Resource types that support Cloud Control API - Cloud Control API

Resource types that support Cloud Control API

The following table lists the public resource types published by AWS that currently support AWS Cloud Control API, organized by service. Each resource type name links to the corresponding reference topic for that resource type in the Resource and property types reference section of the AWS CloudFormation User Guide.

Third-party resource types, both public and private, support Cloud Control API.

For information about how to determine if a specific resource type supports Cloud Control API, see Determining if a resource type supports Cloud Control API. For more information about using resource types, see Using resource types.

Table last updated: March 01, 2024

Resource Create Read Update Delete List

AWS::AccessAnalyzer::Analyzer

Create

Read

Update

Delete

List

AWS::ACMPCA::Certificate

Create

Read

Update

Delete

AWS::ACMPCA::CertificateAuthority

Create

Read

Update

Delete

List

AWS::ACMPCA::CertificateAuthorityActivation

Create

Read

Update

Delete

AWS::ACMPCA::Permission

Create

Read

Delete

AWS::Amplify::App

Create

Read

Update

Delete

List

AWS::Amplify::Branch

Create

Read

Update

Delete

List

AWS::Amplify::Domain

Create

Read

Update

Delete

List

AWS::AmplifyUIBuilder::Component

Create

Read

Update

Delete

List

AWS::AmplifyUIBuilder::Form

Create

Read

Update

Delete

List

AWS::AmplifyUIBuilder::Theme

Create

Read

Update

Delete

List

AWS::ApiGateway::Account

Create

Read

Update

Delete

AWS::ApiGateway::ApiKey

Create

Read

Update

Delete

List

AWS::ApiGateway::Authorizer

Create

Read

Update

Delete

List

AWS::ApiGateway::BasePathMapping

Create

Read

Update

Delete

List

AWS::ApiGateway::ClientCertificate

Create

Read

Update

Delete

List

AWS::ApiGateway::Deployment

Create

Read

Update

Delete

List

AWS::ApiGateway::DocumentationPart

Create

Read

Update

Delete

List

AWS::ApiGateway::DocumentationVersion

Create

Read

Update

Delete

List

AWS::ApiGateway::DomainName

Create

Read

Update

Delete

List

AWS::ApiGateway::GatewayResponse

Create

Update

Delete

List

AWS::ApiGateway::Method

Create

Read

Update

Delete

AWS::ApiGateway::Model

Create

Read

Update

Delete

List

AWS::ApiGateway::RequestValidator

Create

Read

Update

Delete

List

AWS::ApiGateway::Resource

Create

Read

Update

Delete

List

AWS::ApiGateway::RestApi

Create

Read

Update

Delete

List

AWS::ApiGateway::Stage

Create

Read

Update

Delete

List

AWS::ApiGateway::UsagePlan

Create

Read

Update

Delete

List

AWS::ApiGateway::UsagePlanKey

Create

Read

Delete

List

AWS::ApiGateway::VpcLink

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::Api

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::ApiMapping

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::Authorizer

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::Deployment

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::DomainName

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::IntegrationResponse

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::Model

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::Route

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::RouteResponse

Create

Read

Update

Delete

List

AWS::ApiGatewayV2::VpcLink

Create

Read

Update

Delete

List

AWS::AppConfig::Application

Create

Read

Update

Delete

List

AWS::AppConfig::ConfigurationProfile

Create

Read

Update

Delete

List

AWS::AppConfig::Environment

Create

Read

Update

Delete

List

AWS::AppConfig::Extension

Create

Read

Update

Delete

List

AWS::AppConfig::ExtensionAssociation

Create

Read

Update

Delete

List

AWS::AppConfig::HostedConfigurationVersion

Create

Read

Delete

List

AWS::AppFlow::Connector

Create

Read

Update

Delete

List

AWS::AppFlow::ConnectorProfile

Create

Read

Update

Delete

List

AWS::AppFlow::Flow

Create

Read

Update

Delete

List

AWS::AppIntegrations::DataIntegration

Create

Read

Update

Delete

List

AWS::AppIntegrations::EventIntegration

Create

Read

Update

Delete

List

AWS::ApplicationAutoScaling::ScalableTarget

Create

Read

Update

Delete

List

AWS::ApplicationAutoScaling::ScalingPolicy

Create

Read

Update

Delete

List

AWS::ApplicationInsights::Application

Create

Read

Update

Delete

List

AWS::AppRunner::AutoScalingConfiguration

Create

Read

Delete

List

AWS::AppRunner::ObservabilityConfiguration

Create

Read

Delete

List

AWS::AppRunner::Service

Create

Read

Update

Delete

List

AWS::AppRunner::VpcConnector

Create

Read

Delete

List

AWS::AppRunner::VpcIngressConnection

Create

Read

Update

Delete

List

AWS::AppStream::AppBlock

Create

Read

Delete

AWS::AppStream::AppBlockBuilder

Create

Read

Update

Delete

List

AWS::AppStream::Application

Create

Read

Update

Delete

AWS::AppStream::ApplicationEntitlementAssociation

Create

Read

Delete

AWS::AppStream::ApplicationFleetAssociation

Create

Read

Delete

AWS::AppStream::DirectoryConfig

Create

Read

Update

Delete

List

AWS::AppStream::Entitlement

Create

Read

Update

Delete

AWS::AppStream::ImageBuilder

Create

Read

Delete

List

AWS::AppSync::DomainName

Create

Read

Update

Delete

List

AWS::AppSync::DomainNameApiAssociation

Create

Read

Update

Delete

AWS::AppSync::FunctionConfiguration

Create

Read

Update

Delete

List

AWS::AppSync::Resolver

Create

Read

Update

Delete

List

AWS::AppSync::SourceApiAssociation

Create

Read

Update

Delete

List

AWS::APS::RuleGroupsNamespace

Create

Read

Update

Delete

List

AWS::APS::Workspace

Create

Read

Update

Delete

List

AWS::ARCZonalShift::ZonalAutoshiftConfiguration

Create

Read

Update

Delete

List

AWS::Athena::CapacityReservation

Create

Read

Update

Delete

List

AWS::Athena::DataCatalog

Create

Read

Update

Delete

List

AWS::Athena::NamedQuery

Create

Read

Delete

List

AWS::Athena::PreparedStatement

Create

Read

Update

Delete

List

AWS::Athena::WorkGroup

Create

Read

Update

Delete

List

AWS::AuditManager::Assessment

Create

Read

Update

Delete

List

AWS::AutoScaling::AutoScalingGroup

Create

Read

Update

Delete

List

AWS::AutoScaling::LaunchConfiguration

Create

Read

Delete

List

AWS::AutoScaling::LifecycleHook

Create

Read

Update

Delete

List

AWS::AutoScaling::ScalingPolicy

Create

Read

Update

Delete

List

AWS::AutoScaling::ScheduledAction

Create

Read

Update

Delete

List

AWS::AutoScaling::WarmPool

Create

Read

Update

Delete

AWS::B2BI::Capability

Create

Read

Update

Delete

List

AWS::B2BI::Partnership

Create

Read

Update

Delete

List

AWS::B2BI::Profile

Create

Read

Update

Delete

List

AWS::B2BI::Transformer

Create

Read

Update

Delete

List

AWS::Backup::BackupPlan

Create

Read

Update

Delete

List

AWS::Backup::BackupSelection

Create

Read

Delete

List

AWS::Backup::BackupVault

Create

Read

Update

Delete

List

AWS::Backup::Framework

Create

Read

Update

Delete

List

AWS::Backup::ReportPlan

Create

Read

Update

Delete

List

AWS::Backup::RestoreTestingPlan

Create

