resource types. If the resource type is optional (not indicated as required), then you can choose to use one of the optional resource types.

TheCondition keys column of the Actions table includes keys that you can specify in a policy statement'sCondition element. For more information on the condition keys that are associated with resources for the service, see theCondition keys column of the Resource types table.

TheDependent actions column of the Actions table shows additional permissions that may be required to successfully call an action. These permissions may be needed in addition to the permission for the action itself. When an action specifies dependent actions, those dependencies may apply to additional resources defined for that action, not only the first resource listed in the table.

Resource condition keys are listed in theResource types table. You can find a link to the resource type that applies to an action in theResource types (*required) column of the Actions table. The resource type in the Resource types table includes theCondition keys column, which are the resource condition keys that apply to an action in the Actions table.

For details about the columns in the following table, seeActions table.

ActionsDescriptionAccess levelResource types (*required)Condition keysDependent actions
AcceptAddressTransferGrants permission to accept an Elastic IP address transferWrite

elastic-ip*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:CreateTags

ec2:Region

AcceptCapacityReservationBillingOwnershipGrants permission to accept assign billing of the available capacity of a shared Capacity Reservation to the calling accountWrite

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

AcceptReservedInstancesExchangeQuoteGrants permission to accept a Convertible Reserved Instance exchange quoteWrite

reserved-instances*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:InstanceType

ec2:ReservedInstancesOfferingType

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:Region

AcceptTransitGatewayMulticastDomainAssociationsGrants permission to accept a request to associate subnets with a transit gateway multicast domainWrite

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

AcceptTransitGatewayPeeringAttachmentGrants permission to accept a transit gateway peering attachment requestWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

AcceptTransitGatewayVpcAttachmentGrants permission to accept a request to attach a VPC to a transit gatewayWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

AcceptVpcEndpointConnectionsGrants permission to accept one or more interface VPC endpoint connections to your VPC endpoint serviceWrite

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceSupportedRegion

ec2:Region

AcceptVpcPeeringConnectionGrants permission to accept a VPC peering connection requestWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpc-peering-connection*

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

ec2:Region

AdvertiseByoipCidrGrants permission to advertise an IP address range that is provisioned for use in AWS through bring your own IP addresses (BYOIP)Write

ec2:Region

AllocateAddressGrants permission to allocate an Elastic IP address (EIP) to your accountWrite

elastic-ip*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AllocateHostsGrants permission to allocate a Dedicated Host to your accountWrite

dedicated-host*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AutoPlacement

ec2:AvailabilityZone

ec2:HostRecovery

ec2:InstanceType

ec2:Quantity

ec2:CreateTags

ec2:Region

AllocateIpamPoolCidrGrants permission to allocate a CIDR from an Amazon VPC IP Address Manager (IPAM) poolWrite

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ApplySecurityGroupsToClientVpnTargetNetworkGrants permission to apply a security group to the association between a Client VPN endpoint and a target networkWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AssignIpv6AddressesGrants permission to assign one or more IPv6 addresses to a network interfaceWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

AssignPrivateIpAddressesGrants permission to assign one or more secondary private IP addresses to a network interfaceWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

AssignPrivateNatGatewayAddressGrants permission to assign one or more secondary private IP addresses to a private NAT gatewayWrite

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateAddressGrants permission to associate an Elastic IP address (EIP) with an instance or a network interfaceWrite

elastic-ip

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

AssociateCapacityReservationBillingOwnerGrants permission to assign billing of the unused capacity of a shared Capacity Reservation to a consumer accountWrite

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

AssociateClientVpnTargetNetworkGrants permission to associate a target network with a Client VPN endpointWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Region

AssociateDhcpOptionsGrants permission to associate or disassociate a set of DHCP options with a VPCWrite

dhcp-options*

aws:ResourceTag/${TagKey}

ec2:DhcpOptionsID

ec2:ResourceTag/${TagKey}

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AssociateEnclaveCertificateIamRoleGrants permission to associate an ACM certificate with an IAM role to be used in an EC2 EnclaveWrite

certificate*

role*

ec2:Region

AssociateIamInstanceProfileGrants permission to associate an IAM instance profile with a running or stopped instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

iam:PassRole

ec2:Region

AssociateInstanceEventWindowGrants permission to associate one or more targets with an event windowWrite

instance-event-window*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateIpamByoasnGrants permission to associate an Autonomous System Number (ASN) with a BYOIP CIDRWrite

ec2:Region

AssociateIpamResourceDiscoveryGrants permission to associate an IPAM resource discovery with an Amazon VPC IPAMWrite

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-resource-discovery-association*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

AssociateNatGatewayAddressGrants permission to associate an Elastic IP address and private IP address with a public Nat gatewayWrite

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateRouteServerGrants permission to associate a route server with a VPCWrite

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc*

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AssociateRouteTableGrants permission to associate a subnet or gateway with a route tableWrite

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

internet-gateway

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateSecurityGroupVpcGrants permission to associate a security group with another VPC in the same RegionWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc*

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AssociateSubnetCidrBlockGrants permission to associate a CIDR block with a subnetWrite

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateTransitGatewayMulticastDomainGrants permission to associate an attachment and list of subnets with a transit gateway multicast domainWrite

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

AssociateTransitGatewayPolicyTableGrants permission to associate a policy table with a transit gateway attachmentWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

AssociateTransitGatewayRouteTableGrants permission to associate an attachment with a transit gateway route tableWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

AssociateTrunkInterfaceGrants permission to associate a branch network interface with a trunk network interfaceWrite

ec2:Region

AssociateVerifiedAccessInstanceWebAcl [permission only]Grants permission to associate an AWS Web Application Firewall (WAF) web access control list (ACL) with a Verified Access instanceWrite

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateVpcCidrBlockGrants permission to associate a CIDR block with a VPCWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AttachClassicLinkVpcGrants permission to link an EC2-Classic instance to a ClassicLink-enabled VPC through one or more of the VPC's security groupsWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AttachInternetGatewayGrants permission to attach an internet gateway to a VPCWrite

internet-gateway*

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AttachNetworkInterfaceGrants permission to attach a network interface to an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

AttachVerifiedAccessTrustProviderGrants permission to attach a trust provider to a Verified Access instanceWrite

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-trust-provider*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AttachVolumeGrants permission to attach an EBS volume to a running or stopped instance and expose it to the instance with the specified device nameWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

AttachVpnGatewayGrants permission to attach a virtual private gateway to a VPCWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AuthorizeClientVpnIngressGrants permission to add an inbound authorization rule to a Client VPN endpointWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

AuthorizeSecurityGroupEgressGrants permission to add one or more outbound rules to a VPC security group. Policies using the security-group-rule resource-level permission are only enforced when the API request includes TagSpecificationsWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:CreateTags

security-group-rule

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

AuthorizeSecurityGroupIngressGrants permission to add one or more inbound rules to a VPC security group. Policies using the security-group-rule resource-level permission are only enforced when the API request includes TagSpecificationsWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:CreateTags

security-group-rule

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

BundleInstanceGrants permission to bundle an instance store-backed Windows instanceWrite

ec2:Region

CancelBundleTaskGrants permission to cancel a bundling operationWrite

ec2:Region

CancelCapacityReservationGrants permission to cancel a Capacity Reservation and release the reserved capacityWrite

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:CapacityReservationFleet

ec2:Region

CancelCapacityReservationFleetsGrants permission to cancel one or more Capacity Reservation FleetsWrite

capacity-reservation-fleet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CancelCapacityReservation

ec2:Region

CancelConversionTaskGrants permission to cancel an active conversion taskWrite

ec2:Region

CancelDeclarativePoliciesReportGrants permission to cancel a declarative policies reportWrite

declarative-policies-report*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CancelExportTaskGrants permission to cancel an active export taskWrite

export-image-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

export-instance-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CancelImageLaunchPermissionGrants permission to remove your AWS account from the launch permissions for the specified AMIPermissions management

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

CancelImportTaskGrants permission to cancel an in-process import virtual machine or import snapshot taskWrite

import-image-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

import-snapshot-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CancelReservedInstancesListingGrants permission to cancel a Reserved Instance listing on the Reserved Instance MarketplaceWrite

ec2:Region

CancelSpotFleetRequestsGrants permission to cancel one or more Spot Fleet requestsWrite

spot-fleet-request*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CancelSpotInstanceRequestsGrants permission to cancel one or more Spot Instance requestsWrite

spot-instances-request*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ConfirmProductInstanceGrants permission to determine whether an owned product code is associated with an instanceWrite

ec2:Region

CopyFpgaImageGrants permission to copy a source Amazon FPGA image (AFI) to the current Region. Resource-level permissions specified for this action apply to the new AFI only. They do not apply to the source AFIWrite

fpga-image*

ec2:Owner

ec2:Region

CopyImageGrants permission to copy an Amazon Machine Image (AMI) from a source Region to the current RegionWrite

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:Owner

ec2:CreateTags

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CopySnapshotGrants permission to copy a point-in-time snapshot of an EBS volume and store it in Amazon S3. Resource-level permissions specified for this action apply to both the snapshot copy and the source snapshotWrite

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Encrypted

ec2:OutpostArn

ec2:Owner

ec2:ParentSnapshot

ec2:ParentVolume

ec2:ProductCode

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:CreateTags

ec2:Region

CopyVolumesGrants permission to create a copy of an EBS volume. Resource-level permissions specified for this action apply to the source and copied volume. Condition keys for the copied volume correspond to parameters specified in the CopyVolumes API requestWrite

volume*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ParentVolume

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:CreateTags

ec2:Region

CreateCapacityManagerDataExportGrants permission to create a new S3 Data Export for Capacity ManagerWrite

capacity-manager-data-export*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateCapacityReservationGrants permission to create a Capacity ReservationWrite

capacity-reservation*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CapacityReservationFleet

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:EphemeralStorage

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:Tenancy

ec2:CreateTags

ec2:Region

CreateCapacityReservationBySplittingGrants permission to create a new Capacity Reservation by splitting the available capacity of the source Capacity ReservationWrite

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:CreateTags

ec2:Region

CreateCapacityReservationFleetGrants permission to create a Capacity Reservation FleetWrite

capacity-reservation-fleet*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateCapacityReservation

ec2:CreateTags

ec2:DescribeCapacityReservations

ec2:DescribeInstances

ec2:Region

CreateCarrierGatewayGrants permission to create a carrier gateway and provides CSP connectivity to VPC customersWrite

carrier-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateClientVpnEndpointGrants permission to create a Client VPN endpointWrite

client-vpn-endpoint*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:CreateTags

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpcID

ec2:Region

CreateClientVpnRouteGrants permission to add a network route to a Client VPN endpoint's route tableWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Region

CreateCoipCidrGrants permission to create a range of customer-owned IP (CoIP) addressesWrite

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateCoipPoolGrants permission to create a pool of customer-owned IP (CoIP) addressesWrite

coip-pool*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateCoipPoolPermission [permission only]Grants permission to allow a service to access a customer-owned IP (CoIP) poolPermissions management

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateCustomerGatewayGrants permission to create a customer gateway, which provides information to AWS about your customer gateway deviceWrite

customer-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateDefaultSubnetGrants permission to create a default subnet in a specified Availability Zone in a default VPCWrite

ec2:Region

CreateDefaultVpcGrants permission to create a default VPC with a default subnet in each Availability ZoneWrite

ec2:Region

CreateDelegateMacVolumeOwnershipTaskGrants permission to create a volume ownership delegation task for an Apple silicon Mac instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:CreateTags

mac-modification-task*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateDhcpOptionsGrants permission to create a set of DHCP options for a VPCWrite

dhcp-options*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:DhcpOptionsID

ec2:CreateTags

ec2:Region

CreateEgressOnlyInternetGatewayGrants permission to create an egress-only internet gateway for a VPCWrite

egress-only-internet-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateFleetGrants permission to launch an EC2 Fleet. Resource-level permissions for this action do not include the resources specified in a launch template. To specify resource-level permissions for resources specified in a launch template, you must include the resources in the RunInstances action statementWrite

fleet*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

instance*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceProfile

ec2:InstanceType

ec2:PlacementGroup

ec2:RootDeviceType

ec2:Tenancy

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

launch-template

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

volume

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:KmsKeyId

ec2:ParentSnapshot

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

CreateFlowLogsGrants permission to create one or more flow logs to capture IP traffic for a network interfaceWrite

vpc-flow-log*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ecs:ListClusters

ecs:ListContainerInstances

ecs:ListServices

ecs:ListTaskDefinitions

ecs:ListTasks

iam:PassRole

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

transit-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateFpgaImageGrants permission to create an Amazon FPGA Image (AFI) from a design checkpoint (DCP)Write

fpga-image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Owner

ec2:Public

ec2:CreateTags

ec2:Region

CreateImageGrants permission to create an Amazon EBS-backed AMI from a stopped or running Amazon EBS-backed instance. This action can reboot instances as part of the image creation process, even without RebootInstances permissions. To prevent instance reboots during image creation, use the NoReboot parameterWrite

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:Owner

ec2:CreateTags

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:OutpostArn

ec2:ParentVolume

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

ec2:Region

CreateImageUsageReportGrants permission to create an AMI usage reportWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:CreateTags

image-usage-report*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateInstanceConnectEndpointGrants permission to create an EC2 Instance Connect Endpoint that allows you to connect to an instance without a public IPv4 addressWrite

instance-connect-endpoint*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:SubnetID

ec2:CreateTags

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

CreateInstanceEventWindowGrants permission to create an event window in which scheduled events for the associated Amazon EC2 instances can runWrite

instance-event-window*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateInstanceExportTaskGrants permission to export a running or stopped instance to an Amazon S3 bucketWrite

export-instance-task*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

CreateInternetGatewayGrants permission to create an internet gateway for a VPCWrite

internet-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:InternetGatewayID

ec2:CreateTags

ec2:Region

CreateIpamGrants permission to create an Amazon VPC IP Address Manager (IPAM)Write

ipam*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

iam:CreateServiceLinkedRole

ec2:Region

CreateIpamExternalResourceVerificationTokenGrants permission to create a verification token, which proves ownership of an external resourceWrite

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

ipam-external-resource-verification-token*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateIpamPoolGrants permission to create an IP address pool for Amazon VPC IP Address Manager (IPAM), which is a collection of contiguous IP address CIDRsWrite

ipam-pool*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateIpamResourceDiscoveryGrants permission to create an IPAM resource discoveryWrite

ipam-resource-discovery*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

iam:CreateServiceLinkedRole

ec2:Region

CreateIpamScopeGrants permission to create an Amazon VPC IP Address Manager (IPAM) scope, which is the highest-level container within IPAMWrite

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

ipam-scope*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateKeyPairGrants permission to create a 2048-bit RSA key pairWrite

key-pair*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:KeyPairType

ec2:CreateTags

ec2:Region

CreateLaunchTemplateGrants permission to create a launch templateWrite

launch-template*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ssm:GetParameters

ec2:Region

CreateLaunchTemplateVersionGrants permission to create a new version of a launch templateWrite

launch-template*

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ssm:GetParameters

ec2:Region

CreateLocalGatewayRouteGrants permission to create a static route for a local gateway route tableWrite

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateLocalGatewayRouteTableGrants permission to create a local gateway route tableWrite

local-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

local-gateway-route-table*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateLocalGatewayRouteTablePermission [permission only]Grants permission to allow a service to access a local gateway route tablePermissions management

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociationGrants permission to create a local gateway route table virtual interface group associationWrite

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

local-gateway-route-table-virtual-interface-group-association*

aws:RequestTag/${TagKey}

aws:TagKeys

local-gateway-virtual-interface-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateLocalGatewayRouteTableVpcAssociationGrants permission to associate a VPC with a local gateway route tableWrite

