ROSAImageRegistryOperatorPolicy - AWS Managed Policy

ROSAImageRegistryOperatorPolicy

Description: Allows the OpenShift Image Registry Operator to provision and manage Amazon S3 buckets and objects for use by the Red Hat OpenShift Service on AWS (ROSA) in-cluster image registry to satisfy ROSA storage requirements. The OpenShift Image Registry Operator installs and maintains the internal registry of a Red Hat OpenShift cluster.

ROSAImageRegistryOperatorPolicy is an AWS managed policy.

Using this policy

You can attach ROSAImageRegistryOperatorPolicy to your users, groups, and roles.

Policy details

  • Type: Service role policy

  • Creation time: April 27, 2023, 20:13 UTC

  • Edited time: December 12, 2023, 19:53 UTC

  • ARN: arn:aws:iam::aws:policy/service-role/ROSAImageRegistryOperatorPolicy

Policy version

Policy version: v2 (default)

The policy's default version is the version that defines the permissions for the policy. When a user or role with the policy makes a request to access an AWS resource, AWS checks the default version of the policy to determine whether to allow the request.

JSON policy document

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "ListBuckets", "Effect" : "Allow", "Action" : [ "s3:ListBucket", "s3:ListBucketMultipartUploads" ], "Resource" : "*" }, { "Sid" : "AllowSpecificBucketActions", "Effect" : "Allow", "Action" : [ "s3:CreateBucket", "s3:DeleteBucket", "s3:GetBucketTagging", "s3:GetBucketPublicAccessBlock", "s3:GetEncryptionConfiguration", "s3:GetLifecycleConfiguration", "s3:GetBucketLocation", "s3:PutBucketPublicAccessBlock", "s3:PutBucketTagging", "s3:PutEncryptionConfiguration", "s3:PutLifecycleConfiguration" ], "Resource" : [ "arn:aws:s3:::*-image-registry-${aws:RequestedRegion}-*", "arn:aws:s3:::*-image-registry-${aws:RequestedRegion}" ] }, { "Sid" : "AllowSpecificObjectActions", "Effect" : "Allow", "Action" : [ "s3:AbortMultipartUpload", "s3:DeleteObject", "s3:GetObject", "s3:ListMultipartUploadParts", "s3:PutObject" ], "Resource" : [ "arn:aws:s3:::*-image-registry-${aws:RequestedRegion}-*/*", "arn:aws:s3:::*-image-registry-${aws:RequestedRegion}/*" ] } ] }

Learn more