Read

Update

Delete

List

AWS::Backup::RestoreTestingSelection

Create

Read

Update

Delete

List

AWS::BackupGateway::Hypervisor

Create

Read

Update

Delete

List

AWS::Batch::ComputeEnvironment

Create

Read

Update

Delete

List

AWS::Batch::JobQueue

Create

Read

Update

Delete

List

AWS::Batch::SchedulingPolicy

Create

Read

Update

Delete

List

AWS::BillingConductor::BillingGroup

Create

Read

Update

Delete

List

AWS::BillingConductor::CustomLineItem

Create

Read

Update

Delete

List

AWS::BillingConductor::PricingPlan

Create

Read

Update

Delete

List

AWS::BillingConductor::PricingRule

Create

Read

Update

Delete

List

AWS::Budgets::BudgetsAction

Create

Read

Update

Delete

List

AWS::Cassandra::Keyspace

Create

Read

Update

Delete

List

AWS::Cassandra::Table

Create

Read

Update

Delete

List

AWS::CE::AnomalyMonitor

Create

Read

Update

Delete

List

AWS::CE::AnomalySubscription

Create

Read

Update

Delete

List

AWS::CE::CostCategory

Create

Read

Update

Delete

List

AWS::CertificateManager::Account

Create

Read

Update

Delete

AWS::Chatbot::MicrosoftTeamsChannelConfiguration

Create

Read

Update

Delete

List

AWS::Chatbot::SlackChannelConfiguration

Create

Read

Update

Delete

List

AWS::CleanRooms::AnalysisTemplate

Create

Read

Update

Delete

List

AWS::CleanRooms::Collaboration

Create

Read

Update

Delete

List

AWS::CleanRooms::ConfiguredTable

Create

Read

Update

Delete

List

AWS::CleanRooms::ConfiguredTableAssociation

Create

Read

Update

Delete

List

AWS::CleanRooms::Membership

Create

Read

Update

Delete

List

AWS::CloudFormation::HookDefaultVersion

Create

Read

Update

Delete

List

AWS::CloudFormation::HookTypeConfig

Create

Read

Update

Delete

List

AWS::CloudFormation::HookVersion

Create

Read

Delete

List

AWS::CloudFormation::ModuleDefaultVersion

Create

Read

Delete

List

AWS::CloudFormation::ModuleVersion

Create

Read

Delete

AWS::CloudFormation::PublicTypeVersion

Create

Read

Delete

List

AWS::CloudFormation::Publisher

Create

Read

Delete

List

AWS::CloudFormation::ResourceDefaultVersion

Create

Read

Update

Delete

List

AWS::CloudFormation::ResourceVersion

Create

Read

Delete

List

AWS::CloudFormation::Stack

Create

Read

Update

Delete

List

AWS::CloudFormation::StackSet

Create

Read

Update

Delete

List

AWS::CloudFormation::TypeActivation

Create

Read

Update

Delete

List

AWS::CloudFront::CachePolicy

Create

Read

Update

Delete

List

AWS::CloudFront::CloudFrontOriginAccessIdentity

Create

Read

Update

Delete

List

AWS::CloudFront::ContinuousDeploymentPolicy

Create

Read

Update

Delete

List

AWS::CloudFront::Distribution

Create

Read

Update

Delete

List

AWS::CloudFront::Function

Create

Read

Update

Delete

List

AWS::CloudFront::KeyGroup

Create

Read

Update

Delete

List

AWS::CloudFront::KeyValueStore

Create

Read

Update

Delete

List

AWS::CloudFront::MonitoringSubscription

Create

Read

Delete

AWS::CloudFront::OriginAccessControl

Create

Read

Update

Delete

List

AWS::CloudFront::OriginRequestPolicy

Create

Read

Update

Delete

List

AWS::CloudFront::PublicKey

Create

Read

Update

Delete

List

AWS::CloudFront::RealtimeLogConfig

Create

Read

Update

Delete

List

AWS::CloudFront::ResponseHeadersPolicy

Create

Read

Update

Delete

List

AWS::CloudTrail::Channel

Create

Read

Update

Delete

List

AWS::CloudTrail::EventDataStore

Create

Read

Update

Delete

List

AWS::CloudTrail::ResourcePolicy

Create

Read

Update

Delete

AWS::CloudTrail::Trail

Create

Read

Update

Delete

List

AWS::CloudWatch::Alarm

Create

Read

Update

Delete

List

AWS::CloudWatch::CompositeAlarm

Create

Read

Update

Delete

List

AWS::CloudWatch::MetricStream

Create

Read

Update

Delete

List

AWS::CodeArtifact::Domain

Create

Read

Update

Delete

List

AWS::CodeArtifact::Repository

Create

Read

Update

Delete

List

AWS::CodeBuild::Fleet

Create

Read

Update

Delete

List

AWS::CodeDeploy::Application

Create

Read

Update

Delete

List

AWS::CodeDeploy::DeploymentConfig

Create

Read

Delete

List

AWS::CodeGuruProfiler::ProfilingGroup

Create

Read

Update

Delete

List

AWS::CodeGuruReviewer::RepositoryAssociation

Create

Read

Delete

List

AWS::CodePipeline::CustomActionType

Create

Read

Update

Delete

List

AWS::CodeStarConnections::Connection

Create

Read

Update

Delete

List

AWS::CodeStarConnections::RepositoryLink

Create

Read

Update

Delete

List

AWS::CodeStarConnections::SyncConfiguration

Create

Read

Update

Delete

List

AWS::CodeStarNotifications::NotificationRule

Create

Read

Update

Delete

List

AWS::Cognito::IdentityPool

Create

Read

Update

Delete

List

AWS::Cognito::IdentityPoolPrincipalTag

Create

Read

Update

Delete

List

AWS::Cognito::IdentityPoolRoleAttachment

Create

Read

Update

Delete

List

AWS::Cognito::LogDeliveryConfiguration

Create

Read

Update

Delete

AWS::Cognito::UserPool

Create

Read

Update

Delete

List

AWS::Cognito::UserPoolClient

Create

Read

Update

Delete

List

AWS::Cognito::UserPoolGroup

Create

Read

Update

Delete

List

AWS::Cognito::UserPoolRiskConfigurationAttachment

Create

Read

Update

Delete

AWS::Cognito::UserPoolUser

Create

Read

Delete

List

AWS::Cognito::UserPoolUserToGroupAttachment

Create

Read

Delete

AWS::Comprehend::DocumentClassifier

Create

Read

Update

Delete

List

AWS::Comprehend::Flywheel

Create

Read

Update

Delete

List

AWS::Config::AggregationAuthorization

Create

Read

Update

Delete

List

AWS::Config::ConfigRule

Create

Read

Update

Delete

List

AWS::Config::ConfigurationAggregator

Create

Read

Update

Delete

List

AWS::Config::ConformancePack

Create

Read

Update

Delete

List

AWS::Config::OrganizationConformancePack

Create

Read

Update

Delete

List

AWS::Config::StoredQuery

Create

Read

Update

Delete

List

AWS::Connect::ApprovedOrigin

Create

Read

Update

Delete

List

AWS::Connect::ContactFlow

Create

Read

Update

Delete

List

AWS::Connect::ContactFlowModule

Create

Read

Update

Delete

List

AWS::Connect::EvaluationForm

Create

Read

Update

Delete

List

AWS::Connect::HoursOfOperation

Create

Read

Update

Delete

List

AWS::Connect::Instance

Create

Read

Update

Delete

List

AWS::Connect::InstanceStorageConfig

Create

Read

Update

Delete

List

AWS::Connect::IntegrationAssociation

Create

Read

Update

Delete

List

AWS::Connect::PhoneNumber

Create

Read

Update

Delete

List

AWS::Connect::PredefinedAttribute

Create

Read

Update

Delete

List

AWS::Connect::Prompt

Create

Read

Update

Delete

List

AWS::Connect::Queue

Create

Read

Update

Delete

List

AWS::Connect::QuickConnect

Create

Read

Update

Delete

List

AWS::Connect::RoutingProfile

Create

Read

Update

Delete

List

AWS::Connect::Rule

Create

Read

Update

Delete

AWS::Connect::SecurityKey

Create

Read

Update

Delete

List

AWS::Connect::SecurityProfile

Create

Read

Update

Delete

List

AWS::Connect::TaskTemplate

Create

Read

Update

Delete

List

AWS::Connect::TrafficDistributionGroup

Create

Read

Update

Delete

List