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

local-gateway-route-table-vpc-association*

aws:RequestTag/${TagKey}

aws:TagKeys

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateLocalGatewayVirtualInterfaceGrants permission to create a local gateway virtual interfaceWrite

local-gateway-virtual-interface*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

local-gateway-virtual-interface-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

outpost-lag*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateLocalGatewayVirtualInterfaceGroupGrants permission to create a local gateway virtual interface groupWrite

local-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

local-gateway-virtual-interface-group*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateMacSystemIntegrityProtectionModificationTaskGrants permission to create a System Integrity Protection (SIP) modification task for an Amazon EC2 Mac instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:CreateTags

mac-modification-task*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateManagedPrefixListGrants permission to create a managed prefix listWrite

prefix-list*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateNatGatewayGrants permission to create a NAT gateway in a subnetWrite

natgateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

elastic-ip

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

CreateNetworkAclGrants permission to create a network ACL in a VPCWrite

network-acl*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:NetworkAclID

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateNetworkAclEntryGrants permission to create a numbered entry (a rule) in a network ACLWrite

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

ec2:Region

CreateNetworkInsightsAccessScopeGrants permission to create a Network Access ScopeWrite

network-insights-access-scope*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateNetworkInsightsPathGrants permission to create a path to analyze for reachabilityWrite

network-insights-path*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

internet-gateway

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-peering-connection

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateNetworkInterfaceGrants permission to create a network interface in a subnetWrite

network-interface*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:NetworkInterfaceID

ec2:CreateTags

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

CreateNetworkInterfacePermissionGrants permission to create a permission for an AWS-authorized user to perform certain operations on a network interfacePermissions management

network-interface*

aws:ResourceTag/${TagKey}

ec2:AuthorizedService

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

CreatePlacementGroupGrants permission to create a placement groupWrite

placement-group*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:CreateTags

ec2:Region

CreatePublicIpv4PoolGrants permission to create a public IPv4 address pool for public IPv4 CIDRs that you own and bring to Amazon to manage with Amazon VPC IP Address Manager (IPAM)Write

ipv4pool-ec2*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateReplaceRootVolumeTaskGrants permission to create a root volume replacement taskWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:CreateTags

replace-root-volume-task*

aws:RequestTag/${TagKey}

aws:TagKeys

volume*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:VolumeID

ec2:VolumeInitializationRate

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

snapshot

aws:ResourceTag/${TagKey}

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

CreateReservedInstancesListingGrants permission to create a listing for Standard Reserved Instances to be sold in the Reserved Instance MarketplaceWrite

ec2:Region

CreateRestoreImageTaskGrants permission to start a task that restores an AMI from an S3 object previously created by using CreateStoreImageTaskWrite

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:Owner

ec2:CreateTags

ec2:Region

CreateRouteGrants permission to create a route in a VPC route tableWrite

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

CreateRouteServerGrants permission to create a route serverWrite

route-server*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

sns:CreateTopic

ec2:Region

CreateRouteServerEndpointGrants permission to create a route server endpointWrite

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:AuthorizeSecurityGroupIngress

ec2:CreateNetworkInterface

ec2:CreateNetworkInterfacePermission

ec2:CreateSecurityGroup

ec2:CreateTags

ec2:DescribeSecurityGroups

route-server-endpoint*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

CreateRouteServerPeerGrants permission to create a route server peerWrite

route-server-endpoint*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:AuthorizeSecurityGroupIngress

ec2:CreateTags

route-server-peer*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:Region

CreateRouteTableGrants permission to create a route table for a VPCWrite

route-table*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:RouteTableID

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateSecurityGroupGrants permission to create a security groupWrite

security-group*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:SecurityGroupID

ec2:CreateTags

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateSnapshotGrants permission to create a snapshot of an EBS volume and store it in Amazon S3Write

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Location

ec2:OutpostArn

ec2:ParentVolume

ec2:SnapshotID

ec2:SourceAvailabilityZone

ec2:SourceOutpostArn

ec2:VolumeSize

ec2:CreateTags

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

CreateSnapshotsGrants permission to create crash-consistent snapshots of multiple EBS volumes and store them in Amazon S3Write

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceProfile

ec2:InstanceType

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:CreateTags

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Location

ec2:OutpostArn

ec2:ParentVolume

ec2:SnapshotID

ec2:SourceAvailabilityZone

ec2:SourceOutpostArn

ec2:VolumeSize

volume*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

CreateSpotDatafeedSubscriptionGrants permission to create a data feed for Spot Instances to view Spot Instance usage logsWrite

ec2:Region

CreateStoreImageTaskGrants permission to store an AMI as a single object in an S3 bucketWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

CreateSubnetGrants permission to create a subnet in a VPCWrite

subnet*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:SubnetID

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateSubnetCidrReservationGrants permission to create a subnet CIDR reservationWrite

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:CreateTags

ec2:Region

CreateTagsGrants permission to add or overwrite one or more tags for Amazon EC2 resourcesTagging

capacity-block

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

capacity-manager-data-export

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

capacity-reservation

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

capacity-reservation-fleet

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

carrier-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:Vpc

client-vpn-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

coip-pool

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

customer-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

declarative-policies-report

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

dedicated-host

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AutoPlacement

ec2:AvailabilityZone

ec2:HostRecovery

ec2:InstanceType

ec2:Quantity

ec2:ResourceTag/${TagKey}

dhcp-options

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:DhcpOptionsID

ec2:ResourceTag/${TagKey}

egress-only-internet-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

elastic-gpu

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ElasticGpuType

ec2:ResourceTag/${TagKey}

elastic-ip

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

export-image-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

export-instance-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

fleet

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

fpga-image

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

host-reservation

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

image

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

image-usage-report

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

import-image-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

import-snapshot-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

instance

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

instance-connect-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:SubnetID

instance-event-window

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

internet-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

ipam

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-external-resource-verification-token

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-pool

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-resource-discovery

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-resource-discovery-association

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-scope

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

key-pair

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:KeyPairName

ec2:KeyPairType

ec2:ResourceTag/${TagKey}

launch-template

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

local-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-route-table

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-route-table-virtual-interface-group-association

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-route-table-vpc-association

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-group

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

natgateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-acl

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

network-insights-access-scope

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-insights-access-scope-analysis

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-insights-analysis

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-insights-path

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-interface

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

placement-group

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

prefix-list

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

replace-root-volume-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

reserved-instances

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:InstanceType

ec2:ReservedInstancesOfferingType

ec2:ResourceTag/${TagKey}

ec2:Tenancy

route-server

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

route-server-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

route-server-peer

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

route-table

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

security-group

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

security-group-rule

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

snapshot

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

spot-fleet-request

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

spot-instances-request

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

subnet

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

subnet-cidr-reservation

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

traffic-mirror-filter

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

traffic-mirror-filter-rule

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

traffic-mirror-session

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

traffic-mirror-target

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

transit-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-attachment

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-connect-peer

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:transitGatewayConnectPeerId

transit-gateway-multicast-domain

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

transit-gateway-policy-table

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

transit-gateway-route-table

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-route-table-announcement

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

verified-access-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-endpoint-target

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-group

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-instance

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-policy

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-trust-provider

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

volume

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

vpc

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpc-block-public-access-exclusion

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-endpoint-connection

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceServiceRegion

ec2:VpceSupportedRegion

vpc-endpoint-service-permission

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-flow-log

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-peering-connection

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

vpn-connection

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:ResourceTag/${TagKey}

ec2:RoutingType

vpn-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ec2:CreateAction

ec2:Region

CreateTrafficMirrorFilterGrants permission to create a traffic mirror filterWrite

traffic-mirror-filter*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateTrafficMirrorFilterRuleGrants permission to create a traffic mirror filter ruleWrite

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

traffic-mirror-filter-rule*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateTrafficMirrorSessionGrants permission to create a traffic mirror sessionWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:CreateTags

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-session*

aws:RequestTag/${TagKey}

aws:TagKeys

traffic-mirror-target*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateTrafficMirrorTargetGrants permission to create a traffic mirror targetWrite

traffic-mirror-target*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

network-interface

aws:ResourceTag/${TagKey}

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceServiceName

ec2:VpceServiceOwner

ec2:Region

CreateTransitGatewayGrants permission to create a transit gatewayWrite

transit-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayId

ec2:CreateTags

ec2:Region

CreateTransitGatewayConnectGrants permission to create a Connect attachment from a specified transit gateway attachmentWrite

transit-gateway-attachment*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayAttachmentId

ec2:CreateTags

ec2:Region

CreateTransitGatewayConnectPeerGrants permission to create a Connect peer between a transit gateway and an applianceWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:CreateTags

transit-gateway-connect-peer*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayConnectPeerId

ec2:Region

CreateTransitGatewayMulticastDomainGrants permission to create a multicast domain for a transit gatewayWrite

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:CreateTags

transit-gateway-multicast-domain*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayMulticastDomainId

ec2:Region

CreateTransitGatewayPeeringAttachmentGrants permission to request a transit gateway peering attachment between a requester and accepter transit gatewayWrite

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:CreateTags

transit-gateway-attachment*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayAttachmentId

ec2:Region

CreateTransitGatewayPolicyTableGrants permission to create a transit gateway policy tableWrite

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:CreateTags

transit-gateway-policy-table*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayPolicyTableId

ec2:Region

CreateTransitGatewayPrefixListReferenceGrants permission to create a transit gateway prefix list referenceWrite

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

CreateTransitGatewayRouteGrants permission to create a static route for a transit gateway route tableWrite

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

CreateTransitGatewayRouteTableGrants permission to create a route table for a transit gatewayWrite

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:CreateTags

transit-gateway-route-table*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayRouteTableId

ec2:Region

CreateTransitGatewayRouteTableAnnouncementGrants permission to create an announcement for a transit gateway route tableWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:CreateTags

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-route-table-announcement*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayRouteTableAnnouncementId

ec2:Region

CreateTransitGatewayVpcAttachmentGrants permission to attach a VPC to a transit gatewayWrite

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:CreateTags

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-attachment*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayAttachmentId

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateVerifiedAccessEndpointGrants permission to create a Verified Access endpointWrite

verified-access-endpoint*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

CreateVerifiedAccessGroupGrants permission to create a Verified Access groupWrite

verified-access-group*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateVerifiedAccessInstanceGrants permission to create a Verified Access instanceWrite

verified-access-instance*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateVerifiedAccessTrustProviderGrants permission to create a verified trust providerWrite

verified-access-trust-provider*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateVolumeGrants permission to create an EBS volumeWrite

volume*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:KmsKeyId

ec2:ParentSnapshot

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:CreateTags

snapshot

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

CreateVpcGrants permission to create a VPC with a specified CIDR blockWrite

vpc*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:VpcID

ec2:CreateTags

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateVpcBlockPublicAccessExclusionGrants permission to create an exclusion list for blocked public access on a VPCWrite

vpc-block-public-access-exclusion*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

vpc

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateVpcEndpointGrants permission to create a VPC endpoint for an AWS serviceWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpcID

ec2:CreateTags

ec2:DescribeSecurityGroups

ec2:DescribeSubnets

ec2:DescribeVpcs

route53:AssociateVPCWithHostedZone

vpc-endpoint*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:VpceMultiRegion

ec2:VpceServiceName

ec2:VpceServiceOwner

ec2:VpceServiceRegion

route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

subnet

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Region

CreateVpcEndpointConnectionNotificationGrants permission to create a connection notification for a VPC endpoint or VPC endpoint serviceWrite

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceServiceRegion

ec2:Region

CreateVpcEndpointServiceConfigurationGrants permission to create a VPC endpoint service configuration to which service consumers (AWS accounts, IAM users, and IAM roles) can connectWrite

vpc-endpoint-service*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:VpceMultiRegion

ec2:VpceServicePrivateDnsName

ec2:VpceServiceRegion

ec2:CreateTags

ec2:Region

CreateVpcPeeringConnectionGrants permission to request a VPC peering connection between two VPCsWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:CreateTags

vpc-peering-connection*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AccepterVpc

ec2:RequesterVpc

ec2:VpcPeeringConnectionID

ec2:Region

CreateVpnConnectionGrants permission to create a VPN connection between a virtual private gateway or transit gateway and a customer gatewayWrite

customer-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

vpn-connection*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:RoutingType

transit-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateVpnConnectionRouteGrants permission to create a static route for a VPN connection between a virtual private gateway and a customer gatewayWrite

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateVpnGatewayGrants permission to create a virtual private gatewayWrite

vpn-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

DeleteCapacityManagerDataExportGrants permission to delete an existing Capacity Manager data export configurationWrite

capacity-manager-data-export*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteCarrierGatewayGrants permission to delete a carrier gatewayWrite

carrier-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteClientVpnEndpointGrants permission to delete a Client VPN endpointWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DeleteClientVpnRouteGrants permission to delete a route from a Client VPN endpointWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

DeleteCoipCidrGrants permission to delete a range of customer-owned IP (CoIP) addressesWrite

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteCoipPoolGrants permission to delete a pool of customer-owned IP (CoIP) addressesWrite

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteCoipPoolPermission [permission only]Grants permission to deny a service from accessing a customer-owned IP (CoIP) poolPermissions management

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteCustomerGatewayGrants permission to delete a customer gatewayWrite

customer-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteDhcpOptionsGrants permission to delete a set of DHCP optionsWrite

dhcp-options*

aws:ResourceTag/${TagKey}

ec2:DhcpOptionsID

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteEgressOnlyInternetGatewayGrants permission to delete an egress-only internet gatewayWrite

egress-only-internet-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteFleetsGrants permission to delete one or more EC2 FleetsWrite

fleet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteFlowLogsGrants permission to delete one or more flow logsWrite

vpc-flow-log*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteFpgaImageGrants permission to delete an Amazon FPGA Image (AFI)Write

fpga-image*

aws:ResourceTag/${TagKey}

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteImageUsageReportGrants permission to delete an AMI usage reportWrite

image-usage-report*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteInstanceConnectEndpointGrants permission to delete an EC2 Instance Connect EndpointWrite

instance-connect-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Region

DeleteInstanceEventWindowGrants permission to delete the specified event windowWrite

instance-event-window*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteInternetGatewayGrants permission to delete an internet gatewayWrite

internet-gateway*

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpamGrants permission to delete an Amazon VPC IP Address Manager (IPAM) and remove all monitored data associated with the IPAM including the historical data for CIDRsWrite

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpamExternalResourceVerificationTokenGrants permission to delete a verification token, which proves ownership of an external resourceWrite

ipam-external-resource-verification-token*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpamPoolGrants permission to delete an Amazon VPC IP Address Manager (IPAM) poolWrite

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpamResourceDiscoveryGrants permission to delete an IPAM resource discoveryWrite

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpamScopeGrants permission to delete the scope for an Amazon VPC IP Address Manager (IPAM)Write

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteKeyPairGrants permission to delete a key pair by removing the public key from Amazon EC2Write

key-pair

aws:ResourceTag/${TagKey}

ec2:KeyPairName

ec2:KeyPairType

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLaunchTemplateGrants permission to delete a launch template and its associated versionsWrite

launch-template*

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLaunchTemplateVersionsGrants permission to delete one or more versions of a launch templateWrite

launch-template*

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRouteGrants permission to delete a route from a local gateway route tableWrite

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRouteTableGrants permission to delete a local gateway route tableWrite

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRouteTablePermission [permission only]Grants permission to deny a service from accessing a local gateway route tablePermissions management

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociationGrants permission to delete a local gateway route table virtual interface group associationWrite

local-gateway-route-table-virtual-interface-group-association*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRouteTableVpcAssociationGrants permission to delete an association between a VPC and local gateway route tableWrite

local-gateway-route-table-vpc-association*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayVirtualInterfaceGrants permission to delete a local gateway virtual interfaceWrite

local-gateway-virtual-interface*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayVirtualInterfaceGroupGrants permission to delete a local gateway virtual interface groupWrite

local-gateway-virtual-interface-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteManagedPrefixListGrants permission to delete a managed prefix listWrite

