Skip to content

Latest commit

 

History

History
134 lines (133 loc) · 32.6 KB

File metadata and controls

134 lines (133 loc) · 32.6 KB
Action Description Resource Condition
rds:AddTagsToResource Adds metadata tags to an Amazon RDS resource. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:AddTagsToResource Adds metadata tags to an Amazon RDS resource. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:AddTagsToResource Adds metadata tags to an Amazon RDS resource. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:AddTagsToResource Adds metadata tags to an Amazon RDS resource. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag
rds:AddTagsToResource Adds metadata tags to an Amazon RDS resource. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:AddTagsToResource Adds metadata tags to an Amazon RDS resource. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:AddTagsToResource Adds metadata tags to an Amazon RDS resource. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:AddTagsToResource Adds metadata tags to an Amazon RDS resource. arn:aws:rds:$region:$account-id:ri:$reserved-db-instance-name rds:ri-tag
rds:AddSourceIdentifierToSubscription Adds a source identifier to an existing RDS event notification subscription. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:ApplyPendingMaintenanceAction Applies a pending maintenance action to a resource (for example, to a DB instance). arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:AuthorizeDBSecurityGroupIngress Enables ingress to a DBSecurityGroup using one of two forms of authorization. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag
rds:CopyDBClusterSnapshot Creates a snapshot of a DB cluster. arn:aws:rds:$region:$account-id:cluster-snapshot:$cluster-snapshot-name rds:cluster-snapshot-tag
rds:CopyDBParameterGroup Copies the specified DB parameter group. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:CopyDBSnapshot Copies the specified DB snapshot. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:CopyOptionGroup Copies the specified option group. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:CreateDBClusterParameterGroup Creates a new DB cluster parameter group. arn:aws:rds:$region:$account-id:cluster-pg:$cluster-parameter-group-name rds:cluster-pg-tag
rds:CreateDBClusterSnapshot Creates a snapshot of a DB cluster. arn:aws:rds:$region:$account-id:cluster:$db-cluster-name rds:cluster-tag
rds:CreateDBClusterSnapshot Creates a snapshot of a DB cluster. arn:aws:rds:$region:$account-id:cluster-snapshot:$cluster-snapshot-name rds:cluster-snapshot-tag
rds:CreateDBCluster ??? arn:aws:rds:$region:$account-id:cluster:$db-cluster-name rds:DatabaseEngine, rds:DatabaseName, rds:Vpc,
rds:cluster-tag
rds:CreateDBCluster Creates a new Amazon Aurora DB cluster. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:CreateDBCluster Creates a new Amazon Aurora DB cluster. arn:aws:rds:$region:$account-id:cluster-pg:$cluster-parameter-group-name rds:cluster-pg-tag
rds:CreateDBCluster Creates a new Amazon Aurora DB cluster. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:CreateDBInstance Creates a new DB instance. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:DatabaseClass, rds:DatabaseEngine, rds:DatabaseName, rds:MultiAz, rds:Piops, rds:StorageSize, rds:Vpc, rds:db-tag
rds:CreateDBInstance Creates a new DB instance. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:CreateDBInstance Creates a new DB instance. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:CreateDBInstance Creates a new DB instance. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag
rds:CreateDBInstance Creates a new DB instance. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:CreateDBInstanceReadReplica Creates a DB instance for a DB instance running MySQL, MariaDB, or PostgreSQL that acts as a Read Replica of a source DB instance. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:DatabaseClass, rds:Piops, rds:db-tag
rds:CreateDBInstanceReadReplica Creates a DB instance for a DB instance running MySQL, MariaDB, or PostgreSQL that acts as a Read Replica of a source DB instance. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:CreateDBInstanceReadReplica Creates a DB instance for a DB instance running MySQL, MariaDB, or PostgreSQL that acts as a Read Replica of a source DB instance. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:CreateDBParameterGroup Creates a new DB parameter group. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:CreateDBSecurityGroup Creates a new DB security group. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag
rds:CreateDBSnapshot Creates a DBSnapshot. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:CreateDBSnapshot Creates a DBSnapshot. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:CreateDBSubnetGroup Creates a new DB subnet group. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:CreateEventSubscription Creates an RDS event notification subscription. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:CreateOptionGroup Creates a new option group. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:DeleteDBClusterParameterGroup Deletes a specified DB cluster parameter group. arn:aws:rds:$region:$account-id:cluster-pg:$cluster-parameter-group-name rds:cluster-pg-tag
rds:DeleteDBClusterSnapshot Deletes a DB cluster snapshot. arn:aws:rds:$region:$account-id:cluster-snapshot:$cluster-snapshot-name rds:cluster-snapshot-tag
rds:DeleteDBCluster The DeleteDBCluster action deletes a previously provisioned DB cluster. arn:aws:rds:$region:$account-id:cluster:$db-cluster-name rds:cluster-tag
rds:DeleteDBCluster The DeleteDBCluster action deletes a previously provisioned DB cluster. arn:aws:rds:$region:$account-id:cluster-snapshot:$cluster-snapshot-name rds:cluster-snapshot-tag
rds:DeleteDBInstance The DeleteDBInstance action deletes a previously provisioned DB instance. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:DeleteDBParameterGroup Deletes a specified DBParameterGroup. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:DeleteDBSecurityGroup Deletes a DB security group. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag
rds:DeleteDBSnapshot Deletes a DBSnapshot. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:DeleteDBSubnetGroup Deletes a DB subnet group. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:DeleteEventSubscription Deletes an RDS event notification subscription. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:DeleteOptionGroup Deletes an existing option group. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:DescribeAccountAttributes Lists all of the attributes for a customer account. * -
rds:DescribeCertificates Lists the set of CA certificates provided by Amazon RDS for this AWS account. * -
rds:DescribeEngineDefaultClusterParameters Returns the default engine and system parameter information for the cluster database engine. * -
rds:DescribeEngineDefaultParameters Returns the default engine and system parameter information for the specified database engine. * -
rds:DescribeDBClusterParameterGroups Returns a list of DBClusterParameterGroup descriptions. arn:aws:rds:$region:$account-id:cluster-pg:$cluster-parameter-group-name rds:cluster-pg-tag
rds:DescribeDBClusterParameters Returns the detailed parameter list for a particular DB cluster parameter group. arn:aws:rds:$region:$account-id:cluster-pg:$cluster-parameter-group-name rds:cluster-pg-tag
rds:DescribeDBClusterSnapshots Returns information about DB cluster snapshots. ??? ???
rds:DescribeDBClusters Returns information about provisioned Aurora DB clusters. arn:aws:rds:$region:$account-id:cluster:$db-cluster-name rds:cluster-tag
rds:DescribeDBClusterSnapshotAttributes Returns a list of DB cluster snapshot attribute names and values for a manual DB cluster snapshot. arn:aws:rds:$region:$account-id:cluster-snapshot:$cluster-snapshot-name rds:cluster-snapshot-tag
rds:DescribeDBInstances Returns information about provisioned RDS instances. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:DescribeDBLogFiles Returns a list of DB log files for the DB instance. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:DescribeDBParameterGroups Returns a list of DBParameterGroup descriptions. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:DescribeDBParameters Returns the detailed parameter list for a particular DB parameter group. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:DescribeDBSecurityGroups Returns a list of DBSecurityGroup descriptions. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag
rds:DescribeDBSnapshotAttributes Returns a list of DB snapshot attribute names and values for a manual DB snapshot. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:DescribeDBSnapshots Returns information about DB snapshots. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:DescribeDBSnapshots Returns information about DB snapshots. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:DescribeDBEngineVersions Returns a list of the available DB engines. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:DescribeDBSubnetGroups Returns a list of DBSubnetGroup descriptions. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:DescribeEventCategories Displays a list of categories for all event source types, or, if specified, for a specified source type. * -