AWS::Connect::User

Create

Read

Update

Delete

List

AWS::Connect::UserHierarchyGroup

Create

Read

Update

Delete

List

AWS::Connect::View

Create

Read

Update

Delete

List

AWS::Connect::ViewVersion

Create

Read

Update

Delete

List

AWS::ConnectCampaigns::Campaign

Create

Read

Update

Delete

List

AWS::ControlTower::EnabledBaseline

Create

Read

Update

Delete

List

AWS::ControlTower::EnabledControl

Create

Read

Update

Delete

List

AWS::ControlTower::LandingZone

Create

Read

Update

Delete

List

AWS::CUR::ReportDefinition

Create

Read

Update

Delete

List

AWS::CustomerProfiles::CalculatedAttributeDefinition

Create

Read

Update

Delete

List

AWS::CustomerProfiles::Domain

Create

Read

Update

Delete

List

AWS::CustomerProfiles::EventStream

Create

Read

Update

Delete

List

AWS::CustomerProfiles::Integration

Create

Read

Update

Delete

List

AWS::CustomerProfiles::ObjectType

Create

Read

Update

Delete

List

AWS::DataBrew::Dataset

Create

Read

Update

Delete

List

AWS::DataBrew::Job

Create

Read

Update

Delete

List

AWS::DataBrew::Project

Create

Read

Update

Delete

List

AWS::DataBrew::Recipe

Create

Read

Update

Delete

List

AWS::DataBrew::Ruleset

Create

Read

Update

Delete

List

AWS::DataBrew::Schedule

Create

Read

Update

Delete

List

AWS::DataPipeline::Pipeline

Create

Read

Update

Delete

List

AWS::DataSync::Agent

Create

Read

Update

Delete

List

AWS::DataSync::LocationAzureBlob

Create

Read

Update

Delete

List

AWS::DataSync::LocationEFS

Create

Read

Update

Delete

List

AWS::DataSync::LocationFSxLustre

Create

Read

Update

Delete

List

AWS::DataSync::LocationFSxONTAP

Create

Read

Update

Delete

List

AWS::DataSync::LocationFSxOpenZFS

Create

Read

Update

Delete

List

AWS::DataSync::LocationFSxWindows

Create

Read

Update

Delete

List

AWS::DataSync::LocationHDFS

Create

Read

Update

Delete

List

AWS::DataSync::LocationNFS

Create

Read

Update

Delete

List

AWS::DataSync::LocationObjectStorage

Create

Read

Update

Delete

List

AWS::DataSync::LocationS3

Create

Read

Update

Delete

List

AWS::DataSync::LocationSMB

Create

Read

Update

Delete

List

AWS::DataSync::StorageSystem

Create

Read

Update

Delete

List

AWS::DataSync::Task

Create

Read

Update

Delete

List

AWS::DataZone::DataSource

Create

Read

Update

Delete

List

AWS::DataZone::Domain

Create

Read

Update

Delete

List

AWS::DataZone::Environment

Create

Read

Update

Delete

List

AWS::DataZone::EnvironmentBlueprintConfiguration

Create

Read

Update

Delete

List

AWS::DataZone::EnvironmentProfile

Create

Read

Update

Delete

List

AWS::DataZone::Project

Create

Read

Update

Delete

List

AWS::DataZone::SubscriptionTarget

Create

Read

Update

Delete

List

AWS::Detective::Graph

Create

Read

Update

Delete

List

AWS::Detective::MemberInvitation

Create

Read

Update

Delete

List

AWS::Detective::OrganizationAdmin

Create

Read

Update

Delete

List

AWS::DeviceFarm::DevicePool

Create

Read

Update

Delete

List

AWS::DeviceFarm::InstanceProfile

Create

Read

Update

Delete

List

AWS::DeviceFarm::NetworkProfile

Create

Read

Update

Delete

List

AWS::DeviceFarm::Project

Create

Read

Update

Delete

List

AWS::DeviceFarm::TestGridProject

Create

Read

Update

Delete

List

AWS::DeviceFarm::VPCEConfiguration

Create

Read

Update

Delete

List

AWS::DevOpsGuru::LogAnomalyDetectionIntegration

Create

Read

Update

Delete

List

AWS::DevOpsGuru::NotificationChannel

Create

Read

Delete

List

AWS::DevOpsGuru::ResourceCollection

Create

Read

Update

Delete

List

AWS::DirectoryService::SimpleAD

Create

Read

Update

Delete

List

AWS::DMS::DataProvider

Create

Read

Update

Delete

List

AWS::DMS::InstanceProfile

Create

Read

Update

Delete

List

AWS::DMS::MigrationProject

Create

Read

Update

Delete

List

AWS::DMS::ReplicationConfig

Create

Read

Update

Delete

List

AWS::DocDBElastic::Cluster

Create

Read

Update

Delete

List

AWS::DynamoDB::GlobalTable

Create

Read

Update

Delete

List

AWS::DynamoDB::Table

Create

Read

Update

Delete

List

AWS::EC2::CapacityReservation

Create

Read

Update

Delete

List

AWS::EC2::CapacityReservationFleet

Create

Read

Update

Delete

List

AWS::EC2::CarrierGateway

Create

Read

Update

Delete

List

AWS::EC2::CustomerGateway

Create

Read

Update

Delete

List

AWS::EC2::DHCPOptions

Create

Read

Update

Delete

List

AWS::EC2::EC2Fleet

Create

Read

Update

Delete

List

AWS::EC2::EgressOnlyInternetGateway

Create

Read

Delete

List

AWS::EC2::EIP

Create

Read

Update

Delete

List

AWS::EC2::EIPAssociation

Create

Read

Delete

List

AWS::EC2::EnclaveCertificateIamRoleAssociation

Create

Read

Delete

List

AWS::EC2::FlowLog

Create

Read

Update

Delete

List

AWS::EC2::GatewayRouteTableAssociation

Create

Read

Update

Delete

AWS::EC2::Host

Create

Read

Update

Delete

List

AWS::EC2::InstanceConnectEndpoint

Create

Read

Update

Delete

List

AWS::EC2::InternetGateway

Create

Read

Update

Delete

List

AWS::EC2::IPAM

Create

Read

Update

Delete

List

AWS::EC2::IPAMAllocation

Create

Read

Delete

List

AWS::EC2::IPAMPool

Create

Read

Update

Delete

List

AWS::EC2::IPAMPoolCidr

Create

Read

Delete

List

AWS::EC2::IPAMResourceDiscovery

Create

Read

Update

Delete

List

AWS::EC2::IPAMResourceDiscoveryAssociation

Create

Read

Update

Delete

List

AWS::EC2::IPAMScope

Create

Read

Update

Delete

List

AWS::EC2::KeyPair

Create

Read

Delete

List

AWS::EC2::LaunchTemplate

Create

Read

Update

Delete

List

AWS::EC2::LocalGatewayRoute

Create

Read

Update

Delete

List

AWS::EC2::LocalGatewayRouteTable

Create

Read

Update

Delete

List

AWS::EC2::LocalGatewayRouteTableVirtualInterfaceGroupAssociation

Create

Read

Update

Delete

List

AWS::EC2::LocalGatewayRouteTableVPCAssociation

Create

Read

Update

Delete

List

AWS::EC2::NatGateway

Create

Read

Update

Delete

List

AWS::EC2::NetworkAcl

Create

Read

Update

Delete

List

AWS::EC2::NetworkAclEntry

Create

Update

Delete

AWS::EC2::NetworkInsightsAccessScope

Create

Read

Update

Delete

List

AWS::EC2::NetworkInsightsAccessScopeAnalysis

Create

Read

Update

Delete

List

AWS::EC2::NetworkInsightsAnalysis

Create

Read

Update

Delete

List

AWS::EC2::NetworkInsightsPath

Create

Read

Update

Delete

List

AWS::EC2::NetworkInterface

Create

Read

Update

Delete

List

AWS::EC2::NetworkInterfaceAttachment

Create

Read

Update

Delete

List

AWS::EC2::NetworkPerformanceMetricSubscription

Create

Read

Delete

List

AWS::EC2::PlacementGroup

Create

Read

Delete

List

AWS::EC2::PrefixList

Create

Read

Update

Delete

List

AWS::EC2::Route

Create

Read

Update

Delete

List

AWS::EC2::RouteTable

Create

Read

Update

Delete

List

AWS::EC2::SecurityGroupEgress

Create

Read

Update

Delete

List

AWS::EC2::SecurityGroupIngress

Create

Read

Update

Delete

List

AWS::EC2::SnapshotBlockPublicAccess

Create

Read

Update

Delete

List

AWS::EC2::SpotFleet

Create

Read

Update

Delete

List

AWS::EC2::Subnet

Create

Read

Update

Delete

List