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNatGatewayGrants permission to delete a NAT gatewayWrite

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkAclGrants permission to delete a network ACLWrite

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

ec2:Region

DeleteNetworkAclEntryGrants permission to delete an inbound or outbound entry (rule) from a network ACLWrite

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

ec2:Region

DeleteNetworkInsightsAccessScopeGrants permission to delete a Network Access ScopeWrite

network-insights-access-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkInsightsAccessScopeAnalysisGrants permission to delete a Network Access Scope analysisWrite

network-insights-access-scope-analysis*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkInsightsAnalysisGrants permission to delete a network insights analysisWrite

network-insights-analysis*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkInsightsPathGrants permission to delete a network insights pathWrite

network-insights-path*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkInterfaceGrants permission to delete a detached network interfaceWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DeleteNetworkInterfacePermissionGrants permission to delete a permission that is associated with a network interfacePermissions management

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DeletePlacementGroupGrants permission to delete a placement groupWrite

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

ec2:Region

DeletePublicIpv4PoolGrants permission to delete a public IPv4 address pool for public IPv4 CIDRs that you own and brought to Amazon to manage with Amazon VPC IP Address Manager (IPAM)Write

ipv4pool-ec2*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteQueuedReservedInstancesGrants permission to delete the queued purchases for the specified Reserved InstancesWrite

reserved-instances*

aws:ResourceTag/${TagKey}

ec2:InstanceType

ec2:ReservedInstancesOfferingType

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:Region

DeleteResourcePolicy [permission only]Grants permission to remove an IAM policy that enables cross-account sharing from a resourcePermissions management

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteRouteGrants permission to delete a route from a route tableWrite

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

DeleteRouteServerGrants permission to delete a route serverWrite

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

sns:DeleteTopic

ec2:Region

DeleteRouteServerEndpointGrants permission to delete a route server endpointWrite

route-server-endpoint*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:DeleteNetworkInterface

ec2:DeleteSecurityGroup

ec2:RevokeSecurityGroupIngress

ec2:Region

DeleteRouteServerPeerGrants permission to delete a route server peerWrite

route-server-peer*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:RevokeSecurityGroupIngress

ec2:Region

DeleteRouteTableGrants permission to delete a route tableWrite

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

DeleteSecurityGroupGrants permission to delete a security groupWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

DeleteSnapshotGrants permission to delete a snapshot of an EBS volumeWrite

snapshot*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

DeleteSpotDatafeedSubscriptionGrants permission to delete a data feed for Spot InstancesWrite

ec2:Region

DeleteSubnetGrants permission to delete a subnetWrite

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

DeleteSubnetCidrReservationGrants permission to delete a subnet CIDR reservationWrite

ec2:Region

DeleteTagsGrants permission to delete one or more tags from Amazon EC2 resourcesTagging

capacity-block

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

capacity-manager-data-export

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

capacity-reservation

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

capacity-reservation-fleet

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

carrier-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

client-vpn-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

coip-pool

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

customer-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

declarative-policies-report

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

dedicated-host

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

dhcp-options

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

egress-only-internet-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

elastic-gpu

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

elastic-ip

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

export-image-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

export-instance-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

fleet

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

fpga-image

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

host-reservation

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

image

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

image-usage-report

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

import-image-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

import-snapshot-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

instance

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

instance-connect-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

instance-event-window

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

internet-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-external-resource-verification-token

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-pool

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-resource-discovery

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-resource-discovery-association

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipam-scope

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

key-pair

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

launch-template

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-route-table

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-route-table-virtual-interface-group-association

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-route-table-vpc-association

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-group

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

natgateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-acl

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-insights-access-scope

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-insights-access-scope-analysis

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-insights-analysis

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-insights-path

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

network-interface

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

placement-group

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

prefix-list

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

replace-root-volume-task

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

reserved-instances

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

route-server

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

route-server-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

route-server-peer

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

route-table

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

security-group

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

security-group-rule

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

snapshot

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

spot-fleet-request

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

spot-instances-request

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

subnet

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

subnet-cidr-reservation

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

traffic-mirror-filter

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

traffic-mirror-filter-rule

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

traffic-mirror-session

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

traffic-mirror-target

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

transit-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

transit-gateway-attachment

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

transit-gateway-connect-peer

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

transit-gateway-multicast-domain

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

transit-gateway-policy-table

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

transit-gateway-route-table

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

transit-gateway-route-table-announcement

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-endpoint-target

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-group

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-instance

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-policy

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

verified-access-trust-provider

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

volume

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-block-public-access-exclusion

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-endpoint

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-endpoint-connection

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-endpoint-service-permission

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-flow-log

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpc-peering-connection

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpn-connection

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

vpn-gateway

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

DeleteTrafficMirrorFilterGrants permission to delete a traffic mirror filterWrite

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteTrafficMirrorFilterRuleGrants permission to delete a traffic mirror filter ruleWrite

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-filter-rule*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteTrafficMirrorSessionGrants permission to delete a traffic mirror sessionWrite

traffic-mirror-session*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteTrafficMirrorTargetGrants permission to delete a traffic mirror targetWrite

traffic-mirror-target*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteTransitGatewayGrants permission to delete a transit gatewayWrite

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:Region

DeleteTransitGatewayConnectGrants permission to delete a transit gateway connect attachmentWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

DeleteTransitGatewayConnectPeerGrants permission to delete a transit gateway connect peerWrite

transit-gateway-connect-peer*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayConnectPeerId

ec2:Region

DeleteTransitGatewayMulticastDomainGrants permission to delete a transit gateway multicast domainWrite

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

DeleteTransitGatewayPeeringAttachmentGrants permission to delete a peering attachment from a transit gatewayWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

DeleteTransitGatewayPolicyTableGrants permission to delete a transit gateway policy tableWrite

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

DeleteTransitGatewayPrefixListReferenceGrants permission to delete a transit gateway prefix list referenceWrite

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

DeleteTransitGatewayRouteGrants permission to delete a route from a transit gateway route tableWrite

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

DeleteTransitGatewayRouteTableGrants permission to delete a transit gateway route tableWrite

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

DeleteTransitGatewayRouteTableAnnouncementGrants permission to delete a transit gateway route table announcementWrite

transit-gateway-route-table-announcement*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

ec2:Region

DeleteTransitGatewayVpcAttachmentGrants permission to delete a VPC attachment from a transit gatewayWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

DeleteVerifiedAccessEndpointGrants permission to delete a Verified Access endpointWrite

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVerifiedAccessGroupGrants permission to delete a Verified Access groupWrite

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVerifiedAccessInstanceGrants permission to delete a Verified Access instanceWrite

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVerifiedAccessTrustProviderGrants permission to delete a verified trust providerWrite

verified-access-trust-provider*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVolumeGrants permission to delete an EBS volumeWrite

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

DeleteVpcGrants permission to delete a VPCWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DeleteVpcBlockPublicAccessExclusionGrants permission to delete an exclusion list for blocked public access on a VPCWrite

vpc-block-public-access-exclusion*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVpcEndpointConnectionNotificationsGrants permission to delete one or more VPC endpoint connection notificationsWrite

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceSupportedRegion

ec2:Region

DeleteVpcEndpointServiceConfigurationsGrants permission to delete one or more VPC endpoint service configurationsWrite

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceSupportedRegion

ec2:Region

DeleteVpcEndpointsGrants permission to delete one or more VPC endpointsWrite

vpc-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceServiceName

ec2:VpceServiceRegion

ec2:Region

DeleteVpcPeeringConnectionGrants permission to delete a VPC peering connectionWrite

vpc-peering-connection*

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

ec2:Region

DeleteVpnConnectionGrants permission to delete a VPN connectionWrite

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVpnConnectionRouteGrants permission to delete a static route for a VPN connection between a virtual private gateway and a customer gatewayWrite

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVpnGatewayGrants permission to delete a virtual private gatewayWrite

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeprovisionByoipCidrGrants permission to release an IP address range that was provisioned through bring your own IP addresses (BYOIP), and to delete the corresponding address poolWrite

ec2:Region

DeprovisionIpamByoasnGrants permission to deprovision an Autonomous System Number (ASN) from an Amazon Web Services accountWrite

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeprovisionIpamPoolCidrGrants permission to deprovision a CIDR provisioned from an Amazon VPC IP Address Manager (IPAM) poolWrite

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeprovisionPublicIpv4PoolCidrGrants permission to deprovision a CIDR from a public IPv4 poolWrite

ipv4pool-ec2*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeregisterImageGrants permission to deregister an Amazon Machine Image (AMI)Write

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DeregisterInstanceEventNotificationAttributesGrants permission to remove tags from the set of tags to include in notifications about scheduled events for your instancesWrite

ec2:Region

DeregisterTransitGatewayMulticastGroupMembersGrants permission to deregister one or more network interface members from a group IP address in a transit gateway multicast domainWrite

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

DeregisterTransitGatewayMulticastGroupSourcesGrants permission to deregister one or more network interface sources from a group IP address in a transit gateway multicast domainWrite

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

DescribeAccountAttributesGrants permission to describe the attributes of the AWS accountList

ec2:Region

DescribeAddressTransfersGrants permission to describe an Elastic IP address transferList

ec2:Region

DescribeAddressesGrants permission to describe one or more Elastic IP addressesList

ec2:Region

DescribeAddressesAttributeGrants permission to describe the attributes of the specified Elastic IP addressesList

ec2:Region

DescribeAggregateIdFormatGrants permission to describe the longer ID format settings for all resource typesList

ec2:Region

DescribeAvailabilityZonesGrants permission to describe one or more of the Availability Zones that are available to youList

ec2:Region

DescribeAwsNetworkPerformanceMetricSubscriptionsGrants permission to describe the current infrastructure performance metric subscriptionsList

ec2:Region

DescribeBundleTasksGrants permission to describe one or more bundling tasksList

ec2:Region

DescribeByoipCidrsGrants permission to describe the IP address ranges that were provisioned through bring your own IP addresses (BYOIP)List

ec2:Region

DescribeCapacityBlockExtensionHistoryGrants permission to describe Capacity Block extensions historyList

ec2:Region

DescribeCapacityBlockExtensionOfferingsGrants permission to describe Capacity Block extensions offeringsList

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

DescribeCapacityBlockOfferingsGrants permission to describe Capacity Block offerings available for purchaseList

ec2:Region

DescribeCapacityBlockStatusGrants permission to describe the availability of capacity for the specified Capacity blocks, or all of your Capacity BlocksList

ec2:Region

DescribeCapacityBlocksGrants permission to describe details about Capacity Blocks in the AWS Region that you're currently usingList

ec2:Region

DescribeCapacityManagerDataExportsGrants permission to describe one or more Capacity Manager data export configurationsList

ec2:Region

DescribeCapacityReservationBillingRequestsGrants permission to describe one or more requests to assign the billing of the unused capacity of a Capacity ReservationList

ec2:Region

DescribeCapacityReservationFleetsGrants permission to describe one or more Capacity Reservation FleetsList

ec2:Region

DescribeCapacityReservationsGrants permission to describe one or more Capacity ReservationsList

ec2:Region

DescribeCarrierGatewaysGrants permission to describe one or more Carrier GatewaysList

ec2:Region

DescribeClassicLinkInstancesGrants permission to describe one or more linked EC2-Classic instancesList

ec2:Region

DescribeClientVpnAuthorizationRulesGrants permission to describe the authorization rules for a Client VPN endpointList

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeClientVpnConnectionsGrants permission to describe active client connections and connections that have been terminated within the last 60 minutes for a Client VPN endpointList

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DescribeClientVpnEndpointsGrants permission to describe one or more Client VPN endpointsList

ec2:Region

DescribeClientVpnRoutesGrants permission to describe the routes for a Client VPN endpointList

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DescribeClientVpnTargetNetworksGrants permission to describe the target networks that are associated with a Client VPN endpointList

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DescribeCoipPoolsGrants permission to describe the specified customer-owned address pools or all of your customer-owned address poolsList

ec2:Region

DescribeConversionTasksGrants permission to describe one or more conversion tasksList

ec2:Region

DescribeCustomerGatewaysGrants permission to describe one or more customer gatewaysList

ec2:Region

DescribeDeclarativePoliciesReportsGrants permission to describe one or more declarative policies reportsList

ec2:Region

DescribeDhcpOptionsGrants permission to describe one or more DHCP options setsList

ec2:Region

DescribeEgressOnlyInternetGatewaysGrants permission to describe one or more egress-only internet gatewaysList

ec2:Region

DescribeElasticGpusGrants permission to describe an Elastic Graphics accelerator that is associated with an instanceList

ec2:Region

DescribeExportImageTasksGrants permission to describe one or more export image tasksList

ec2:Region

DescribeExportTasksGrants permission to describe one or more export instance tasksList

ec2:Region

DescribeFastLaunchImagesGrants permission to describe fast-launch enabled Windows AMIsList

ec2:Region

DescribeFastSnapshotRestoresGrants permission to describe the state of fast snapshot restores for snapshotsList

ec2:Region

DescribeFleetHistoryGrants permission to describe the events for an EC2 Fleet during a specified timeList

fleet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeFleetInstancesGrants permission to describe the running instances for an EC2 FleetList

fleet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeFleetsGrants permission to describe one or more EC2 FleetsList

ec2:Region

DescribeFlowLogsGrants permission to describe one or more flow logsList

ec2:Region

DescribeFpgaImageAttributeGrants permission to describe the attributes of an Amazon FPGA Image (AFI)List

fpga-image*

aws:ResourceTag/${TagKey}

ec2:Owner

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeFpgaImagesGrants permission to describe one or more Amazon FPGA Images (AFIs)List

ec2:Region

DescribeHostReservationOfferingsGrants permission to describe the Dedicated Host Reservations that are available to purchaseList

ec2:Region

DescribeHostReservationsGrants permission to describe the Dedicated Host Reservations that are associated with Dedicated Hosts in the AWS accountList

ec2:Region

DescribeHostsGrants permission to describe one or more Dedicated HostsList

ec2:Region

DescribeIamInstanceProfileAssociationsGrants permission to describe the IAM instance profile associationsList

ec2:Region

DescribeIdFormatGrants permission to describe the ID format settings for resourcesList

ec2:Region

DescribeIdentityIdFormatGrants permission to describe the ID format settings for resources for an IAM user, IAM role, or root userList

ec2:Region

DescribeImageAttributeGrants permission to describe an attribute of an Amazon Machine Image (AMI)List

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DescribeImageReferencesGrants permission to describe your AWS resources that are referencing specified imagesList

ec2:Region

DescribeImageUsageReportEntriesGrants permission to describe the entries of an AMI usage reportList

ec2:Region

DescribeImageUsageReportsGrants permission to describe the configuration and status of an AMI usage reportList

ec2:Region

DescribeImagesGrants permission to describe one or more images (AMIs, AKIs, and ARIs)List

ec2:Region

DescribeImportImageTasksGrants permission to describe import virtual machine or import snapshot tasksList

ec2:Region

DescribeImportSnapshotTasksGrants permission to describe import snapshot tasksList

ec2:Region

DescribeInstanceAttributeGrants permission to describe the attributes of an instanceList