rds:DescribeEvents Returns events related to DB instances, DB security groups, DB snapshots, and DB parameter groups for the past 14 days. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:DescribeEventSubscriptions Lists all the subscription descriptions for a customer account. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:DescribeOptionGroups Describes the available option groups. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:DescribeOptionGroupOptions Describes all available options. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:DescribeOrderableDBInstanceOptions Returns a list of orderable DB instance options for the specified engine. * -
rds:DescribePendingMaintenanceActions Returns a list of resources (for example, DB instances) that have at least one pending maintenance action. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:DatabaseClass, rds:DatabaseEngine, rds:DatabaseName, rds:MultiAz, rds:Piops, rds:StorageSize, rds:Vpc, rds:db-tag
rds:DescribeReservedDBInstances Returns information about reserved DB instances for this account, or about a specified reserved DB instance. arn:aws:rds:$region:$account-id:ri:$reserved-db-instance-name rds:DatabaseClass, rds:MultiAz, rds:ri-tag
rds:DescribeReservedDBInstancesOfferings Lists available reserved DB instance offerings. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:DatabaseClass, rds:MultiAz
rds:DownloadDBLogFilePortion Downloads all or a portion of the specified log file, up to 1 MB in size. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:FailoverDBCluster Forces a failover for a DB cluster. arn:aws:rds:$region:$account-id:cluster:$db-cluster-name rds:cluster-tag
rds:ListTagsForResource Lists all tags on an Amazon RDS resource. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:ListTagsForResource Lists all tags on an Amazon RDS resource. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:ListTagsForResource Lists all tags on an Amazon RDS resource. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:ListTagsForResource Lists all tags on an Amazon RDS resource. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag
rds:ListTagsForResource Lists all tags on an Amazon RDS resource. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:ListTagsForResource Lists all tags on an Amazon RDS resource. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:ListTagsForResource Lists all tags on an Amazon RDS resource. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:ListTagsForResource Lists all tags on an Amazon RDS resource. arn:aws:rds:$region:$account-id:ri:$reserved-db-instance-name rds:ri-tag
rds:ModifyDBClusterParameterGroup arn:aws:rds:$region:$account-id:cluster-pg:$cluster-parameter-group-name rds:cluster-pg-tag
rds:ModifyDBClusterSnapshotAttribute Adds an attribute and values to, or removes an attribute and values from, a manual DB cluster snapshot. arn:aws:rds:$region:$account-id:cluster-snapshot:$cluster-snapshot-name rds:cluster-snapshot-tag
rds:ModifyDBCluster Modify a setting for an Amazon Aurora DB cluster. arn:aws:rds:$region:$account-id:cluster:$db-cluster-name rds:Vpc, rds:cluster-tag
rds:ModifyDBCluster Modify a setting for an Amazon Aurora DB cluster. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:ModifyDBCluster Modify a setting for an Amazon Aurora DB cluster. arn:aws:rds:$region:$account-id:cluster-pg:$cluster-parameter-group-name rds:cluster-pg-tag
rds:ModifyDBInstance Modify settings for a DB instance. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:DatabaseClass, rds:MultiAz, rds:Piops, rds:StorageSize, rds:Vpc, rds:db-tag
rds:ModifyDBInstance Modify settings for a DB instance. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:ModifyDBInstance Modify settings for a DB instance. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:ModifyDBInstance Modify settings for a DB instance. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag
rds:ModifyDBParameterGroup Modifies the parameters of a DB parameter group. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:ModifyDBSnapshotAttribute Adds an attribute and values to, or removes an attribute and values from, a manual DB snapshot. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:ModifyDBSubnetGroup Modifies an existing DB subnet group. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:ModifyEventSubscription Modifies an existing RDS event notification subscription. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:ModifyOptionGroup Modifies an existing option group. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:PromoteReadReplica Promotes a Read Replica DB instance to a standalone DB instance. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:PromoteReadReplicaDBCluster Promotes a Read Replica DB cluster to a standalone DB cluster. arn:aws:rds:$region:$account-id:cluster:$db-cluster-name -