AWS::EC2::SubnetCidrBlock

Create

Read

Delete

List

AWS::EC2::SubnetNetworkAclAssociation

Create

Read

Delete

List

AWS::EC2::SubnetRouteTableAssociation

Create

Read

Delete

List

AWS::EC2::TransitGateway

Create

Read

Update

Delete

List

AWS::EC2::TransitGatewayAttachment

Create

Read

Update

Delete

List

AWS::EC2::TransitGatewayConnect

Create

Read

Update

Delete

List

AWS::EC2::TransitGatewayMulticastDomain

Create

Read

Update

Delete

List

AWS::EC2::TransitGatewayMulticastDomainAssociation

Create

Read

Delete

List

AWS::EC2::TransitGatewayMulticastGroupMember

Create

Read

Delete

List

AWS::EC2::TransitGatewayMulticastGroupSource

Create

Read

Delete

List

AWS::EC2::TransitGatewayPeeringAttachment

Create

Read

Update

Delete

List

AWS::EC2::TransitGatewayRouteTable

Create

Read

Delete

List

AWS::EC2::TransitGatewayVpcAttachment

Create

Read

Update

Delete

List

AWS::EC2::VerifiedAccessEndpoint

Create

Read

Update

Delete

List

AWS::EC2::VerifiedAccessGroup

Create

Read

Update

Delete

List

AWS::EC2::VerifiedAccessInstance

Create

Read

Update

Delete

List

AWS::EC2::VerifiedAccessTrustProvider

Create

Read

Update

Delete

List

AWS::EC2::Volume

Create

Read

Update

Delete

List

AWS::EC2::VolumeAttachment

Create

Read

Delete

List

AWS::EC2::VPC

Create

Read

Update

Delete

List

AWS::EC2::VPCDHCPOptionsAssociation

Create

Read

Update

Delete

List

AWS::EC2::VPCEndpoint

Create

Read

Update

Delete

List

AWS::EC2::VPCEndpointConnectionNotification

Create

Read

Update

Delete

List

AWS::EC2::VPCEndpointService

Create

Read

Update

Delete

List

AWS::EC2::VPCEndpointServicePermissions

Create

Read

Update

Delete

List

AWS::EC2::VPCGatewayAttachment

Create

Read

Update

Delete

List

AWS::EC2::VPCPeeringConnection

Create

Read

Update

Delete

List

AWS::EC2::VPNConnection

Create

Read

Update

Delete

List

AWS::EC2::VPNConnectionRoute

Create

Read

Delete

List

AWS::EC2::VPNGateway

Create

Read

Update

Delete

List

AWS::ECR::PublicRepository

Create

Read

Update

Delete

List

AWS::ECR::PullThroughCacheRule

Create

Read

Update

Delete

List

AWS::ECR::RegistryPolicy

Create

Read

Update

Delete

List

AWS::ECR::ReplicationConfiguration

Create

Read

Update

Delete

List

AWS::ECR::Repository

Create

Read

Update

Delete

List

AWS::ECS::CapacityProvider

Create

Read

Update

Delete

List

AWS::ECS::Cluster

Create

Read

Update

Delete

List

AWS::ECS::ClusterCapacityProviderAssociations

Create

Read

Update

Delete

List

AWS::ECS::PrimaryTaskSet

Create

Read

Update

Delete

AWS::ECS::Service

Create

Read

Update

Delete

List

AWS::ECS::TaskDefinition

Create

Read

Update

Delete

List

AWS::ECS::TaskSet

Create

Read

Update

Delete

AWS::EFS::AccessPoint

Create

Read

Update

Delete

List

AWS::EFS::FileSystem

Create

Read

Update

Delete

List

AWS::EFS::MountTarget

Create

Read

Update

Delete

List

AWS::EKS::AccessEntry

Create

Read

Update

Delete

List

AWS::EKS::Addon

Create

Read

Update

Delete

List

AWS::EKS::Cluster

Create

Read

Update

Delete

List

AWS::EKS::FargateProfile

Create

Read

Update

Delete

List

AWS::EKS::IdentityProviderConfig

Create

Read

Update

Delete

List

AWS::EKS::Nodegroup

Create

Read

Update

Delete

List

AWS::EKS::PodIdentityAssociation

Create

Read

Update

Delete

List

AWS::ElastiCache::GlobalReplicationGroup

Create

Read

Update

Delete

List

AWS::ElastiCache::ServerlessCache

Create

Read

Update

Delete

List

AWS::ElastiCache::SubnetGroup

Create

Read

Update

Delete

List

AWS::ElastiCache::User

Create

Read

Update

Delete

List

AWS::ElastiCache::UserGroup

Create

Read

Update

Delete

List

AWS::ElasticBeanstalk::Application

Create

Read

Update

Delete

List

AWS::ElasticBeanstalk::ApplicationVersion

Create

Read

Update

Delete

List

AWS::ElasticBeanstalk::ConfigurationTemplate

Create

Read

Update

Delete

List

AWS::ElasticBeanstalk::Environment

Create

Read

Update

Delete

List

AWS::ElasticLoadBalancingV2::Listener

Create

Read

Update

Delete

List

AWS::ElasticLoadBalancingV2::ListenerRule

Create

Read

Update

Delete

List

AWS::ElasticLoadBalancingV2::LoadBalancer

Create

Read

Update

Delete

List

AWS::ElasticLoadBalancingV2::TargetGroup

Create

Read

Update

Delete

List

AWS::ElasticLoadBalancingV2::TrustStore

Create

Read

Update

Delete

List

AWS::ElasticLoadBalancingV2::TrustStoreRevocation

Create

Read

Delete

List

AWS::EMR::SecurityConfiguration

Create

Read

Delete

List

AWS::EMR::Step

Create

Delete

AWS::EMR::Studio

Create

Read

Update

Delete

List

AWS::EMR::StudioSessionMapping

Create

Read

Update

Delete

List

AWS::EMR::WALWorkspace

Create

Read

Update

Delete

List

AWS::EMRContainers::VirtualCluster

Create

Read

Update

Delete

List

AWS::EMRServerless::Application

Create

Read

Update

Delete

List

AWS::EntityResolution::IdMappingWorkflow

Create

Read

Update

Delete

List

AWS::EntityResolution::MatchingWorkflow

Create

Read

Update

Delete

List

AWS::EntityResolution::SchemaMapping

Create

Read

Update

Delete

List

AWS::Events::ApiDestination

Create

Read

Update

Delete

List

AWS::Events::Archive

Create

Read

Update

Delete

List

AWS::Events::Connection

Create

Read

Update

Delete

List

AWS::Events::Endpoint

Create

Read

Update

Delete

List

AWS::Events::EventBus

Create

Read

Update

Delete

List

AWS::Events::Rule

Create

Read

Update

Delete

List

AWS::EventSchemas::Discoverer

Create

Read

Update

Delete

List

AWS::EventSchemas::Registry

Create

Read

Update

Delete

List

AWS::EventSchemas::RegistryPolicy

Create

Read

Update

Delete

AWS::EventSchemas::Schema

Create

Read

Update

Delete

List

AWS::Evidently::Experiment

Create

Read

Update

Delete

AWS::Evidently::Feature

Create

Read

Update

Delete

AWS::Evidently::Launch

Create

Read

Update

Delete

AWS::Evidently::Project

Create

Read

Update

Delete

AWS::Evidently::Segment

Create

Read

Delete

List

AWS::FinSpace::Environment

Create

Read

Update

Delete

List

AWS::FIS::ExperimentTemplate

Create

Read

Update

Delete

List

AWS::FIS::TargetAccountConfiguration

Create

Read

Update

Delete

List

AWS::FMS::NotificationChannel

Create

Read

Update

Delete

List

AWS::FMS::Policy

Create

Read

Update

Delete

List

AWS::FMS::ResourceSet

Create

Read

Update

Delete

List

AWS::Forecast::Dataset

Create

Read

Delete

List

AWS::Forecast::DatasetGroup

Create

Read

Update

Delete

List

AWS::FraudDetector::Detector

Create

Read

Update

Delete

List

AWS::FraudDetector::EntityType

Create

Read

Update

Delete

List

AWS::FraudDetector::EventType

Create

Read

Update

Delete

List

AWS::FraudDetector::Label

Create

Read

Update

Delete

List

AWS::FraudDetector::List

Create

Read

Update

Delete

List

AWS::FraudDetector::Outcome

Create

Read

Update

Delete

List

AWS::FraudDetector::Variable

Create

Read

Update

Delete

List

AWS::FSx::DataRepositoryAssociation

Create

Read

Update

Delete

List

AWS::GameLift::Alias

Create

Read

Update

Delete

List

AWS::GameLift::Build