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

DescribeInstanceConnectEndpointsGrants permission to describe EC2 Instance Connect EndpointsList

ec2:Region

DescribeInstanceCreditSpecificationsGrants permission to describe the credit option for CPU usage of one or more burstable performance instancesList

ec2:Region

DescribeInstanceEventNotificationAttributesGrants permission to describe the set of tags to include in notifications about scheduled events for your instancesList

ec2:Region

DescribeInstanceEventWindowsGrants permission to describe the specified event windows or all event windowsList

ec2:Region

DescribeInstanceImageMetadataGrants permission to describe the AMI that was used to launch an instanceList

ec2:Region

DescribeInstanceStatusGrants permission to describe the status of one or more instancesList

ec2:Region

DescribeInstanceTopologyGrants permission to describe a tree-based hierarchy that represents the physical host placement of EC2 instancesList

ec2:Region

DescribeInstanceTypeOfferingsGrants permission to describe the set of instance types that are offered in a locationList

ec2:Region

DescribeInstanceTypesGrants permission to describe the details of instance types that are offered in a locationList

ec2:Region

DescribeInstancesGrants permission to describe one or more instancesList

ec2:Region

DescribeInternetGatewaysGrants permission to describe one or more internet gatewaysList

ec2:Region

DescribeIpamByoasnGrants permission to describe a bring your own Autonomous System Number (BYOASN) that you've brought to IPAMList

ec2:Region

DescribeIpamExternalResourceVerificationTokensGrants permission to describe verification tokens, which proves ownership of an external resourceList

ec2:Region

DescribeIpamPoolsGrants permission to describe Amazon VPC IP Address Manager (IPAM) poolsList

ec2:Region

DescribeIpamResourceDiscoveriesGrants permission to describe IPAM resource discoveriesList

ec2:Region

DescribeIpamResourceDiscoveryAssociationsGrants permission to describe resource discovery associations with an Amazon VPC IPAMList

ec2:Region

DescribeIpamScopesGrants permission to describe Amazon VPC IP Address Manager (IPAM) scopesList

ec2:Region

DescribeIpamsGrants permission to describe an Amazon VPC IP Address Manager (IPAM)List

ec2:Region

DescribeIpv6PoolsGrants permission to describe one or more IPv6 address poolsList

ec2:Region

DescribeKeyPairsGrants permission to describe one or more key pairsList

ec2:Region

DescribeLaunchTemplateVersionsGrants permission to describe one or more launch template versionsList

ec2:Region

ssm:GetParameters

DescribeLaunchTemplatesGrants permission to describe one or more launch templatesList

ec2:Region

DescribeLocalGatewayRouteTablePermissions [permission only]Grants permission to allow a service to describe local gateway route table permissionsList

ec2:Region

DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociationsGrants permission to describe the associations between virtual interface groups and local gateway route tablesList

ec2:Region

DescribeLocalGatewayRouteTableVpcAssociationsGrants permission to describe an association between VPCs and local gateway route tablesList

ec2:Region

DescribeLocalGatewayRouteTablesGrants permission to describe one or more local gateway route tablesList

ec2:Region

DescribeLocalGatewayVirtualInterfaceGroupsGrants permission to describe local gateway virtual interface groupsList

ec2:Region

DescribeLocalGatewayVirtualInterfacesGrants permission to describe local gateway virtual interfacesList

ec2:Region

DescribeLocalGatewaysGrants permission to describe one or more local gatewaysList

ec2:Region

DescribeLockedSnapshotsGrants permission to describe the lock status for a snapshotList

ec2:Region

DescribeMacHostsGrants permission to describe your EC2 Mac Dedicated hostsList

ec2:Region

DescribeMacModificationTasksGrants permission to describe a System Integrity Protection (SIP) modification task or volume ownership delegation task for an Amazon EC2 Mac instanceList

ec2:Region

DescribeManagedPrefixListsGrants permission to describe your managed prefix lists and any AWS-managed prefix listsList

ec2:Region

DescribeMovingAddressesGrants permission to describe Elastic IP addresses that are being moved to the EC2-VPC platformList

ec2:Region

DescribeNatGatewaysGrants permission to describe one or more NAT gatewaysList

ec2:Region

DescribeNetworkAclsGrants permission to describe one or more network ACLsList

ec2:Region

DescribeNetworkInsightsAccessScopeAnalysesGrants permission to describe one or more Network Access Scope analysesList

ec2:Region

DescribeNetworkInsightsAccessScopesGrants permission to describe the Network Access ScopesList

ec2:Region

DescribeNetworkInsightsAnalysesGrants permission to describe one or more network insights analysesList

ec2:Region

DescribeNetworkInsightsPathsGrants permission to describe one or more network insights pathsList

ec2:Region

DescribeNetworkInterfaceAttributeGrants permission to describe a network interface attributeList

ec2:Region

DescribeNetworkInterfacePermissionsGrants permission to describe the permissions that are associated with a network interfaceList

ec2:Region

DescribeNetworkInterfacesGrants permission to describe one or more network interfacesList

ec2:Region

DescribeOutpostLagsGrants permission to describe Outpost LAGsList

ec2:Region

DescribePlacementGroupsGrants permission to describe one or more placement groupsList

ec2:Region

DescribePrefixListsGrants permission to describe available AWS services in a prefix list formatList

ec2:Region

DescribePrincipalIdFormatGrants permission to describe the ID format settings for the root user and all IAM roles and IAM users that have explicitly specified a longer ID (17-character ID) preferenceList

ec2:Region

DescribePublicIpv4PoolsGrants permission to describe one or more IPv4 address poolsList

ec2:Region

DescribeRegionsGrants permission to describe one or more AWS Regions that are currently available in your accountList

ec2:Region

DescribeReplaceRootVolumeTasksGrants permission to describe a root volume replacement taskList

ec2:Region

DescribeReservedInstancesGrants permission to describe one or more purchased Reserved Instances in your accountList

ec2:Region

DescribeReservedInstancesListingsGrants permission to describe your account's Reserved Instance listings in the Reserved Instance MarketplaceList

ec2:Region

DescribeReservedInstancesModificationsGrants permission to describe the modifications made to one or more Reserved InstancesList

ec2:Region

DescribeReservedInstancesOfferingsGrants permission to describe the Reserved Instance offerings that are available for purchaseList

ec2:Region

DescribeRouteServerEndpointsGrants permission to describe one or more route server endpointsList

ec2:Region

DescribeRouteServerPeersGrants permission to describe one or more route server peersList

ec2:Region

DescribeRouteServersGrants permission to describe one or more route serversList

ec2:Region

DescribeRouteTablesGrants permission to describe one or more route tablesList

ec2:Region

DescribeScheduledInstanceAvailabilityGrants permission to find available schedules for Scheduled InstancesList

ec2:Region

DescribeScheduledInstancesGrants permission to describe one or more Scheduled Instances in your accountList

ec2:Region

DescribeSecurityGroupReferencesGrants permission to describe the VPCs on the other side of a VPC peering connection that are referencing specified VPC security groupsList

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

DescribeSecurityGroupRulesGrants permission to describe one or more of your security group rulesList

ec2:Region

DescribeSecurityGroupVpcAssociationsGrants permission to describe security group VPC associationsList

ec2:Region

DescribeSecurityGroupsGrants permission to describe one or more security groupsList

ec2:Region

DescribeServiceLinkVirtualInterfacesGrants permission to describe service link virtual interfacesList

ec2:Region

DescribeSnapshotAttributeGrants permission to describe an attribute of a snapshotList

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

ec2:Region

DescribeSnapshotTierStatusGrants permission to describe the storage tier status for Amazon EBS snapshotsList

ec2:Region

DescribeSnapshotsGrants permission to describe one or more EBS snapshotsList

ec2:Region

DescribeSpotDatafeedSubscriptionGrants permission to describe the data feed for Spot InstancesList

ec2:Region

DescribeSpotFleetInstancesGrants permission to describe the running instances for a Spot FleetList

spot-fleet-request*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeSpotFleetRequestHistoryGrants permission to describe the events for a Spot Fleet request during a specified timeList

spot-fleet-request*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeSpotFleetRequestsGrants permission to describe one or more Spot Fleet requestsList

ec2:Region

DescribeSpotInstanceRequestsGrants permission to describe one or more Spot Instance requestsList

ec2:Region

DescribeSpotPriceHistoryGrants permission to describe the Spot Instance price historyList

ec2:Region

DescribeStaleSecurityGroupsGrants permission to describe the stale security group rules for security groups in a specified VPCList

ec2:Region

DescribeStoreImageTasksGrants permission to describe the progress of the AMI store tasksList

ec2:Region

DescribeSubnetsGrants permission to describe one or more subnetsList

ec2:Region

DescribeTagsGrants permission to describe one or more tags for an Amazon EC2 resourceList

ec2:Region

DescribeTrafficMirrorFilterRulesGrants permission to describe traffic mirror filters that determine the traffic that is mirroredList

ec2:Region

DescribeTrafficMirrorFiltersGrants permission to describe one or more traffic mirror filtersList

ec2:Region

DescribeTrafficMirrorSessionsGrants permission to describe one or more traffic mirror sessionsList

ec2:Region

DescribeTrafficMirrorTargetsGrants permission to describe one or more traffic mirror targetsList

ec2:Region

DescribeTransitGatewayAttachmentsGrants permission to describe one or more attachments between resources and transit gatewaysList

ec2:Region

DescribeTransitGatewayConnectPeersGrants permission to describe one or more transit gateway connect peersList

ec2:Region

DescribeTransitGatewayConnectsGrants permission to describe one or more transit gateway connect attachmentsList

ec2:Region

DescribeTransitGatewayMulticastDomainsGrants permission to describe one or more transit gateway multicast domainsList

ec2:Region

DescribeTransitGatewayPeeringAttachmentsGrants permission to describe one or more transit gateway peering attachmentsList

ec2:Region

DescribeTransitGatewayPolicyTablesGrants permission to describe a transit gateway policy tableList

ec2:Region

DescribeTransitGatewayRouteTableAnnouncementsGrants permission to describe a transit gateway route table announcementList

ec2:Region

DescribeTransitGatewayRouteTablesGrants permission to describe one or more transit gateway route tablesList

ec2:Region

DescribeTransitGatewayVpcAttachmentsGrants permission to describe one or more VPC attachments on a transit gatewayList

ec2:Region

DescribeTransitGatewaysGrants permission to describe one or more transit gatewaysList

ec2:Region

DescribeTrunkInterfaceAssociationsGrants permission to describe one or more network interface trunk associationsList

ec2:Region

DescribeVerifiedAccessEndpointsGrants permission to describe the specified Verified Access endpoints or all Verified Access endpointsList

ec2:Region

DescribeVerifiedAccessGroupsGrants permission to describe the specified Verified Access groups or all Verified Access groupsList

ec2:Region

DescribeVerifiedAccessInstanceLoggingConfigurationsGrants permission to describe the current logging configuration for the Verified Access instancesList

ec2:Region

DescribeVerifiedAccessInstanceWebAclAssociations [permission only]Grants permission to describe the AWS Web Application Firewall (WAF) web access control list (ACL) associations for a Verified Access instanceList

ec2:Region

DescribeVerifiedAccessInstancesGrants permission to describe the specified Verified Access instances or all Verified Access instancesList

ec2:Region

DescribeVerifiedAccessTrustProvidersGrants permission to describe details of existing Verified Access trust providersList

ec2:Region

DescribeVolumeAttributeGrants permission to describe an attribute of an EBS volumeList

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

DescribeVolumeStatusGrants permission to describe the status of one or more EBS volumesList

ec2:Region

DescribeVolumesGrants permission to describe one or more EBS volumesList

ec2:Region

DescribeVolumesModificationsGrants permission to describe the current modification status of one or more EBS volumesList

ec2:Region

DescribeVpcAttributeGrants permission to describe an attribute of a VPCList

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DescribeVpcBlockPublicAccessExclusionsGrants permission to describe an exclusion list for blocked public access on a VPCList

ec2:Region

DescribeVpcBlockPublicAccessOptionsGrants permission to describe options for blocked public access on a VPCList

ec2:Region

DescribeVpcClassicLinkGrants permission to describe the ClassicLink status of one or more VPCsList

ec2:Region

DescribeVpcClassicLinkDnsSupportGrants permission to describe the ClassicLink DNS support status of one or more VPCsList

ec2:Region

DescribeVpcEndpointAssociationsGrants permission to describe the VPC endpoint associationsList

ec2:Region

DescribeVpcEndpointConnectionNotificationsGrants permission to describe the connection notifications for VPC endpoints and VPC endpoint servicesList

ec2:Region

DescribeVpcEndpointConnectionsGrants permission to describe the VPC endpoint connections to your VPC endpoint servicesList

ec2:Region

DescribeVpcEndpointServiceConfigurationsGrants permission to describe VPC endpoint service configurations (your services)List

ec2:Region

DescribeVpcEndpointServicePermissionsGrants permission to describe the principals (service consumers) that are permitted to discover your VPC endpoint serviceList

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceSupportedRegion

ec2:Region

DescribeVpcEndpointServicesGrants permission to describe all supported AWS services that can be specified when creating a VPC endpointList

ec2:Region

DescribeVpcEndpointsGrants permission to describe one or more VPC endpointsList

ec2:Region

DescribeVpcPeeringConnectionsGrants permission to describe one or more VPC peering connectionsList

ec2:Region

DescribeVpcsGrants permission to describe one or more VPCsList

ec2:Region

DescribeVpnConnectionsGrants permission to describe one or more VPN connectionsList

ec2:Region

DescribeVpnGatewaysGrants permission to describe one or more virtual private gatewaysList

ec2:Region

DetachClassicLinkVpcGrants permission to unlink (detach) a linked EC2-Classic instance from a VPCWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DetachInternetGatewayGrants permission to detach an internet gateway from a VPCWrite

internet-gateway*

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DetachNetworkInterfaceGrants permission to detach a network interface from an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DetachVerifiedAccessTrustProviderGrants permission to detach a trust provider from a Verified Access instanceWrite

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-trust-provider*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DetachVolumeGrants permission to detach an EBS volume from an instanceWrite

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

DetachVpnGatewayGrants permission to detach a virtual private gateway from a VPCWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisableAddressTransferGrants permission to disable Elastic IP address transferWrite

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

DisableAllowedImagesSettingsGrants permission to disable allowed images settingsWrite

ec2:Region

DisableAwsNetworkPerformanceMetricSubscriptionGrants permission to disable infrastructure performance metric subscriptionsWrite

ec2:Region

DisableCapacityManagerGrants permission to disable EC2 Capacity Manager for your accountWrite

ec2:Region

DisableEbsEncryptionByDefaultGrants permission to disable EBS encryption by default for your accountWrite

ec2:Region

DisableFastLaunchGrants permission to disable faster launching for Windows AMIsWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DisableFastSnapshotRestoresGrants permission to disable fast snapshot restores for one or more snapshots in specified Availability ZonesWrite

snapshot*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

DisableImageGrants permission to disable an AMIWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DisableImageBlockPublicAccessGrants permission to disable block public access for AMIs at the account level in the specified AWS RegionPermissions management

ec2:Region

DisableImageDeprecationGrants permission to cancel the deprecation of the specified AMIWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DisableImageDeregistrationProtectionGrants permission to disable deregistration protection for an AMI. When deregistration protection is disabled, the AMI can be deregisteredWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DisableIpamOrganizationAdminAccountGrants permission to disable an AWS Organizations member account as an Amazon VPC IP Address Manager (IPAM) admin accountWrite

ec2:Region

organizations:DeregisterDelegatedAdministrator

DisableRouteServerPropagationGrants permission to disable route server propagationWrite

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

DisableSerialConsoleAccessGrants permission to disable access to the EC2 serial console of all instances for your accountWrite

ec2:Region

DisableSnapshotBlockPublicAccessGrants permission to disable the block public access for snapshots setting for a RegionPermissions management

ec2:Region

DisableTransitGatewayRouteTablePropagationGrants permission to disable a resource attachment from propagating routes to the specified propagation route tableWrite

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-route-table-announcement

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

ec2:Region

DisableVgwRoutePropagationGrants permission to disable a virtual private gateway from propagating routes to a specified route table of a VPCWrite