rds:PurchaseReservedDBInstancesOffering Purchases a reserved DB instance offering. * -
rds:RebootDBInstance Rebooting a DB instance restarts the database engine service. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:RemoveSourceIdentifierFromSubscription Removes a source identifier from an existing RDS event notification subscription. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:RemoveTagsFromResource Removes metadata tags from an Amazon RDS resource. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:db-tag
rds:RemoveTagsFromResource Removes metadata tags from an Amazon RDS resource. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:RemoveTagsFromResource Removes metadata tags from an Amazon RDS resource. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:RemoveTagsFromResource Removes metadata tags from an Amazon RDS resource. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag
rds:RemoveTagsFromResource Removes metadata tags from an Amazon RDS resource. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:RemoveTagsFromResource Removes metadata tags from an Amazon RDS resource. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:RemoveTagsFromResource Removes metadata tags from an Amazon RDS resource. arn:aws:rds:$region:$account-id:es:$subscription-name rds:es-tag
rds:RemoveTagsFromResource Removes metadata tags from an Amazon RDS resource. arn:aws:rds:$region:$account-id:ri:$reserved-db-instance-name rds:ri-tag
rds:RestoreDBClusterFromSnapshot Creates a new DB cluster from a DB cluster snapshot. arn:aws:rds:$region:$account-id:cluster:$db-cluster-instance-name rds:DatabaseEngine, rds:DatabaseName, rds:Vpc, rds:cluster-tag
rds:RestoreDBClusterFromSnapshot Creates a new DB cluster from a DB cluster snapshot. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:RestoreDBClusterFromSnapshot Creates a new DB cluster from a DB cluster snapshot. arn:aws:rds:$region:$account-id:cluster-snapshot:$cluster-snapshot-name rds:cluster-snapshot-tag
rds:RestoreDBClusterToPointInTime Restores a DB cluster to an arbitrary point in time. arn:aws:rds:$region:$account-id:cluster:$db-cluster-instance-name rds:Vpc, rds:cluster-tag
rds:RestoreDBClusterToPointInTime Restores a DB cluster to an arbitrary point in time. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:RestoreDBClusterToPointInTime Restores a DB cluster to an arbitrary point in time. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:RestoreDBInstanceFromDBSnapshot Creates a new DB instance from a DB snapshot. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:DatabaseClass, rds:DatabaseEngine, rds:DatabaseName, rds:MultiAz, rds:Piops, rds:Vpc, rds:db-tag
rds:RestoreDBInstanceFromDBSnapshot Creates a new DB instance from a DB snapshot. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:RestoreDBInstanceFromDBSnapshot Creates a new DB instance from a DB snapshot. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:RestoreDBInstanceFromDBSnapshot Creates a new DB instance from a DB snapshot. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:RestoreDBInstanceToPointInTime Restores a DB instance to an arbitrary point in time. arn:aws:rds:$region:$account-id:db:$db-instance-name rds:DatabaseClass, rds:DatabaseEngine, rds:DatabaseName, rds:MultiAz, rds:Piops, rds:Vpc, rds:db-tag
rds:RestoreDBInstanceToPointInTime Restores a DB instance to an arbitrary point in time. arn:aws:rds:$region:$account-id:og:$option-group-name rds:og-tag
rds:RestoreDBInstanceToPointInTime Restores a DB instance to an arbitrary point in time. arn:aws:rds:$region:$account-id:snapshot:$snapshot-name rds:snapshot-tag
rds:RestoreDBInstanceToPointInTime Restores a DB instance to an arbitrary point in time. arn:aws:rds:$region:$account-id:subgrp:$subnet-group-name rds:subgrp-tag
rds:ResetDBClusterParameterGroup Modifies the parameters of a DB cluster parameter group to the default value. arn:aws:rds:$region:$account-id:cluster-pg:$cluster-parameter-group-name rds:cluster-pg-tag
rds:ResetDBParameterGroup Modifies the parameters of a DB parameter group to the engine/system default value. arn:aws:rds:$region:$account-id:pg:$parameter-group-name rds:pg-tag
rds:RevokeDBSecurityGroupIngress Revokes ingress from a DBSecurityGroup for previously authorized IP ranges or EC2 or VPC Security Groups. arn:aws:rds:$region:$account-id:secgrp:$security-group-name rds:secgrp-tag