Create

Read

Update

Delete

List

AWS::GameLift::Fleet

Create

Read

Update

Delete

List

AWS::GameLift::GameServerGroup

Create

Read

Update

Delete

List

AWS::GameLift::GameSessionQueue

Create

Read

Update

Delete

List

AWS::GameLift::Location

Create

Read

Update

Delete

List

AWS::GameLift::MatchmakingConfiguration

Create

Read

Update

Delete

List

AWS::GameLift::MatchmakingRuleSet

Create

Read

Update

Delete

List

AWS::GameLift::Script

Create

Read

Update

Delete

List

AWS::GlobalAccelerator::Accelerator

Create

Read

Update

Delete

List

AWS::GlobalAccelerator::EndpointGroup

Create

Read

Update

Delete

List

AWS::GlobalAccelerator::Listener

Create

Read

Update

Delete

List

AWS::Glue::Registry

Create

Read

Update

Delete

List

AWS::Glue::Schema

Create

Read

Update

Delete

List

AWS::Glue::SchemaVersion

Create

Read

Delete

List

AWS::Glue::SchemaVersionMetadata

Create

Read

Delete

List

AWS::Grafana::Workspace

Create

Read

Update

Delete

List

AWS::GreengrassV2::ComponentVersion

Create

Read

Update

Delete

List

AWS::GreengrassV2::Deployment

Create

Read

Update

Delete

List

AWS::GroundStation::Config

Create

Read

Update

Delete

List

AWS::GroundStation::DataflowEndpointGroup

Create

Read

Delete

List

AWS::GroundStation::MissionProfile

Create

Read

Update

Delete

List

AWS::GuardDuty::Detector

Create

Read

Update

Delete

List

AWS::GuardDuty::Filter

Create

Read

Update

Delete

List

AWS::GuardDuty::IPSet

Create

Read

Update

Delete

List

AWS::GuardDuty::Master

Create

Read

Delete

List

AWS::GuardDuty::Member

Create

Read

Update

Delete

List

AWS::GuardDuty::ThreatIntelSet

Create

Read

Update

Delete

List

AWS::HealthImaging::Datastore

Create

Read

Delete

List

AWS::HealthLake::FHIRDatastore

Create

Read

Update

Delete

List

AWS::IAM::Group

Create

Read

Update

Delete

List

AWS::IAM::GroupPolicy

Create

Read

Update

Delete

AWS::IAM::InstanceProfile

Create

Read

Update

Delete

List

AWS::IAM::ManagedPolicy

Create

Read

Update

Delete

List

AWS::IAM::OIDCProvider

Create

Read

Update

Delete

List

AWS::IAM::Policy

Create

Update

Delete

AWS::IAM::Role

Create

Read

Update

Delete

List

AWS::IAM::RolePolicy

Create

Read

Update

Delete

AWS::IAM::SAMLProvider

Create

Read

Update

Delete

List

AWS::IAM::ServerCertificate

Create

Read

Update

Delete

List

AWS::IAM::ServiceLinkedRole

Create

Read

Update

Delete

AWS::IAM::User

Create

Read

Update

Delete

List

AWS::IAM::UserPolicy

Create

Read

Update

Delete

AWS::IAM::VirtualMFADevice

Create

Read

Update

Delete

List

AWS::IdentityStore::Group

Create

Read

Update

Delete

List

AWS::IdentityStore::GroupMembership

Create

Read

Delete

List

AWS::ImageBuilder::Component

Create

Read

Delete

List

AWS::ImageBuilder::ContainerRecipe

Create

Read

Delete

List

AWS::ImageBuilder::DistributionConfiguration

Create

Read

Update

Delete

List

AWS::ImageBuilder::Image

Create

Read

Delete

List

AWS::ImageBuilder::ImagePipeline

Create

Read

Update

Delete

List

AWS::ImageBuilder::ImageRecipe

Create

Read

Delete

List

AWS::ImageBuilder::InfrastructureConfiguration

Create

Read

Update

Delete

List

AWS::ImageBuilder::LifecyclePolicy

Create

Read

Update

Delete

List

AWS::ImageBuilder::Workflow

Create

Read

Delete

List

AWS::Inspector::AssessmentTarget

Create

Read

Update

Delete

List

AWS::Inspector::AssessmentTemplate

Create

Read

Delete

List

AWS::Inspector::ResourceGroup

Create

Read

Delete

AWS::InspectorV2::CisScanConfiguration

Create

Read

Update

Delete

List

AWS::InspectorV2::Filter

Create

Read

Update

Delete

List

AWS::InternetMonitor::Monitor

Create

Read

Update

Delete

List

AWS::IoT::AccountAuditConfiguration

Create

Read

Update

Delete

List

AWS::IoT::Authorizer

Create

Read

Update

Delete

List

AWS::IoT::BillingGroup

Create

Read

Update

Delete

List

AWS::IoT::CACertificate

Create

Read

Update

Delete

List

AWS::IoT::Certificate

Create

Read

Update

Delete

List

AWS::IoT::CertificateProvider

Create

Read

Update

Delete

List

AWS::IoT::CustomMetric

Create

Read

Update

Delete

List

AWS::IoT::Dimension

Create

Read

Update

Delete

List

AWS::IoT::DomainConfiguration

Create

Read

Update

Delete

List

AWS::IoT::FleetMetric

Create

Read

Update

Delete

List

AWS::IoT::JobTemplate

Create

Read

Delete

List

AWS::IoT::Logging

Create

Read

Update

Delete

List

AWS::IoT::MitigationAction

Create

Read

Update

Delete

List

AWS::IoT::Policy

Create

Read

Update

Delete

List

AWS::IoT::ProvisioningTemplate

Create

Read

Update

Delete

List

AWS::IoT::ResourceSpecificLogging

Create

Read

Update

Delete

List

AWS::IoT::RoleAlias

Create

Read

Update

Delete

List

AWS::IoT::ScheduledAudit

Create

Read

Update

Delete

List

AWS::IoT::SecurityProfile

Create

Read

Update

Delete

List

AWS::IoT::SoftwarePackage

Create

Read

Update

Delete

List

AWS::IoT::SoftwarePackageVersion

Create

Read

Update

Delete

List

AWS::IoT::Thing

Create

Read

Update

Delete

List

AWS::IoT::ThingGroup

Create

Read

Update

Delete

List

AWS::IoT::ThingType

Create

Read

Update

Delete

List

AWS::IoT::TopicRule

Create

Read

Update

Delete

List

AWS::IoT::TopicRuleDestination

Create

Read

Update

Delete

List

AWS::IoTAnalytics::Channel

Create

Read

Update

Delete

List

AWS::IoTAnalytics::Dataset

Create

Read

Update

Delete

List

AWS::IoTAnalytics::Datastore

Create

Read

Update

Delete

List

AWS::IoTAnalytics::Pipeline

Create

Read

Update

Delete

List

AWS::IoTCoreDeviceAdvisor::SuiteDefinition

Create

Read

Update

Delete

List

AWS::IoTEvents::AlarmModel

Create

Read

Update

Delete

List

AWS::IoTEvents::DetectorModel

Create

Read

Update

Delete

List

AWS::IoTEvents::Input

Create

Read

Update

Delete

List

AWS::IoTFleetHub::Application

Create

Read

Update

Delete

List

AWS::IoTFleetWise::Campaign

Create

Read

Update

Delete

List

AWS::IoTFleetWise::DecoderManifest

Create

Read

Update

Delete

List

AWS::IoTFleetWise::Fleet

Create

Read

Update

Delete

List

AWS::IoTFleetWise::ModelManifest

Create

Read

Update

Delete

List

AWS::IoTFleetWise::SignalCatalog

Create

Read

Update

Delete

List

AWS::IoTFleetWise::Vehicle

Create

Read

Update

Delete

List

AWS::IoTSiteWise::AccessPolicy

Create

Read

Update

Delete

List

AWS::IoTSiteWise::Asset

Create

Read

Update

Delete

List

AWS::IoTSiteWise::AssetModel

Create

Read

Update

Delete

List

AWS::IoTSiteWise::Dashboard

Create

Read

Update

Delete

List

AWS::IoTSiteWise::Gateway

Create

Read

Update

Delete

List

AWS::IoTSiteWise::Portal

Create

Read

Update

Delete

List

AWS::IoTSiteWise::Project

Create

Read

Update

Delete

List

AWS::IoTTwinMaker::ComponentType

Create

Read

Update

Delete

List

AWS::IoTTwinMaker::Entity

Create

Read

Update

Delete

List

AWS::IoTTwinMaker::Scene

Create

Read

Update

Delete

List

AWS::IoTTwinMaker::SyncJob

Create

Read

Delete

List

AWS::IoTTwinMaker::Workspace

Create

Read

Update

Delete

List