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisableVpcClassicLinkGrants permission to disable ClassicLink for a VPCWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DisableVpcClassicLinkDnsSupportGrants permission to disable ClassicLink DNS support for a VPCWrite

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DisassociateAddressGrants permission to disassociate an Elastic IP address from an instance or network interfaceWrite

elastic-ip

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DisassociateCapacityReservationBillingOwnerGrants permission to cancel a pending request to assign billing of the unused capacity of a Capacity Reservation to a consumer accountWrite

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

DisassociateClientVpnTargetNetworkGrants permission to disassociate a target network from a Client VPN endpointWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DisassociateEnclaveCertificateIamRoleGrants permission to disassociate an ACM certificate from a IAM roleWrite

certificate*

role*

ec2:Region

DisassociateIamInstanceProfileGrants permission to disassociate an IAM instance profile from a running or stopped instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

DisassociateInstanceEventWindowGrants permission to disassociate one or more targets from an event windowWrite

instance-event-window*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisassociateIpamByoasnGrants permission to disassociate an Autonomous System Number (ASN) from a BYOIP CIDRWrite

ec2:Region

DisassociateIpamResourceDiscoveryGrants permission to disassociate a resource discovery from an Amazon VPC IPAMWrite

ipam-resource-discovery-association*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisassociateNatGatewayAddressGrants permission to disassociate a secondary Elastic IP address from a public NAT gatewayWrite

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DisassociateRouteServerGrants permission to disassociate a route server from a VPCWrite

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc*

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DisassociateRouteTableGrants permission to disassociate a subnet from a route tableWrite

internet-gateway

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisassociateSecurityGroupVpcGrants permission to disassociate a security group from a VPCWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DisassociateSubnetCidrBlockGrants permission to disassociate a CIDR block from a subnetWrite

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

DisassociateTransitGatewayMulticastDomainGrants permission to disassociate one or more subnets from a transit gateway multicast domainWrite

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

DisassociateTransitGatewayPolicyTableGrants permission to disassociate a policy table from a transit gatewayWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

DisassociateTransitGatewayRouteTableGrants permission to disassociate a resource attachment from a transit gateway route tableWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

DisassociateTrunkInterfaceGrants permission to disassociate a branch network interface to a trunk network interfaceWrite

ec2:Region

DisassociateVerifiedAccessInstanceWebAcl [permission only]Grants permission to disassociate an AWS Web Application Firewall (WAF) web access control list (ACL) from a Verified Access instanceWrite

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisassociateVpcCidrBlockGrants permission to disassociate a CIDR block from a VPCWrite

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

EnableAddressTransferGrants permission to enable Elastic IP address transferWrite

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

EnableAllowedImagesSettingsGrants permission to enable allowed images settingsWrite

ec2:Region

EnableAwsNetworkPerformanceMetricSubscriptionGrants permission to enable infrastructure performance subscriptionsWrite

ec2:Region

EnableCapacityManagerGrants permission to enable EC2 Capacity Manager for your accountWrite

ec2:Region

EnableEbsEncryptionByDefaultGrants permission to enable EBS encryption by default for your accountWrite

ec2:Region

EnableFastLaunchGrants permission to enable faster launching for Windows AMIsWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:CreateLaunchTemplate

ec2:CreateSnapshot

ec2:CreateTags

ec2:DeleteSnapshot

ec2:DescribeImages

ec2:DescribeInstanceAttribute

ec2:DescribeInstanceStatus

ec2:DescribeInstanceTypeOfferings

ec2:DescribeInstances

ec2:DescribeLaunchTemplateVersions

ec2:DescribeLaunchTemplates

ec2:DescribeSnapshots

ec2:DescribeSubnets

ec2:RunInstances

ec2:StopInstances

ec2:TerminateInstances

iam:PassRole

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ec2:Region

EnableFastSnapshotRestoresGrants permission to enable fast snapshot restores for one or more snapshots in specified Availability ZonesWrite

snapshot*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

EnableImageGrants permission to re-enable a disabled AMIWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

EnableImageBlockPublicAccessGrants permission to enable block public access for AMIs at the account level in the specified AWS RegionPermissions management

ec2:Region

EnableImageDeprecationGrants permission to enable deprecation of the specified AMI at the specified date and timeWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

EnableImageDeregistrationProtectionGrants permission to enable deregistration protection for an AMI. When deregistration protection is enabled, the AMI can't be deregisteredWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

EnableIpamOrganizationAdminAccountGrants permission to enable an AWS Organizations member account as an Amazon VPC IP Address Manager (IPAM) admin accountWrite

ec2:Region

iam:CreateServiceLinkedRole

organizations:EnableAWSServiceAccess

organizations:RegisterDelegatedAdministrator

EnableReachabilityAnalyzerOrganizationSharingGrants permission to enable organization sharing of reachability analyzerWrite

ec2:Region

iam:CreateServiceLinkedRole

organizations:EnableAWSServiceAccess

EnableRouteServerPropagationGrants permission to enable route server propagationWrite

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

EnableSerialConsoleAccessGrants permission to enable access to the EC2 serial console of all instances for your accountWrite

ec2:Region

EnableSnapshotBlockPublicAccessGrants permission to enable or modify the block public access for snapshots setting for a RegionPermissions management

ec2:Region

EnableTransitGatewayRouteTablePropagationGrants permission to enable an attachment to propagate routes to a propagation route tableWrite

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-route-table-announcement

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

ec2:Region

EnableVgwRoutePropagationGrants permission to enable a virtual private gateway to propagate routes to a VPC route tableWrite

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

EnableVolumeIOGrants permission to enable I/O operations for a volume that had I/O operations disabledWrite

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

EnableVpcClassicLinkGrants permission to enable a VPC for ClassicLinkWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

EnableVpcClassicLinkDnsSupportGrants permission to enable a VPC to support DNS hostname resolution for ClassicLinkWrite

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

ExportClientVpnClientCertificateRevocationListGrants permission to download the client certificate revocation list for a Client VPN endpointRead

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

ExportClientVpnClientConfigurationGrants permission to download the contents of the Client VPN endpoint configuration file for a Client VPN endpointRead

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

ExportImageGrants permission to export an Amazon Machine Image (AMI) to a VM fileWrite

export-image-task*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

ExportTransitGatewayRoutesGrants permission to export routes from a transit gateway route table to an Amazon S3 bucketWrite

ec2:Region

ExportVerifiedAccessInstanceClientConfigurationGrants permission to export a verified access instance client configurationRead

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetActiveVpnTunnelStatusGrants permission to retrieve the current security parameters for an active VPN tunnelRead

vpn-connection*

ec2:ResourceTag/${TagKey}

ec2:Region

GetAllowedImagesSettingsGrants permission to get the allowed settings for imagesRead

ec2:Region

GetAssociatedEnclaveCertificateIamRolesGrants permission to get the list of roles associated with an ACM certificateRead

certificate*

ec2:Region

GetAssociatedIpv6PoolCidrsGrants permission to get information about the IPv6 CIDR block associations for a specified IPv6 address poolRead

ipv6pool-ec2*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetAwsNetworkPerformanceDataGrants permission to get network performance dataRead

ec2:Region

GetCapacityManagerAttributesGrants permission to retrieve the current configuration and status of EC2 Capacity ManagerRead

ec2:Region

GetCapacityManagerMetricDataGrants permission to retrieve capacity usage metrics for your EC2 resourcesRead

ec2:Region

GetCapacityManagerMetricDimensionsGrants permission to retrieve the available dimension values for capacity metrics within a specified time rangeRead

ec2:Region

GetCapacityReservationUsageGrants permission to get usage information about a Capacity ReservationRead

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:CapacityReservationFleet

ec2:Region

GetCoipPoolUsageGrants permission to describe the allocations from the specified customer-owned address poolRead

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetConsoleOutputGrants permission to get the console output for an instanceRead

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetConsoleScreenshotGrants permission to retrieve a JPG-format screenshot of a running instanceRead

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetDeclarativePoliciesReportSummaryGrants permission to get the report summary of declarative policiesRead

declarative-policies-report*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetDefaultCreditSpecificationGrants permission to get the default credit option for CPU usage of a burstable performance instance familyRead

ec2:Region

GetEbsDefaultKmsKeyIdGrants permission to get the ID of the default customer master key (CMK) for EBS encryption by defaultRead

ec2:Region

GetEbsEncryptionByDefaultGrants permission to describe whether EBS encryption by default is enabled for your accountRead

ec2:Region

GetFlowLogsIntegrationTemplateGrants permission to generate a CloudFormation template to streamline the integration of VPC flow logs with Amazon AthenaRead

vpc-flow-log*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetGroupsForCapacityReservationGrants permission to list the resource groups to which a Capacity Reservation has been addedList

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:CapacityReservationFleet

ec2:Region

GetHostReservationPurchasePreviewGrants permission to preview a reservation purchase with configurations that match those of a Dedicated HostRead

ec2:Region

GetImageBlockPublicAccessStateGrants permission to get the current state of block public access for AMIs at the account level in the specified AWS RegionRead

ec2:Region

GetInstanceMetadataDefaultsGrants permission to view the default instance metadata service (IMDS) settings set for your account in the specified RegionList

ec2:Region

GetInstanceTpmEkPubGrants permission to get the public endorsement key associated with the Nitro Trusted Platform Module (NitroTPM) for the specified instanceRead

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetInstanceTypesFromInstanceRequirementsGrants permission to view a list of instance types with specified instance attributesList

ec2:Region

GetInstanceUefiDataGrants permission to retrieve the binary representation of the UEFI variable storeRead

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetIpamAddressHistoryGrants permission to retrieve historical information about a CIDR within an Amazon VPC IP Address Manager (IPAM) scopeRead

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamDiscoveredAccountsGrants permission to retrieve IPAM discovered accountsRead

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamDiscoveredPublicAddressesGrants permission to retrieve the public IP addresses that have been discovered by IPAMRead

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamDiscoveredResourceCidrsGrants permission to retrieve the resource CIDRs that are monitored as part of a resource discoveryRead

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamPoolAllocationsGrants permission to get a list of all the CIDR allocations in an Amazon VPC IP Address Manager (IPAM) poolList

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamPoolCidrsGrants permission to get the CIDRs provisioned to an Amazon VPC IP Address Manager (IPAM) poolRead

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamResourceCidrsGrants permission to get information about the resources in an Amazon VPC IP Address Manager (IPAM) scopeRead

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetLaunchTemplateDataGrants permission to get the configuration data of the specified instance for use with a new launch template or launch template versionRead

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetManagedPrefixListAssociationsGrants permission to get information about the resources that are associated with the specified managed prefix listRead

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetManagedPrefixListEntriesGrants permission to get information about the entries for a specified managed prefix listRead

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetNetworkInsightsAccessScopeAnalysisFindingsGrants permission to get the findings for one or more Network Access Scope analysesRead

network-insights-access-scope-analysis*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetNetworkInsightsAccessScopeContentGrants permission to get the content for a specified Network Access ScopeRead

network-insights-access-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetPasswordDataGrants permission to retrieve the encrypted administrator password for a running Windows instanceRead

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetReservedInstancesExchangeQuoteGrants permission to return a quote and exchange information for exchanging one or more Convertible Reserved Instances for a new Convertible Reserved InstanceRead

reserved-instances*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:InstanceType

ec2:ReservedInstancesOfferingType

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:Region

GetResourcePolicy [permission only]Grants permission to describe an IAM policy that enables cross-account sharingRead

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetRouteServerAssociationsGrants permission to get associations for a route serverRead

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetRouteServerPropagationsGrants permission to get propagations for a route serverRead

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

GetRouteServerRoutingDatabaseGrants permission to get the routing database for a route serverRead

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetSecurityGroupsForVpcGrants permission to retrieve a list of security groups for a specified VPCRead

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

GetSerialConsoleAccessStatusGrants permission to retrieve the access status of your account to the EC2 serial console of all instancesRead

ec2:Region

GetSnapshotBlockPublicAccessStateGrants permission to retrieve the current state of the block public access for snapshots setting for a RegionRead

ec2:Region

GetSpotPlacementScoresGrants permission to calculate the Spot placement score for a Region or Availability Zone based on the specified target capacity and compute requirementsRead

ec2:Region

GetSubnetCidrReservationsGrants permission to retrieve information about the subnet CIDR reservationsRead

ec2:Region

GetTransitGatewayAttachmentPropagationsGrants permission to list the route tables to which a resource attachment propagates routesList

ec2:Region

GetTransitGatewayMulticastDomainAssociationsGrants permission to get information about the associations for a transit gateway multicast domainList

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

GetTransitGatewayPolicyTableAssociationsGrants permission to get information about associations for a transit gateway policy tableList

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

GetTransitGatewayPolicyTableEntriesGrants permission to get information about associations for a transit gateway policy table entryList

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

GetTransitGatewayPrefixListReferencesGrants permission to get information about prefix list references for a transit gateway route tableList

ec2:Region

GetTransitGatewayRouteTableAssociationsGrants permission to get information about associations for a transit gateway route tableList

ec2:Region

GetTransitGatewayRouteTablePropagationsGrants permission to get information about the route table propagations for a transit gateway route tableList

ec2:Region

GetVerifiedAccessEndpointPolicyGrants permission to show the Verified Access policy associated with the endpointList

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetVerifiedAccessEndpointTargetsGrants permission to get verified access endpoint targetsList

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetVerifiedAccessGroupPolicyGrants permission to show the contents of the Verified Access policy associated with the groupList

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetVerifiedAccessInstanceWebAcl [permission only]Grants permission to show the AWS Web Application Firewall (WAF) web access control list (ACL) for a Verified Access instanceList

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetVpnConnectionDeviceSampleConfigurationGrants permission to download an AWS-provided sample configuration file to be used with the customer gateway deviceList

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpn-connection-device-type*

ec2:Region

GetVpnConnectionDeviceTypesGrants permission to obtain a list of customer gateway devices for which sample configuration files can be providedList

ec2:Region

GetVpnTunnelReplacementStatusGrants permission to view available tunnel endpoint maintenance eventsList

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ImportByoipCidrToIpam [permission only]Grants permission to transfer existing BYOIP IPv4 CIDRs to IPAMWrite

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ImportClientVpnClientCertificateRevocationListGrants permission to upload a client certificate revocation list to a Client VPN endpointWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

ImportImageGrants permission to import single or multi-volume disk images or EBS snapshots into an Amazon Machine Image (AMI)Write

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:RootDeviceType

ec2:CreateTags

import-image-task*

aws:RequestTag/${TagKey}

aws:TagKeys

snapshot

aws:ResourceTag/${TagKey}

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ImportInstanceGrants permission to create an import instance task using metadata from a disk imageWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ImportKeyPairGrants permission to import a public key from an RSA key pair that was created with a third-party toolWrite

key-pair*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

ImportSnapshotGrants permission to import a disk into an EBS snapshotWrite

import-snapshot-task*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Owner

ec2:ParentVolume

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ImportVolumeGrants permission to create an import volume task using metadata from a disk imageWrite

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

InjectApiError [permission only]Grants permission to temporarily inject errors for target API requestsWrite

ec2:FisActionId

ec2:FisTargetArns

ec2:Region

ListImagesInRecycleBinGrants permission to list Amazon Machine Images (AMIs) that are currently in the Recycle BinList

ec2:Region

ListSnapshotsInRecycleBinGrants permission to list the Amazon EBS snapshots that are currently in the Recycle BinList

ec2:Region

LockSnapshotGrants permission to lock an Amazon EBS snapshot in either governance or compliance mode to protect it against accidental or malicious deletionsWrite

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotCoolOffPeriod

ec2:SnapshotID

ec2:SnapshotLockDuration

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ModifyAddressAttributeGrants permission to modify an attribute of the specified Elastic IP addressWrite

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyAvailabilityZoneGroupGrants permission to modify the opt-in status of the Local Zone and Wavelength Zone group for your accountWrite

ec2:Region

ModifyCapacityReservationGrants permission to modify a Capacity Reservation's capacity and the conditions under which it is to be releasedWrite