AWS::IoTWireless::Destination

Create

Read

Update

Delete

List

AWS::IoTWireless::DeviceProfile

Create

Read

Delete

List

AWS::IoTWireless::FuotaTask

Create

Read

Update

Delete

List

AWS::IoTWireless::MulticastGroup

Create

Read

Update

Delete

List

AWS::IoTWireless::NetworkAnalyzerConfiguration

Create

Read

Update

Delete

List

AWS::IoTWireless::PartnerAccount

Create

Read

Update

Delete

List

AWS::IoTWireless::ServiceProfile

Create

Read

Delete

List

AWS::IoTWireless::TaskDefinition

Create

Read

Delete

List

AWS::IoTWireless::WirelessDevice

Create

Read

Update

Delete

List

AWS::IoTWireless::WirelessDeviceImportTask

Create

Read

Update

Delete

List

AWS::IoTWireless::WirelessGateway

Create

Read

Update

Delete

List

AWS::IVS::Channel

Create

Read

Update

Delete

List

AWS::IVS::PlaybackKeyPair

Create

Read

Update

Delete

List

AWS::IVS::RecordingConfiguration

Create

Read

Update

Delete

List

AWS::IVS::Stage

Create

Read

Update

Delete

List

AWS::IVS::StreamKey

Create

Read

Update

Delete

List

AWS::IVSChat::LoggingConfiguration

Create

Read

Update

Delete

List

AWS::IVSChat::Room

Create

Read

Update

Delete

List

AWS::KafkaConnect::Connector

Create

Read

Update

Delete

List

AWS::Kendra::DataSource

Create

Read

Update

Delete

List

AWS::Kendra::Faq

Create

Read

Update

Delete

List

AWS::Kendra::Index

Create

Read

Update

Delete

List

AWS::KendraRanking::ExecutionPlan

Create

Read

Update

Delete

List

AWS::Kinesis::Stream

Create

Read

Update

Delete

List

AWS::KinesisAnalyticsV2::Application

Create

Read

Update

Delete

List

AWS::KinesisFirehose::DeliveryStream

Create

Read

Update

Delete

List

AWS::KinesisVideo::SignalingChannel

Create

Read

Update

Delete

AWS::KinesisVideo::Stream

Create

Read

Update

Delete

AWS::KMS::Alias

Create

Read

Update

Delete

List

AWS::KMS::Key

Create

Read

Update

Delete

List

AWS::KMS::ReplicaKey

Create

Read

Update

Delete

List

AWS::LakeFormation::DataCellsFilter

Create

Read

Delete

List

AWS::LakeFormation::PrincipalPermissions

Create

Read

Delete

AWS::LakeFormation::Tag

Create

Read

Update

Delete

List

AWS::LakeFormation::TagAssociation

Create

Read

Delete

AWS::Lambda::CodeSigningConfig

Create

Read

Update

Delete

List

AWS::Lambda::EventInvokeConfig

Create

Read

Update

Delete

List

AWS::Lambda::EventSourceMapping

Create

Read

Update

Delete

List

AWS::Lambda::Function

Create

Read

Update

Delete

List

AWS::Lambda::LayerVersion

Create

Read

Delete

List

AWS::Lambda::LayerVersionPermission

Create

Read

Delete

List

AWS::Lambda::Permission

Create

Read

Delete

List

AWS::Lambda::Url

Create

Read

Update

Delete

List

AWS::Lambda::Version

Create

Read

Update

Delete

List

AWS::Lex::Bot

Create

Read

Update

Delete

List

AWS::Lex::BotAlias

Create

Read

Update

Delete

List

AWS::Lex::BotVersion

Create

Read

Delete

List

AWS::Lex::ResourcePolicy

Create

Read

Update

Delete

List

AWS::LicenseManager::Grant

Create

Read

Update

Delete

List

AWS::LicenseManager::License

Create

Read

Update

Delete

List

AWS::Lightsail::Alarm

Create

Read

Update

Delete

List

AWS::Lightsail::Bucket

Create

Read

Update

Delete

List

AWS::Lightsail::Certificate

Create

Read

Update

Delete

List

AWS::Lightsail::Container

Create

Read

Update

Delete

List

AWS::Lightsail::Database

Create

Read

Update

Delete

List

AWS::Lightsail::Disk

Create

Read

Update

Delete

List

AWS::Lightsail::Distribution

Create

Read

Update

Delete

List

AWS::Lightsail::Instance

Create

Read

Update

Delete

List

AWS::Lightsail::LoadBalancer

Create

Read

Update

Delete

List

AWS::Lightsail::LoadBalancerTlsCertificate

Create

Read

Update

Delete

List

AWS::Lightsail::StaticIp

Create

Read

Update

Delete

List

AWS::Location::APIKey

Create

Read

Update

Delete

List

AWS::Location::GeofenceCollection

Create

Read

Update

Delete

List

AWS::Location::Map

Create

Read

Update

Delete

List

AWS::Location::PlaceIndex

Create

Read

Update

Delete

List

AWS::Location::RouteCalculator

Create

Read

Update

Delete

List

AWS::Location::Tracker

Create

Read

Update

Delete

List

AWS::Location::TrackerConsumer

Create

Read

Delete

List

AWS::Logs::AccountPolicy

Create

Read

Update

Delete

List

AWS::Logs::Delivery

Create

Read

Update

Delete

List

AWS::Logs::DeliveryDestination

Create

Read

Update

Delete

List

AWS::Logs::DeliverySource

Create

Read

Update

Delete

List

AWS::Logs::Destination

Create

Read

Update

Delete

List

AWS::Logs::LogAnomalyDetector

Create

Read

Update

Delete

List

AWS::Logs::LogGroup

Create

Read

Update

Delete

List

AWS::Logs::LogStream

Create

Read

Delete

List

AWS::Logs::MetricFilter

Create

Read

Update

Delete

List

AWS::Logs::QueryDefinition

Create

Read

Update

Delete

List

AWS::Logs::ResourcePolicy

Create

Read

Update

Delete

List

AWS::Logs::SubscriptionFilter

Create

Read

Update

Delete

List

AWS::LookoutEquipment::InferenceScheduler

Create

Read

Update

Delete

List

AWS::LookoutMetrics::Alert

Create

Read

Delete

List

AWS::LookoutMetrics::AnomalyDetector

Create

Read

Update

Delete

List

AWS::LookoutVision::Project

Create

Read

Update

Delete

List

AWS::M2::Application

Create

Read

Update

Delete

List

AWS::M2::Environment

Create

Read

Update

Delete

List

AWS::Macie::AllowList

Create

Read

Update

Delete

List

AWS::Macie::CustomDataIdentifier

Create

Read

Update

Delete

List

AWS::Macie::FindingsFilter

Create

Read

Update

Delete

List

AWS::Macie::Session

Create

Read

Update

Delete

List

AWS::ManagedBlockchain::Accessor

Create

Read

Update

Delete

List

AWS::MediaConnect::Bridge

Create

Read

Update

Delete

List

AWS::MediaConnect::BridgeOutput

Create

Read

Update

Delete

AWS::MediaConnect::BridgeSource

Create

Read

Update

Delete

AWS::MediaConnect::Flow

Create

Read

Update

Delete

List

AWS::MediaConnect::FlowEntitlement

Create

Read

Update

Delete

List

AWS::MediaConnect::FlowOutput

Create

Read

Update

Delete

List

AWS::MediaConnect::FlowSource

Create

Read

Update

Delete

List

AWS::MediaConnect::FlowVpcInterface

Create

Read

Update

Delete

List

AWS::MediaConnect::Gateway

Create

Read

Delete

List

AWS::MediaLive::Multiplex

Create

Read

Update

Delete

List

AWS::MediaLive::Multiplexprogram

Create

Read

Update

Delete

List

AWS::MediaPackage::Asset

Create

Read

Delete

List

AWS::MediaPackage::Channel

Create

Read

Update

Delete

List

AWS::MediaPackage::OriginEndpoint

Create

Read

Update

Delete

List

AWS::MediaPackage::PackagingConfiguration

Create

Read

Delete

List

AWS::MediaPackage::PackagingGroup

Create

Read

Update

Delete

List

AWS::MediaPackageV2::Channel

Create

Read

Update

Delete

List

AWS::MediaPackageV2::ChannelGroup

Create

Read

Update

Delete

List

AWS::MediaPackageV2::ChannelPolicy

Create

Read

Update

Delete

AWS::MediaPackageV2::OriginEndpoint

Create

Read

Update

Delete

List

AWS::MediaPackageV2::OriginEndpointPolicy

Create

Read

Update

Delete

AWS::MediaTailor::Channel