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:CapacityReservationFleet

ec2:Region

ModifyCapacityReservationFleetGrants permission to modify a Capacity Reservation FleetWrite

capacity-reservation-fleet*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:ModifyCapacityReservation

ec2:Region

ModifyClientVpnEndpointGrants permission to modify a Client VPN endpointWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

ModifyDefaultCreditSpecificationGrants permission to change the account level default credit option for CPU usage of burstable performance instancesWrite

ec2:Region

ModifyEbsDefaultKmsKeyIdGrants permission to change the default customer master key (CMK) for EBS encryption by default for your accountWrite

ec2:Region

ModifyFleetGrants permission to modify an EC2 FleetWrite

fleet*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifyFpgaImageAttributeGrants permission to modify an attribute of an Amazon FPGA Image (AFI)Write

fpga-image*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyHostsGrants permission to modify a Dedicated HostWrite

dedicated-host*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIdFormatGrants permission to modify the ID format for a resourceWrite

ec2:Region

ModifyIdentityIdFormatGrants permission to modify the ID format of a resource for a specific principal in your accountWrite

ec2:Region

ModifyImageAttributeGrants permission to modify an attribute of an Amazon Machine Image (AMI)Write

image*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

ModifyInstanceAttributeGrants permission to modify an attribute of an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

volume

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

ModifyInstanceCapacityReservationAttributesGrants permission to modify the Capacity Reservation settings for a stopped instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

capacity-reservation

aws:ResourceTag/${TagKey}

ec2:Region

ModifyInstanceConnectEndpointGrants permission to modify an existing EC2 Instance Connect EndpointWrite

instance-connect-endpoint*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

ModifyInstanceCpuOptionsGrants permission to modify the CPU options on an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstanceCreditSpecificationGrants permission to modify the credit option for CPU usage on an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstanceEventStartTimeGrants permission to modify the start time for a scheduled EC2 instance eventWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstanceEventWindowGrants permission to modify the specified event windowWrite

instance-event-window*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyInstanceMaintenanceOptionsGrants permission to modify the recovery behaviour for an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstanceMetadataDefaultsGrants permission to modify the default instance metadata service (IMDS) settings for your account in the specified RegionWrite

ec2:Attribute/${AttributeName}

ec2:Region

ModifyInstanceMetadataOptionsGrants permission to modify the metadata options for an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstanceNetworkPerformanceOptionsGrants permission to modify the network performance options for an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstancePlacementGrants permission to modify the placement attributes for an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

dedicated-host

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpamGrants permission to modify the configurations of an Amazon VPC IP Address Manager (IPAM)Write

ipam*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpamPoolGrants permission to modify the configurations of an Amazon VPC IP Address Manager (IPAM) poolWrite

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpamResourceCidrGrants permission to modify the configurations of an Amazon VPC IP Address Manager (IPAM) resource CIDRWrite

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpamResourceDiscoveryGrants permission to modify a resource discoveryWrite

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpamScopeGrants permission to modify the configurations of an Amazon VPC IP Address Manager (IPAM) scopeWrite

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyLaunchTemplateGrants permission to modify a launch templateWrite

launch-template*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyLocalGatewayRouteGrants permission to modify a local gateway routeWrite

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyManagedPrefixListGrants permission to modify a managed prefix listWrite

prefix-list*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyNetworkInterfaceAttributeGrants permission to modify an attribute of a network interfaceWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:Vpc

ec2:Region

ModifyPrivateDnsNameOptionsGrants permission to modify the options for instance hostnames for the specified instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyPublicIpDnsNameOptionsGrants permission to modify public hostname options for a network interfaceWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

ModifyReservedInstancesGrants permission to modify attributes of one or more Reserved InstancesWrite

reserved-instances*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:InstanceType

ec2:ReservedInstancesOfferingType

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:Region

ModifyRouteServerGrants permission to modify a route serverWrite

route-server*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifySecurityGroupRulesGrants permission to modify the rules of a security groupWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

security-group-rule*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifySnapshotAttributeGrants permission to add or remove permission settings for a snapshotPermissions management

snapshot*

aws:ResourceTag/${TagKey}

ec2:Add/group

ec2:Add/userId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:Owner

ec2:ParentVolume

ec2:Remove/group

ec2:Remove/userId

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ModifySnapshotTierGrants permission to archive Amazon EBS snapshotsWrite

snapshot*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ModifySpotFleetRequestGrants permission to modify a Spot Fleet requestWrite

spot-fleet-request*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifySubnetAttributeGrants permission to modify an attribute of a subnetWrite

subnet*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifyTrafficMirrorFilterNetworkServicesGrants permission to allow or restrict mirroring network servicesWrite

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyTrafficMirrorFilterRuleGrants permission to modify a traffic mirror ruleWrite

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

traffic-mirror-filter-rule*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyTrafficMirrorSessionGrants permission to modify a traffic mirror sessionWrite

traffic-mirror-session*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

traffic-mirror-filter

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-target

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyTransitGatewayGrants permission to modify a transit gatewayWrite

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

ModifyTransitGatewayPrefixListReferenceGrants permission to modify a transit gateway prefix list referenceWrite

prefix-list*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

ModifyTransitGatewayVpcAttachmentGrants permission to modify a VPC attachment on a transit gatewayWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifyVerifiedAccessEndpointGrants permission to modify the configuration of a Verified Access endpointWrite

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessEndpointPolicyGrants permission to modify the specified Verified Access endpoint policyWrite

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessGroupGrants permission to modify the specified Verified Access Group configurationWrite

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

verified-access-instance

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessGroupPolicyGrants permission to modify the specified Verified Access group policyWrite

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessInstanceGrants permission to modify the configuration of the specified Verified Access instanceWrite

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessInstanceLoggingConfigurationGrants permission to modify the logging configuration for the specified Verified Access instanceWrite

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessTrustProviderGrants permission to modify the configuration of the specified Verified Access trust providerWrite

verified-access-trust-provider*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVolumeGrants permission to modify the parameters of an EBS volumeWrite

volume*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

ModifyVolumeAttributeGrants permission to modify an attribute of a volumeWrite

volume*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

ModifyVpcAttributeGrants permission to modify an attribute of a VPCWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

ModifyVpcBlockPublicAccessExclusionGrants permission to modify an exclusion list for blocked public access on a VPCWrite

vpc-block-public-access-exclusion*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVpcBlockPublicAccessOptionsGrants permission to modify options for blocked public access on a VPCWrite

ec2:Region

ModifyVpcEndpointGrants permission to modify an attribute of a VPC endpointWrite

vpc-endpoint*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceServiceRegion

route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifyVpcEndpointConnectionNotificationGrants permission to modify a connection notification for a VPC endpoint or VPC endpoint serviceWrite

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceSupportedRegion

ec2:Region

ModifyVpcEndpointServiceConfigurationGrants permission to modify the attributes of a VPC endpoint service configurationWrite

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceServicePrivateDnsName

ec2:VpceSupportedRegion

ec2:Region

ModifyVpcEndpointServicePayerResponsibilityGrants permission to modify the payer responsibility for a VPC endpoint serviceWrite

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceSupportedRegion

ec2:Region

ModifyVpcEndpointServicePermissionsGrants permission to modify the permissions for a VPC endpoint servicePermissions management

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceSupportedRegion

ec2:Region

ModifyVpcPeeringConnectionOptionsGrants permission to modify the VPC peering connection options on one side of a VPC peering connectionWrite

vpc-peering-connection*

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

ec2:Region

ModifyVpcTenancyGrants permission to modify the instance tenancy attribute of a VPCWrite

vpc*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

ModifyVpnConnectionGrants permission to modify the target gateway of a Site-to-Site VPN connectionWrite

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:ResourceTag/${TagKey}

ec2:RoutingType

ec2:Region

ModifyVpnConnectionOptionsGrants permission to modify the connection options for your Site-to-Site VPN connectionWrite

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVpnTunnelCertificateGrants permission to modify the certificate for a Site-to-Site VPN connectionWrite

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVpnTunnelOptionsGrants permission to modify the options for a Site-to-Site VPN connectionWrite

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:ResourceTag/${TagKey}

ec2:RoutingType

ec2:Region

MonitorInstancesGrants permission to enable detailed monitoring for a running instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

MoveAddressToVpcGrants permission to move an Elastic IP address from the EC2-Classic platform to the EC2-VPC platformWrite

ec2:Region

MoveByoipCidrToIpamGrants permission to move a BYOIP IPv4 CIDR to Amazon VPC IP Address Manager (IPAM) from a public IPv4 poolWrite

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

MoveCapacityReservationInstancesGrants permission to move available capacity from a source Capacity Reservation to a destination Capacity ReservationWrite

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

PauseVolumeIO [permission only]Grants permission to temporarily pause I/O operations for a target Amazon EBS volumeWrite

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ProvisionByoipCidrGrants permission to provision an address range for use in AWS through bring your own IP addresses (BYOIP), and to create a corresponding address poolWrite

ec2:Region

ProvisionIpamByoasnGrants permission to provision an Autonomous System Number (ASN) for use in an Amazon Web Services accountWrite

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ProvisionIpamPoolCidrGrants permission to provision a CIDR to an Amazon VPC IP Address Manager (IPAM) poolWrite

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-external-resource-verification-token

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ProvisionPublicIpv4PoolCidrGrants permission to provision a CIDR to a public IPv4 poolWrite

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv4pool-ec2*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

PurchaseCapacityBlockGrants permission to purchase a Capacity Block offeringWrite

capacity-reservation*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CapacityReservationFleet

ec2:CreateTags

ec2:Region

PurchaseCapacityBlockExtensionGrants permission to purchase a Capacity Block extensionWrite

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:CapacityReservationFleet

ec2:Region

PurchaseHostReservationGrants permission to purchase a reservation with configurations that match those of a Dedicated HostWrite

dedicated-host*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

ec2:Region

PurchaseReservedInstancesOfferingGrants permission to purchase a Reserved Instance offeringWrite

ec2:Region

PurchaseScheduledInstancesGrants permission to purchase one or more Scheduled Instances with a specified scheduleWrite

ec2:Region

PutResourcePolicy [permission only]Grants permission to attach an IAM policy that enables cross-account sharing to a resourcePermissions management

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

RebootInstancesGrants permission to request a reboot of one or more instancesWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

RegisterImageGrants permission to register an Amazon Machine Image (AMI)Write

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:Owner

ec2:CreateTags

snapshot

aws:ResourceTag/${TagKey}

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

ec2:Region

RegisterInstanceEventNotificationAttributesGrants permission to add tags to the set of tags to include in notifications about scheduled events for your instancesWrite

ec2:Region

RegisterTransitGatewayMulticastGroupMembersGrants permission to register one or more network interfaces as a member of a group IP address in a transit gateway multicast domainWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

RegisterTransitGatewayMulticastGroupSourcesGrants permission to register one or more network interfaces as a source of a group IP address in a transit gateway multicast domainWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

RejectCapacityReservationBillingOwnershipGrants permission to reject a request to assign billing of the available capacity of a shared Capacity Reservation to your accountWrite

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

RejectTransitGatewayMulticastDomainAssociationsGrants permission to reject requests to associate cross-account subnets with a transit gateway multicast domainWrite

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

RejectTransitGatewayPeeringAttachmentGrants permission to reject a transit gateway peering attachment requestWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

RejectTransitGatewayVpcAttachmentGrants permission to reject a request to attach a VPC to a transit gatewayWrite

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

RejectVpcEndpointConnectionsGrants permission to reject one or more VPC endpoint connection requests to a VPC endpoint serviceWrite

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceSupportedRegion

ec2:Region

RejectVpcPeeringConnectionGrants permission to reject a VPC peering connection requestWrite

vpc-peering-connection*

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

ec2:Region

ReleaseAddressGrants permission to release an Elastic IP addressWrite

elastic-ip

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

ReleaseHostsGrants permission to release one or more On-Demand Dedicated HostsWrite

dedicated-host*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ReleaseIpamPoolAllocationGrants permission to release an allocation within an Amazon VPC IP Address Manager (IPAM) poolWrite

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ReplaceIamInstanceProfileAssociationGrants permission to replace an IAM instance profile for an instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

iam:PassRole

ec2:Region

ReplaceImageCriteriaInAllowedImagesSettingsGrants permission to replace image criteria in allowed images settingsWrite

ec2:Region

ReplaceNetworkAclAssociationGrants permission to change which network ACL a subnet is associated withWrite

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ReplaceNetworkAclEntryGrants permission to replace an entry (rule) in a network ACLWrite

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

ec2:Region

ReplaceRouteGrants permission to replace a route within a route table in a VPCWrite

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

ReplaceRouteTableAssociationGrants permission to change the route table that is associated with a subnetWrite

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

internet-gateway

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ReplaceTransitGatewayRouteGrants permission to replace a route in a transit gateway route tableWrite

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

ReplaceVpnTunnelGrants permission to replace a VPN tunnelWrite

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ReportInstanceStatusGrants permission to submit feedback about the status of an instanceWrite

instance*

ec2:AvailabilityZoneId

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:Region

RequestSpotFleetGrants permission to create a Spot Fleet requestWrite

spot-fleet-request*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

key-pair

aws:ResourceTag/${TagKey}

ec2:KeyPairName

ec2:KeyPairType

ec2:ResourceTag/${TagKey}

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

snapshot

aws:ResourceTag/${TagKey}

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

RequestSpotInstancesGrants permission to create a Spot Instance requestWrite

spot-instances-request*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

iam:PassRole

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

key-pair

aws:ResourceTag/${TagKey}

ec2:KeyPairName

ec2:KeyPairType

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

snapshot

aws:ResourceTag/${TagKey}

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ResetAddressAttributeGrants permission to reset the attribute of the specified IP addressWrite

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

ResetEbsDefaultKmsKeyIdGrants permission to reset the default customer master key (CMK) for EBS encryption for your account to use the AWS-managed CMK for EBSWrite

ec2:Region

ResetFpgaImageAttributeGrants permission to reset an attribute of an Amazon FPGA Image (AFI) to its default valueWrite

fpga-image*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:Region

ResetImageAttributeGrants permission to reset an attribute of an Amazon Machine Image (AMI) to its default valueWrite

image*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

ResetInstanceAttributeGrants permission to reset an attribute of an instance to its default valueWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ResetNetworkInterfaceAttributeGrants permission to reset an attribute of a network interfaceWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

ResetSnapshotAttributeGrants permission to reset permission settings for a snapshotPermissions management

snapshot*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

RestoreAddressToClassicGrants permission to restore an Elastic IP address that was previously moved to the EC2-VPC platform back to the EC2-Classic platformWrite

ec2:Region

RestoreImageFromRecycleBinGrants permission to restore an Amazon Machine Image (AMI) from the Recycle BinWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

RestoreManagedPrefixListVersionGrants permission to restore the entries from a previous version of a managed prefix list to a new version of the prefix listWrite

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

RestoreSnapshotFromRecycleBinGrants permission to restore an Amazon EBS snapshot from the Recycle BinWrite

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

RestoreSnapshotTierGrants permission to restore an archived Amazon EBS snapshot for use temporarily or permanently, or modify the restore period or restore type for a snapshot that was previously temporarily restoredWrite

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

RevokeClientVpnIngressGrants permission to remove an inbound authorization rule from a Client VPN endpointWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

RevokeSecurityGroupEgressGrants permission to remove one or more outbound rules from a VPC security groupWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

RevokeSecurityGroupIngressGrants permission to remove one or more inbound rules from a security groupWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