Create

Read

Update

Delete

List

AWS::MediaTailor::ChannelPolicy

Create

Read

Update

Delete

AWS::MediaTailor::LiveSource

Create

Read

Update

Delete

List

AWS::MediaTailor::PlaybackConfiguration

Create

Read

Update

Delete

List

AWS::MediaTailor::SourceLocation

Create

Read

Update

Delete

List

AWS::MediaTailor::VodSource

Create

Read

Update

Delete

List

AWS::MemoryDB::ACL

Create

Read

Update

Delete

List

AWS::MemoryDB::Cluster

Create

Read

Update

Delete

List

AWS::MemoryDB::ParameterGroup

Create

Read

Update

Delete

List

AWS::MemoryDB::SubnetGroup

Create

Read

Update

Delete

List

AWS::MemoryDB::User

Create

Read

Update

Delete

List

AWS::MSK::BatchScramSecret

Create

Read

Update

Delete

List

AWS::MSK::Cluster

Create

Read

Update

Delete

List

AWS::MSK::ClusterPolicy

Create

Read

Update

Delete

List

AWS::MSK::Configuration

Create

Read

Update

Delete

List

AWS::MSK::Replicator

Create

Read

Update

Delete

List

AWS::MSK::ServerlessCluster

Create

Read

Delete

List

AWS::MSK::VpcConnection

Create

Read

Update

Delete

List

AWS::MWAA::Environment

Create

Read

Update

Delete

List

AWS::Neptune::DBCluster

Create

Read

Update

Delete

List

AWS::NeptuneGraph::Graph

Create

Read

Update

Delete

List

AWS::NeptuneGraph::PrivateGraphEndpoint

Create

Read

Update

Delete

List

AWS::NetworkFirewall::Firewall

Create

Read

Update

Delete

List

AWS::NetworkFirewall::FirewallPolicy

Create

Read

Update

Delete

List

AWS::NetworkFirewall::LoggingConfiguration

Create

Read

Update

Delete

List

AWS::NetworkFirewall::RuleGroup

Create

Read

Update

Delete

List

AWS::NetworkFirewall::TLSInspectionConfiguration

Create

Read

Update

Delete

List

AWS::NetworkManager::ConnectAttachment

Create

Read

Update

Delete

List

AWS::NetworkManager::ConnectPeer

Create

Read

Update

Delete

List

AWS::NetworkManager::CoreNetwork

Create

Read

Update

Delete

List

AWS::NetworkManager::CustomerGatewayAssociation

Create

Read

Delete

List

AWS::NetworkManager::Device

Create

Read

Update

Delete

List

AWS::NetworkManager::GlobalNetwork

Create

Read

Update

Delete

List

AWS::NetworkManager::Link

Create

Read

Update

Delete

List

AWS::NetworkManager::LinkAssociation

Create

Read

Delete

List

AWS::NetworkManager::Site

Create

Read

Update

Delete

List

AWS::NetworkManager::SiteToSiteVpnAttachment

Create

Read

Update

Delete

List

AWS::NetworkManager::TransitGatewayPeering

Create

Read

Update

Delete

List

AWS::NetworkManager::TransitGatewayRegistration

Create

Read

Delete

List

AWS::NetworkManager::TransitGatewayRouteTableAttachment

Create

Read

Update

Delete

List

AWS::NetworkManager::VpcAttachment

Create

Read

Update

Delete

List

AWS::NimbleStudio::LaunchProfile

Create

Read

Update

Delete

List

AWS::NimbleStudio::StreamingImage

Create

Read

Update

Delete

List

AWS::NimbleStudio::Studio

Create

Read

Update

Delete

List

AWS::NimbleStudio::StudioComponent

Create

Read

Update

Delete

List

AWS::Oam::Link

Create

Read

Update

Delete

List

AWS::Oam::Sink

Create

Read

Update

Delete

List

AWS::Omics::AnnotationStore

Create

Read

Update

Delete

List

AWS::Omics::ReferenceStore

Create

Read

Delete

List

AWS::Omics::RunGroup

Create

Read

Update

Delete

List

AWS::Omics::SequenceStore

Create

Read

Delete

List

AWS::Omics::VariantStore

Create

Read

Update

Delete

List

AWS::Omics::Workflow

Create

Read

Update

Delete

List

AWS::OpenSearchServerless::AccessPolicy

Create

Read

Update

Delete

List

AWS::OpenSearchServerless::Collection

Create

Read

Update

Delete

List

AWS::OpenSearchServerless::LifecyclePolicy

Create

Read

Update

Delete

List

AWS::OpenSearchServerless::SecurityConfig

Create

Read

Update

Delete

List

AWS::OpenSearchServerless::SecurityPolicy

Create

Read

Update

Delete

List

AWS::OpenSearchServerless::VpcEndpoint

Create

Read

Update

Delete

List

AWS::OpenSearchService::Domain

Create

Read

Update

Delete

AWS::OpsWorksCM::Server

Create

Read

Update

Delete

List

AWS::Organizations::Account

Create

Read

Update

Delete

List

AWS::Organizations::Organization

Create

Read

Update

Delete

List

AWS::Organizations::OrganizationalUnit

Create

Read

Update

Delete

List

AWS::Organizations::Policy

Create

Read

Update

Delete

List

AWS::Organizations::ResourcePolicy

Create

Read

Update

Delete

List

AWS::OSIS::Pipeline

Create

Read

Update

Delete

List

AWS::Panorama::ApplicationInstance

Create

Read

Update

Delete

List

AWS::Panorama::Package

Create

Read

Update

Delete

List

AWS::Panorama::PackageVersion

Create

Read

Update

Delete

AWS::PCAConnectorAD::Connector

Create

Read

Update

Delete

List

AWS::PCAConnectorAD::DirectoryRegistration

Create

Read

Update

Delete

List

AWS::PCAConnectorAD::ServicePrincipalName

Create

Read

Delete

List

AWS::PCAConnectorAD::Template

Create

Read

Update

Delete

List

AWS::PCAConnectorAD::TemplateGroupAccessControlEntry

Create

Read

Update

Delete

List

AWS::Personalize::Dataset

Create

Read

Update

Delete

List

AWS::Personalize::DatasetGroup

Create

Read

Delete

List

AWS::Personalize::Schema

Create

Read

Delete

List

AWS::Personalize::Solution

Create

Read

Delete

List

AWS::Pinpoint::InAppTemplate

Create

Read

Update

Delete

List

AWS::Pipes::Pipe

Create

Read

Update

Delete

List

AWS::Proton::EnvironmentAccountConnection

Create

Read

Update

Delete

List

AWS::Proton::EnvironmentTemplate

Create

Read

Update

Delete

List

AWS::Proton::ServiceTemplate

Create

Read

Update

Delete

List

AWS::QLDB::Stream

Create

Read

Update

Delete

List

AWS::QuickSight::Analysis

Create

Read

Update

Delete

List

AWS::QuickSight::Dashboard

Create

Read

Update

Delete

List

AWS::QuickSight::DataSet

Create

Read

Update

Delete

List

AWS::QuickSight::DataSource

Create

Read

Update

Delete

List

AWS::QuickSight::RefreshSchedule

Create

Read

Update

Delete

List

AWS::QuickSight::Template

Create

Read

Update

Delete

List

AWS::QuickSight::Theme

Create

Read

Update

Delete

List

AWS::QuickSight::Topic

Create

Read

Update

Delete

List

AWS::QuickSight::VPCConnection

Create

Read

Update

Delete

List

AWS::RAM::Permission

Create

Read

Update

Delete

List

AWS::RDS::CustomDBEngineVersion

Create

Read

Update

Delete

List

AWS::RDS::DBCluster

Create

Read

Update

Delete

List

AWS::RDS::DBClusterParameterGroup

Create

Read

Update

Delete

List

AWS::RDS::DBInstance

Create

Read

Update

Delete

List

AWS::RDS::DBParameterGroup

Create

Read

Update

Delete

List

AWS::RDS::DBProxy

Create

Read

Update

Delete

List

AWS::RDS::DBProxyEndpoint

Create

Read

Update

Delete

List

AWS::RDS::DBProxyTargetGroup

Create

Read

Update

Delete

List

AWS::RDS::DBSubnetGroup

Create

Read

Update

Delete

List

AWS::RDS::EventSubscription

Create

Read

Update

Delete

List

AWS::RDS::GlobalCluster

Create

Read

Update

Delete

List

AWS::RDS::Integration

Create

Read

Update

Delete

List

AWS::RDS::OptionGroup

Create

Read

Update

Delete