RunInstancesGrants permission to launch one or more instancesWrite

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:CreateTags

iam:PassRole

ssm:GetParameters

instance*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:RootDeviceType

ec2:Tenancy

network-interface*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AssociatePublicIpAddress

ec2:AuthorizedService

ec2:AvailabilityZone

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Subnet

ec2:Vpc

security-group*

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

capacity-reservation

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

elastic-gpu

aws:ResourceTag/${TagKey}

ec2:ElasticGpuType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ResourceTag/${TagKey}

elastic-inference

group

key-pair

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:KeyPairName

ec2:KeyPairType

ec2:LaunchTemplate

ec2:ResourceTag/${TagKey}

launch-template

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

license-configuration

placement-group

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

snapshot

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

volume

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

SCENARIO: EC2-Classic-EBS

image*

instance*

security-group*

volume*

key-pair

placement-group

snapshot

SCENARIO: EC2-Classic-InstanceStore

image*

instance*

security-group*

key-pair

placement-group

snapshot

SCENARIO: EC2-VPC-EBS

image*

instance*

network-interface*

security-group*

volume*

key-pair

placement-group

snapshot

SCENARIO: EC2-VPC-EBS-Subnet

image*

instance*

network-interface*

security-group*

subnet*

volume*

key-pair

placement-group

snapshot

SCENARIO: EC2-VPC-InstanceStore

image*

instance*

network-interface*

security-group*

key-pair

placement-group

snapshot

SCENARIO: EC2-VPC-InstanceStore-Subnet

image*

instance*

network-interface*

security-group*

subnet*

key-pair

placement-group

snapshot

RunScheduledInstancesGrants permission to launch one or more Scheduled InstancesWrite

ec2:Region

SearchLocalGatewayRoutesGrants permission to search for routes in a local gateway route tableList

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

SearchTransitGatewayMulticastGroupsGrants permission to search for groups, sources, and members in a transit gateway multicast domainList

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

SearchTransitGatewayRoutesGrants permission to search for routes in a transit gateway route tableList

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

SendDiagnosticInterruptGrants permission to send a diagnostic interrupt to an Amazon EC2 instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

SendSpotInstanceInterruptions [permission only]Grants permission to interrupt a Spot InstanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

StartDeclarativePoliciesReportGrants permission to start a declarative policies reportRead

ec2:Region

StartInstancesGrants permission to start a stopped instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

license-configuration

ec2:Region

StartNetworkInsightsAccessScopeAnalysisGrants permission to start a Network Access Scope analysisWrite

network-insights-access-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

network-insights-access-scope-analysis*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

StartNetworkInsightsAnalysisGrants permission to start analyzing a specified pathWrite

network-insights-analysis*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

network-insights-path*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

StartVpcEndpointServicePrivateDnsVerificationGrants permission to start the private DNS verification process for a VPC endpoint serviceWrite

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceSupportedRegion

ec2:Region

StopInstancesGrants permission to stop an Amazon EBS-backed instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

TerminateClientVpnConnectionsGrants permission to terminate active Client VPN endpoint connectionsWrite

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

TerminateInstancesGrants permission to shut down one or more instancesWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

UnassignIpv6AddressesGrants permission to unassign one or more IPv6 addresses from a network interfaceWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

UnassignPrivateIpAddressesGrants permission to unassign one or more secondary private IP addresses from a network interfaceWrite

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

UnassignPrivateNatGatewayAddressGrants permission to unassign secondary private IPv4 addresses from a private NAT gatewayWrite

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

UnlockSnapshotGrants permission to unlock a snapshot that is locked in governance mode or in compliance mode while still in the cooling-off periodWrite

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotCoolOffPeriod

ec2:SnapshotID

ec2:SnapshotLockDuration

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

UnmonitorInstancesGrants permission to disable detailed monitoring for a running instanceWrite

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

UpdateCapacityManagerOrganizationsAccessGrants permission to update the Organizations access setting for EC2 Capacity ManagerWrite

ec2:Region

UpdateSecurityGroupRuleDescriptionsEgressGrants permission to update descriptions for one or more outbound rules in a VPC security groupWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

UpdateSecurityGroupRuleDescriptionsIngressGrants permission to update descriptions for one or more inbound rules in a security groupWrite

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

WithdrawByoipCidrGrants permission to stop advertising an address range that was provisioned for use in AWS through bring your own IP addresses (BYOIP)Write

ec2:Region

Resource types defined by Amazon EC2

The following resource types are defined by this service and can be used in theResource element of IAM permission policy statements. Each action in theActions table identifies the resource types that can be specified with that action. A resource type can also define which condition keys you can include in a policy. These keys are displayed in the last column of the table. For details about the columns in the following table, seeResource types table.

Resource typesARNCondition keys
elastic-iparn:${Partition}:ec2:${Region}:${Account}:elastic-ip/${AllocationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AllocationId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Domain

ec2:PublicIpAddress

ec2:Region

ec2:ResourceTag/${TagKey}

capacity-blockarn:${Partition}:ec2:${Region}:${Account}:capacity-block/${CapacityBlockId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

capacity-manager-data-exportarn:${Partition}:ec2:${Region}:${Account}:capacity-manager-data-export/${CapacityManagerDataExportId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

capacity-reservation-fleetarn:${Partition}:ec2:${Region}:${Account}:capacity-reservation-fleet/${CapacityReservationFleetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

capacity-reservationarn:${Partition}:ec2:${Region}:${Account}:capacity-reservation/${CapacityReservationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:EphemeralStorage

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:OutpostArn

ec2:PlacementGroup

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

carrier-gatewayarn:${Partition}:ec2:${Region}:${Account}:carrier-gateway/${CarrierGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:Vpc

certificatearn:${Partition}:acm:${Region}:${Account}:certificate/${CertificateId}
client-vpn-endpointarn:${Partition}:ec2:${Region}:${Account}:client-vpn-endpoint/${ClientVpnEndpointId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

customer-gatewayarn:${Partition}:ec2:${Region}:${Account}:customer-gateway/${CustomerGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

declarative-policies-reportarn:${Partition}:ec2:${Region}:${Account}:declarative-policies-report/${DeclarativePoliciesReportId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

dedicated-hostarn:${Partition}:ec2:${Region}:${Account}:dedicated-host/${DedicatedHostId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AutoPlacement

ec2:AvailabilityZone

ec2:HostRecovery

ec2:InstanceType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Quantity

ec2:Region

ec2:ResourceTag/${TagKey}

dhcp-optionsarn:${Partition}:ec2:${Region}:${Account}:dhcp-options/${DhcpOptionsId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:DhcpOptionsID

ec2:Region

ec2:ResourceTag/${TagKey}

egress-only-internet-gatewayarn:${Partition}:ec2:${Region}:${Account}:egress-only-internet-gateway/${EgressOnlyInternetGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

elastic-gpuarn:${Partition}:ec2:${Region}:${Account}:elastic-gpu/${ElasticGpuId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ElasticGpuType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Region

ec2:ResourceTag/${TagKey}

elastic-inferencearn:${Partition}:elastic-inference:${Region}:${Account}:elastic-inference-accelerator/${AcceleratorId}
export-image-taskarn:${Partition}:ec2:${Region}:${Account}:export-image-task/${ExportImageTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

export-instance-taskarn:${Partition}:ec2:${Region}:${Account}:export-instance-task/${ExportTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

fleetarn:${Partition}:ec2:${Region}:${Account}:fleet/${FleetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

fpga-imagearn:${Partition}:ec2:${Region}:${Account}:fpga-image/${FpgaImageId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Owner

ec2:Public

ec2:Region

ec2:ResourceTag/${TagKey}

host-reservationarn:${Partition}:ec2:${Region}:${Account}:host-reservation/${HostReservationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

imagearn:${Partition}:ec2:${Region}::image/${ImageId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ImageID

ec2:ImageType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Owner

ec2:Public

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

image-usage-reportarn:${Partition}:ec2:${Region}:${Account}:image-usage-report/${ImageUsageReportId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

import-image-taskarn:${Partition}:ec2:${Region}:${Account}:import-image-task/${ImportImageTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

import-snapshot-taskarn:${Partition}:ec2:${Region}:${Account}:import-snapshot-task/${ImportSnapshotTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

instance-connect-endpointarn:${Partition}:ec2:${Region}:${Account}:instance-connect-endpoint/${InstanceConnectEndpointId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SubnetID

instance-event-windowarn:${Partition}:ec2:${Region}:${Account}:instance-event-window/${InstanceEventWindowId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

instancearn:${Partition}:ec2:${Region}:${Account}:instance/${InstanceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceBandwidthWeighting

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

internet-gatewayarn:${Partition}:ec2:${Region}:${Account}:internet-gateway/${InternetGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:InternetGatewayID

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-external-resource-verification-tokenarn:${Partition}:ec2::${Account}:ipam-external-resource-verification-token/${IpamExternalResourceVerificationTokenId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ipamarn:${Partition}:ec2::${Account}:ipam/${IpamId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-poolarn:${Partition}:ec2::${Account}:ipam-pool/${IpamPoolId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-resource-discovery-associationarn:${Partition}:ec2::${Account}:ipam-resource-discovery-association/${IpamResourceDiscoveryAssociationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-resource-discoveryarn:${Partition}:ec2::${Account}:ipam-resource-discovery/${IpamResourceDiscoveryId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-scopearn:${Partition}:ec2::${Account}:ipam-scope/${IpamScopeId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

coip-poolarn:${Partition}:ec2:${Region}:${Account}:coip-pool/${Ipv4PoolCoipId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ipv4pool-ec2arn:${Partition}:ec2:${Region}:${Account}:ipv4pool-ec2/${Ipv4PoolEc2Id}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ipv6pool-ec2arn:${Partition}:ec2:${Region}:${Account}:ipv6pool-ec2/${Ipv6PoolEc2Id}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

key-pairarn:${Partition}:ec2:${Region}:${Account}:key-pair/${KeyPairName}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:IsLaunchTemplateResource

ec2:KeyPairName

ec2:KeyPairType

ec2:LaunchTemplate

ec2:Region

ec2:ResourceTag/${TagKey}

launch-templatearn:${Partition}:ec2:${Region}:${Account}:launch-template/${LaunchTemplateId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:Region

ec2:ResourceTag/${TagKey}

license-configurationarn:${Partition}:license-manager:${Region}:${Account}:license-configuration:${LicenseConfigurationId}
local-gatewayarn:${Partition}:ec2:${Region}:${Account}:local-gateway/${LocalGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-route-table-virtual-interface-group-associationarn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-virtual-interface-group-association/${LocalGatewayRouteTableVirtualInterfaceGroupAssociationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-route-table-vpc-associationarn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-vpc-association/${LocalGatewayRouteTableVpcAssociationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-route-tablearn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table/${LocalGatewayRoutetableId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-grouparn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface-group/${LocalGatewayVirtualInterfaceGroupId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interfacearn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface/${LocalGatewayVirtualInterfaceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

mac-modification-taskarn:${Partition}:ec2:${Region}:${Account}:mac-modification-task/${MacModificationTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

natgatewayarn:${Partition}:ec2:${Region}:${Account}:natgateway/${NatGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-aclarn:${Partition}:ec2:${Region}:${Account}:network-acl/${NaclId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:NetworkAclID

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:Vpc

network-insights-access-scope-analysisarn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope-analysis/${NetworkInsightsAccessScopeAnalysisId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-insights-access-scopearn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope/${NetworkInsightsAccessScopeId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-insights-analysisarn:${Partition}:ec2:${Region}:${Account}:network-insights-analysis/${NetworkInsightsAnalysisId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-insights-patharn:${Partition}:ec2:${Region}:${Account}:network-insights-path/${NetworkInsightsPathId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-interfacearn:${Partition}:ec2:${Region}:${Account}:network-interface/${NetworkInterfaceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AssociatePublicIpAddress

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AuthorizedService

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

outpost-lagarn:${Partition}:ec2:${Region}:${Account}:outpost-lag/${OutpostLagId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

placement-grouparn:${Partition}:ec2:${Region}:${Account}:placement-group/${PlacementGroupName}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:Region

ec2:ResourceTag/${TagKey}

prefix-listarn:${Partition}:ec2:${Region}:${Account}:prefix-list/${PrefixListId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

replace-root-volume-taskarn:${Partition}:ec2:${Region}:${Account}:replace-root-volume-task/${ReplaceRootVolumeTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

reserved-instancesarn:${Partition}:ec2:${Region}:${Account}:reserved-instances/${ReservationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:InstanceType

ec2:Region

ec2:ReservedInstancesOfferingType

ec2:ResourceTag/${TagKey}

ec2:Tenancy

grouparn:${Partition}:resource-groups:${Region}:${Account}:group/${GroupName}
rolearn:${Partition}:iam::${Account}:role/${RoleNameWithPath}
route-server-endpointarn:${Partition}:ec2:${Region}:${Account}:route-server-endpoint/${RouteServerEndpointId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:Region

ec2:ResourceTag/${TagKey}

route-serverarn:${Partition}:ec2:${Region}:${Account}:route-server/${RouteServerId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

route-server-peerarn:${Partition}:ec2:${Region}:${Account}:route-server-peer/${RouteServerPeerId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:Region

ec2:ResourceTag/${TagKey}

route-tablearn:${Partition}:ec2:${Region}:${Account}:route-table/${RouteTableId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

security-grouparn:${Partition}:ec2:${Region}:${Account}:security-group/${SecurityGroupId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

security-group-rulearn:${Partition}:ec2:${Region}:${Account}:security-group-rule/${SecurityGroupRuleId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

snapshotarn:${Partition}:ec2:${Region}::snapshot/${SnapshotId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Add/group

ec2:Add/userId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:Encrypted

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Location

ec2:OutpostArn

ec2:Owner

ec2:ParentSnapshot

ec2:ParentVolume

ec2:ProductCode

ec2:Region

ec2:Remove/group

ec2:Remove/userId

ec2:ResourceTag/${TagKey}

ec2:SnapshotCoolOffPeriod

ec2:SnapshotID

ec2:SnapshotLockDuration

ec2:SnapshotTime

ec2:SourceAvailabilityZone

ec2:SourceOutpostArn

ec2:VolumeSize

spot-fleet-requestarn:${Partition}:ec2:${Region}:${Account}:spot-fleet-request/${SpotFleetRequestId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

spot-instances-requestarn:${Partition}:ec2:${Region}:${Account}:spot-instances-request/${SpotInstanceRequestId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

subnet-cidr-reservationarn:${Partition}:ec2:${Region}:${Account}:subnet-cidr-reservation/${SubnetCidrReservationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

subnetarn:${Partition}:ec2:${Region}:${Account}:subnet/${SubnetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

traffic-mirror-filterarn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter/${TrafficMirrorFilterId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

traffic-mirror-filter-rulearn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter-rule/${TrafficMirrorFilterRuleId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

traffic-mirror-sessionarn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-session/${TrafficMirrorSessionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

traffic-mirror-targetarn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-target/${TrafficMirrorTargetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

transit-gateway-attachmentarn:${Partition}:ec2:${Region}:${Account}:transit-gateway-attachment/${TransitGatewayAttachmentId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-connect-peerarn:${Partition}:ec2:${Region}:${Account}:transit-gateway-connect-peer/${TransitGatewayConnectPeerId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayConnectPeerId

transit-gatewayarn:${Partition}:ec2:${Region}:${Account}:transit-gateway/${TransitGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-multicast-domainarn:${Partition}:ec2:${Region}:${Account}:transit-gateway-multicast-domain/${TransitGatewayMulticastDomainId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

transit-gateway-policy-tablearn:${Partition}:ec2:${Region}:${Account}:transit-gateway-policy-table/${TransitGatewayPolicyTableId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

transit-gateway-route-table-announcementarn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table-announcement/${TransitGatewayRouteTableAnnouncementId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

transit-gateway-route-tablearn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table/${TransitGatewayRouteTableId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

verified-access-endpointarn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint/${VerifiedAccessEndpointId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-endpoint-targetarn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint-target/${VerifiedAccessEndpointTargetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-grouparn:${Partition}:ec2:${Region}:${Account}:verified-access-group/${VerifiedAccessGroupId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-instancearn:${Partition}:ec2:${Region}:${Account}:verified-access-instance/${VerifiedAccessInstanceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-policyarn:${Partition}:ec2:${Region}:${Account}:verified-access-policy/${VerifiedAccessPolicyId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-trust-providerarn:${Partition}:ec2:${Region}:${Account}:verified-access-trust-provider/${VerifiedAccessTrustProviderId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

volumearn:${Partition}:ec2:${Region}:${Account}:volume/${VolumeId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:AvailabilityZoneId

ec2:Encrypted

ec2:IsLaunchTemplateResource

ec2:KmsKeyId

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ParentVolume

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeInitializationRate

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

vpc-block-public-access-exclusionarn:${Partition}:ec2:${Region}:${Account}:vpc-block-public-access-exclusion/${VpcBlockPublicAccessExclusionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

vpc-endpoint-connectionarn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-connection/${VpcEndpointConnectionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

vpc-endpointarn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint/${VpcEndpointId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceServiceName

ec2:VpceServiceOwner

ec2:VpceServiceRegion

vpc-endpoint-servicearn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service/${VpcEndpointServiceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:VpceMultiRegion

ec2:VpceServicePrivateDnsName

ec2:VpceServiceRegion

ec2:VpceSupportedRegion

vpc-endpoint-service-permissionarn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service-permission/${VpcEndpointServicePermissionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

vpc-flow-logarn:${Partition}:ec2:${Region}:${Account}:vpc-flow-log/${VpcFlowLogId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

vpcarn:${Partition}:ec2:${Region}:${Account}:vpc/${VpcId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpc-peering-connectionarn:${Partition}:ec2:${Region}:${Account}:vpc-peering-connection/${VpcPeeringConnectionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AccepterVpc

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

vpn-connection-device-typearn:${Partition}:ec2:${Region}:${Account}:vpn-connection-device-type/${VpnConnectionDeviceTypeId}

ec2:Region

vpn-connectionarn:${Partition}:ec2:${Region}:${Account}:vpn-connection/${VpnConnectionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:Region

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:ResourceTag/${TagKey}

ec2:RoutingType

vpn-gatewayarn:${Partition}:ec2:${Region}:${Account}:vpn-gateway/${VpnGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

Condition keys for Amazon EC2

Amazon EC2 defines the following condition keys that can be used in theCondition element of an IAM policy. You can use these keys to further refine the conditions under which the policy statement applies. For details about the columns in the following table, seeCondition keys table.

To view the global condition keys that are available to all services, seeAWS global condition context keys.

Condition keysDescriptionType
aws:RequestTag/${TagKey}Filters access by a tag key and value pair that is allowed in the requestString
aws:ResourceTag/${TagKey}Filters access by a tag key and value pair of a resourceString
aws:TagKeysFilters access by a list of tag keys that are allowed in the requestArrayOfString
ec2:AccepterVpcFilters access by the ARN of an accepter VPC in a VPC peering connectionARN
ec2:Add/groupFilters access by the group being added to a snapshotString
ec2:Add/userIdFilters access by the account id being added to a snapshotString
ec2:AllocationIdFilters access by the allocation ID of the Elastic IP addressString
ec2:AssociatePublicIpAddressFilters access by whether the user wants to associate a public IP address with the instanceBool
ec2:AttributeFilters access by an attribute of a resourceString
ec2:Attribute/${AttributeName}Filters access by an attribute being set on a resourceString
ec2:AuthenticationTypeFilters access by the authentication type for the VPN tunnel endpointsString
ec2:AuthorizedServiceFilters access by the AWS service that has permission to use a resourceString
ec2:AuthorizedUserFilters access by an IAM principal that has permission to use a resourceString
ec2:AutoPlacementFilters access by the Auto Placement properties of a Dedicated HostString
ec2:AvailabilityZoneFilters access by the name of an Availability Zone in an AWS RegionString
ec2:AvailabilityZoneIdFilters access by the ID of an Availability Zone in an AWS RegionString
ec2:CapacityReservationFleetFilters access by the ARN of the Capacity Reservation FleetARN
ec2:ClientRootCertificateChainArnFilters access by the ARN of the client root certificate chainARN
ec2:CloudwatchLogGroupArnFilters access by the ARN of the CloudWatch Logs log groupARN
ec2:CloudwatchLogStreamArnFilters access by the ARN of the CloudWatch Logs log streamARN
ec2:CpuOptionsAmdSevSnpFilters access by the state of AMD SEV-SNP CPU Options. Currently, only US East (Ohio) and Europe (Ireland) are supportedString
ec2:CreateActionFilters access by the name of a resource-creating API actionString
ec2:CreateDateFilters access by the date and time at which the Capacity Reservation was createdDate
ec2:DPDTimeoutSecondsFilters access by the duration after which DPD timeout occurs on a VPN tunnelNumeric
ec2:DestinationCapacityReservationIdFilters access by the ID of the Capacity Reservation that you want to move capacity intoARN
ec2:DhcpOptionsIDFilters access by the ID of a dynamic host configuration protocol (DHCP) options setString
ec2:DirectoryArnFilters access by the ARN of the directoryARN
ec2:DomainFilters access by the domain of the Elastic IP addressString
ec2:EbsOptimizedFilters access by whether the instance is enabled for EBS optimizationBool
ec2:ElasticGpuTypeFilters access by the type of Elastic Graphics acceleratorString
ec2:EncryptedFilters access by whether the EBS volume is encryptedBool
ec2:EndDateFilters access by the date and time at which the Capacity Reservation endsDate
ec2:EndDateTypeFilters access by the way in which the Capacity Reservation endsString
ec2:EphemeralStorageFilters access by whether the instance is enabled for ephemeral storageBool
ec2:FisActionIdFilters access by the ID of an AWS FIS actionString
ec2:FisTargetArnsFilters access by the ARN of an AWS FIS targetArrayOfARN
ec2:GatewayTypeFilters access by the gateway type for a VPN endpoint on the AWS side of a VPN connectionString
ec2:HostRecoveryFilters access by whether host recovery is enabled for a Dedicated HostString
ec2:IKEVersionsFilters access by the internet key exchange (IKE) versions that are permitted for a VPN tunnelArrayOfString
ec2:ImageIDFilters access by the ID of an imageString
ec2:ImageTypeFilters access by the type of image (machine, aki, or ari)String
ec2:InsideTunnelCidrFilters access by the range of inside IP addresses for a VPN tunnelString
ec2:InsideTunnelIpv6CidrFilters access by a range of inside IPv6 addresses for a VPN tunnelString
ec2:InstanceAutoRecoveryFilters access by whether the instance type supports auto recoveryString
ec2:InstanceBandwidthWeightingFilters access by the bandwidth weighting of an instanceString
ec2:InstanceCountFilters access by the number of instancesNumeric
ec2:InstanceIDFilters access by the ID of an instanceString
ec2:InstanceMarketTypeFilters access by the market or purchasing option of an instance (capacity-block, on-demand, or spot)String
ec2:InstanceMatchCriteriaFilters access by the type of instance launches that the Capacity Reservation acceptsString
ec2:InstanceMetadataTagsFilters access by whether the instance allows access to instance tags from the instance metadataString
ec2:InstancePlatformFilters access by the type of operating system for which the Capacity Reservation reserves capacityARN
ec2:InstanceProfileFilters access by the ARN of an instance profileARN
ec2:InstanceTypeFilters access by the type of instanceString
ec2:InternetGatewayIDFilters access by the ID of an internet gatewayString
ec2:Ipv4IpamPoolIdFilters access by the ID of an IPAM pool provided for IPv4 CIDR block allocationString
ec2:Ipv6IpamPoolIdFilters access by the ID of an IPAM pool provided for IPv6 CIDR block allocationString
ec2:IsLaunchTemplateResourceFilters access by whether users are able to override resources that are specified in the launch templateBool
ec2:KeyPairNameFilters access by the name of a key pairString
ec2:KeyPairTypeFilters access by the type of a key pairString
ec2:KmsKeyIdFilters access by the ID of an AWS KMS key provided in the requestString
ec2:LaunchTemplateFilters access by the ARN of a launch templateARN
ec2:LocationFilters access by the destination for the snapshot copyString
ec2:ManagedResourceOperatorFilters access by the presence of an EC2 operator provisioning a managed resourceString
ec2:MetadataHttpEndpointFilters access by whether the HTTP endpoint is enabled for the instance metadata serviceString
ec2:MetadataHttpPutResponseHopLimitFilters access by the allowed number of hops when calling the instance metadata serviceNumeric
ec2:MetadataHttpTokensFilters access by whether tokens are required when calling the instance metadata service (optional or required)String
ec2:NetworkAclIDFilters access by the ID of a network access control list (ACL)String
ec2:NetworkInterfaceIDFilters access by the ID of an elastic network interfaceString
ec2:NewInstanceProfileFilters access by the ARN of the instance profile being attachedARN
ec2:OutpostArnFilters access by the ARN of the OutpostARN
ec2:OwnerFilters access by the owner of the resource (amazon, aws-marketplace, or an AWS account ID)String
ec2:ParentSnapshotFilters access by the ARN of the parent snapshotARN
ec2:ParentVolumeFilters access by the ARN of the parent volume from which the snapshot was createdARN
ec2:PermissionFilters access by the type of permission for a resource (INSTANCE-ATTACH or EIP-ASSOCIATE)String
ec2:Phase1DHGroupFilters access by the Diffie-Hellman group numbers that are permitted for a VPN tunnel for the phase 1 IKE negotiationsArrayOfString
ec2:Phase1EncryptionAlgorithmsFilters access by the encryption algorithms that are permitted for a VPN tunnel for the phase 1 IKE negotiationsArrayOfString
ec2:Phase1IntegrityAlgorithmsFilters access by the integrity algorithms that are permitted for a VPN tunnel for the phase 1 IKE negotiationsArrayOfString
ec2:Phase1LifetimeSecondsFilters access by the lifetime in seconds for phase 1 of the IKE negotiations for a VPN tunnelNumeric
ec2:Phase2DHGroupFilters access by the Diffie-Hellman group numbers that are permitted for a VPN tunnel for the phase 2 IKE negotiationsArrayOfString
ec2:Phase2EncryptionAlgorithmsFilters access by the encryption algorithms that are permitted for a VPN tunnel for the phase 2 IKE negotiationsArrayOfString
ec2:Phase2IntegrityAlgorithmsFilters access by the integrity algorithms that are permitted for a VPN tunnel for the phase 2 IKE negotiationsArrayOfString
ec2:Phase2LifetimeSecondsFilters access by the lifetime in seconds for phase 2 of the IKE negotiations for a VPN tunnelNumeric
ec2:PlacementGroupFilters access by the ARN of the placement groupARN
ec2:PlacementGroupNameFilters access by the name of a placement groupString
ec2:PlacementGroupStrategyFilters access by the instance placement strategy used by the placement group (cluster, spread, or partition)String
ec2:ProductCodeFilters access by the product code that is associated with the AMIString
ec2:PublicFilters access by whether the image has public launch permissionsBool
ec2:PublicIpAddressFilters access by a public IP addressString
ec2:QuantityFilters access by the number of Dedicated Hosts in a requestNumeric
ec2:RegionFilters access by the name of the AWS RegionString
ec2:RekeyFuzzPercentageFilters access by the percentage of increase of the rekey window (determined by the rekey margin time) within which the rekey time is randomly selected for a VPN tunnelNumeric
ec2:RekeyMarginTimeSecondsFilters access by the margin time before the phase 2 lifetime expires for a VPN tunnelNumeric
ec2:Remove/groupFilters access by the group being removed from a snapshotString
ec2:Remove/userIdFilters access by the account id being removed from a snapshotString
ec2:ReplayWindowSizePacketsFilters access by the number of packets in an IKE replay windowString
ec2:RequesterVpcFilters access by the ARN of a requester VPC in a VPC peering connectionARN
ec2:ReservedInstancesOfferingTypeFilters access by the payment option of the Reserved Instance offering (No Upfront, Partial Upfront, or All Upfront)String
ec2:ResourceTag/${TagKey}Filters access by a tag key and value pair of a resourceString
ec2:RoleDeliveryFilters access by the version of the instance metadata service for retrieving IAM role credentials for EC2Numeric
ec2:RootDeviceTypeFilters access by the root device type of the instance (ebs or instance-store)String
ec2:RouteTableIDFilters access by the ID of a route tableString
ec2:RoutingTypeFilters access by the routing type for the VPN connectionString
ec2:SamlProviderArnFilters access by the ARN of the IAM SAML identity providerARN
ec2:SecurityGroupIDFilters access by the ID of a security groupString
ec2:ServerCertificateArnFilters access by the ARN of the server certificateARN
ec2:SnapshotCoolOffPeriodFilters access by the compliance mode cooling-off periodNumeric
ec2:SnapshotIDFilters access by the ID of a snapshotString
ec2:SnapshotLockDurationFilters access by the snapshot lock durationNumeric
ec2:SnapshotTimeFilters access by the initiation time of a snapshotString
ec2:SourceAvailabilityZoneFilters access by the name of the Availability Zone from which the request originatedString
ec2:SourceCapacityReservationIdFilters access by the ID of the Capacity Reservation from which you want to move capacityARN
ec2:SourceInstanceARNFilters access by the ARN of the instance from which the request originatedARN
ec2:SourceOutpostArnFilters access by the ARN of the Outpost from which the request originatedARN
ec2:SubnetFilters access by the ARN of the subnetARN
ec2:SubnetIDFilters access by the ID of a subnetString
ec2:TenancyFilters access by the tenancy of the VPC or instance (default, dedicated, or host)String
ec2:VolumeIDFilters access by the ID of a volumeString
ec2:VolumeInitializationRateFilters access by the initialization rate of the volume, in MiBpsNumeric
ec2:VolumeIopsFilters access by the the number of input/output operations per second (IOPS) provisioned for the volumeNumeric
ec2:VolumeSizeFilters access by the size of the volume, in GiBNumeric
ec2:VolumeThroughputFilters access by the throughput of the volume, in MiBpsNumeric
ec2:VolumeTypeFilters access by the type of volume (gp2, gp3, io1, io2, st1, sc1, or standard)String
ec2:VpcFilters access by the ARN of the VPCARN
ec2:VpcIDFilters access by the ID of a virtual private cloud (VPC)String
ec2:VpcPeeringConnectionIDFilters access by the ID of a VPC peering connectionString
ec2:VpceMultiRegionFilters access by multi region of the VPC endpoint serviceString
ec2:VpceServiceNameFilters access by the name of the VPC endpoint serviceString
ec2:VpceServiceOwnerFilters access by the service owner of the VPC endpoint service (amazon, aws-marketplace, or an AWS account ID)String
ec2:VpceServicePrivateDnsNameFilters access by the private DNS name of the VPC endpoint serviceString
ec2:VpceServiceRegionFilters access by the region of the VPC endpoint serviceString
ec2:VpceSupportedRegionFilters access by the supported region of the VPC endpoint serviceString
ec2:transitGatewayAttachmentIdFilters access by the ID of a transit gateway attachmentString
ec2:transitGatewayConnectPeerIdFilters access by the ID of a transit gateway connect peerString
ec2:transitGatewayIdFilters access by the ID of a transit gatewayString
ec2:transitGatewayMulticastDomainIdFilters access by the ID of a transit gateway multicast domainString
ec2:transitGatewayPolicyTableIdFilters access by the ID of a transit gateway policy tableString
ec2:transitGatewayRouteTableAnnouncementIdFilters access by the ID of a transit gateway route table announcementString
ec2:transitGatewayRouteTableIdFilters access by the ID of a transit gateway route tableString

[8]
ページ先頭

©2009-2025 Movatter.jp