List

AWS::Redshift::Cluster

Create

Read

Update

Delete

List

AWS::Redshift::ClusterParameterGroup

Create

Read

Update

Delete

List

AWS::Redshift::ClusterSubnetGroup

Create

Read

Update

Delete

List

AWS::Redshift::EndpointAccess

Create

Read

Update

Delete

List

AWS::Redshift::EndpointAuthorization

Create

Read

Update

Delete

List

AWS::Redshift::EventSubscription

Create

Read

Update

Delete

List

AWS::Redshift::ScheduledAction

Create

Read

Update

Delete

List

AWS::RedshiftServerless::Namespace

Create

Read

Update

Delete

List

AWS::RedshiftServerless::Workgroup

Create

Read

Update

Delete

List

AWS::RefactorSpaces::Application

Create

Read

Delete

List

AWS::RefactorSpaces::Environment

Create

Read

Delete

List

AWS::RefactorSpaces::Route

Create

Read

Update

Delete

List

AWS::RefactorSpaces::Service

Create

Read

Delete

List

AWS::Rekognition::Collection

Create

Read

Update

Delete

List

AWS::Rekognition::Project

Create

Read

Update

Delete

List

AWS::Rekognition::StreamProcessor

Create

Read

Update

Delete

List

AWS::ResilienceHub::App

Create

Read

Update

Delete

List

AWS::ResilienceHub::ResiliencyPolicy

Create

Read

Update

Delete

List

AWS::ResourceExplorer2::DefaultViewAssociation

Create

Read

Update

Delete

AWS::ResourceExplorer2::Index

Create

Read

Update

Delete

List

AWS::ResourceExplorer2::View

Create

Read

Update

Delete

List

AWS::ResourceGroups::Group

Create

Read

Update

Delete

List

AWS::RoboMaker::Fleet

Create

Read

Update

Delete

List

AWS::RoboMaker::Robot

Create

Read

Update

Delete

List

AWS::RoboMaker::RobotApplication

Create

Read

Update

Delete

List

AWS::RoboMaker::RobotApplicationVersion

Create

Read

Delete

AWS::RoboMaker::SimulationApplication

Create

Read

Update

Delete

List

AWS::RoboMaker::SimulationApplicationVersion

Create

Read

Delete

AWS::RolesAnywhere::CRL

Create

Read

Update

Delete

List

AWS::RolesAnywhere::Profile

Create

Read

Update

Delete

List

AWS::RolesAnywhere::TrustAnchor

Create

Read

Update

Delete

List

AWS::Route53::CidrCollection

Create

Read

Update

Delete

List

AWS::Route53::DNSSEC

Create

Read

Delete

List

AWS::Route53::HealthCheck

Create

Read

Update

Delete

List

AWS::Route53::HostedZone

Create

Read

Update

Delete

List

AWS::Route53::KeySigningKey

Create

Read

Update

Delete

List

AWS::Route53RecoveryControl::Cluster

Create

Read

Delete

List

AWS::Route53RecoveryControl::ControlPanel

Create

Read

Update

Delete

List

AWS::Route53RecoveryControl::RoutingControl

Create

Read

Update

Delete

List

AWS::Route53RecoveryControl::SafetyRule

Create

Read

Update

Delete

List

AWS::Route53RecoveryReadiness::Cell

Create

Read

Update

Delete

List

AWS::Route53RecoveryReadiness::ReadinessCheck

Create

Read

Update

Delete

List

AWS::Route53RecoveryReadiness::RecoveryGroup

Create

Read

Update

Delete

List

AWS::Route53RecoveryReadiness::ResourceSet

Create

Read

Update

Delete

List

AWS::Route53Resolver::FirewallDomainList

Create

Read

Update

Delete

List

AWS::Route53Resolver::FirewallRuleGroup

Create

Read

Update

Delete

List

AWS::Route53Resolver::FirewallRuleGroupAssociation

Create

Read

Update

Delete

List

AWS::Route53Resolver::OutpostResolver

Create

Read

Update

Delete

List

AWS::Route53Resolver::ResolverConfig

Create

Read

Delete

List

AWS::Route53Resolver::ResolverDNSSECConfig

Create

Read

Delete

List

AWS::Route53Resolver::ResolverQueryLoggingConfig

Create

Read

Delete

List

AWS::Route53Resolver::ResolverQueryLoggingConfigAssociation

Create

Read

Delete

List

AWS::Route53Resolver::ResolverRule

Create

Read

Update

Delete

List

AWS::Route53Resolver::ResolverRuleAssociation

Create

Read

Delete

List

AWS::RUM::AppMonitor

Create

Read

Update

Delete

List

AWS::S3::AccessGrant

Create

Read

Update

Delete

List

AWS::S3::AccessGrantsInstance

Create

Read

Update

Delete

List

AWS::S3::AccessGrantsLocation

Create

Read

Update

Delete

List

AWS::S3::AccessPoint

Create

Read

Update

Delete

List

AWS::S3::Bucket

Create

Read

Update

Delete

List

AWS::S3::BucketPolicy

Create

Read

Update

Delete

List

AWS::S3::MultiRegionAccessPoint

Create

Read

Delete

List

AWS::S3::MultiRegionAccessPointPolicy

Create

Read

Update

Delete

List

AWS::S3::StorageLens

Create

Read

Update

Delete

List

AWS::S3::StorageLensGroup

Create

Read

Update

Delete

List

AWS::S3Express::BucketPolicy

Create

Read

Update

Delete

List

AWS::S3Express::DirectoryBucket

Create

Read

Delete

List

AWS::S3ObjectLambda::AccessPoint

Create

Read

Update

Delete

List

AWS::S3ObjectLambda::AccessPointPolicy

Create

Read

Update

Delete

AWS::S3Outposts::AccessPoint

Create

Read

Update

Delete

List

AWS::S3Outposts::Bucket

Create

Read

Update

Delete

List

AWS::S3Outposts::BucketPolicy

Create

Read

Update

Delete

AWS::S3Outposts::Endpoint

Create

Read

Delete

List

AWS::SageMaker::App

Create

Read

Delete

List

AWS::SageMaker::AppImageConfig

Create

Read

Update

Delete

List

AWS::SageMaker::DataQualityJobDefinition

Create

Read

Delete

List

AWS::SageMaker::Device

Create

Read

Update

Delete

AWS::SageMaker::DeviceFleet

Create

Read

Update

Delete

AWS::SageMaker::Domain

Create

Read

Update

Delete

List

AWS::SageMaker::FeatureGroup

Create

Read

Update

Delete

List

AWS::SageMaker::Image

Create

Read

Update

Delete

List

AWS::SageMaker::ImageVersion

Create

Read

Update

Delete

List

AWS::SageMaker::InferenceComponent

Create

Read

Update

Delete

List

AWS::SageMaker::InferenceExperiment

Create

Read

Update

Delete

List

AWS::SageMaker::ModelBiasJobDefinition

Create

Read

Delete

List

AWS::SageMaker::ModelCard

Create

Read

Update

Delete

List

AWS::SageMaker::ModelExplainabilityJobDefinition

Create

Read

Delete

List

AWS::SageMaker::ModelPackage

Create

Read

Update

Delete

List

AWS::SageMaker::ModelPackageGroup

Create

Read

Update

Delete

List

AWS::SageMaker::ModelQualityJobDefinition

Create

Read

Delete

List

AWS::SageMaker::MonitoringSchedule

Create

Read

Update

Delete

List

AWS::SageMaker::Pipeline

Create

Read

Update

Delete

List

AWS::SageMaker::Project

Create

Read

Update

Delete

List

AWS::SageMaker::Space

Create

Read

Update

Delete

List

AWS::SageMaker::UserProfile

Create

Read

Update

Delete

List

AWS::Scheduler::Schedule

Create

Read

Update

Delete

List

AWS::Scheduler::ScheduleGroup

Create

Read

Update

Delete

List

AWS::SecretsManager::Secret

Create

Read

Update

Delete

List

AWS::SecurityHub::AutomationRule

Create

Read

Update

Delete

List

AWS::SecurityHub::Hub

Create

Read

Update

Delete

List

AWS::SecurityHub::Standard

Create

Read

Update

Delete

List

AWS::ServiceCatalog::CloudFormationProvisionedProduct

Create

Read

Update

Delete

AWS::ServiceCatalog::ServiceAction

Create

Read

Update

Delete

List

AWS::ServiceCatalog::ServiceActionAssociation

Create

Read

Delete

List

AWS::ServiceCatalogAppRegistry::Application

Create

Read

Update

Delete

List

AWS::ServiceCatalogAppRegistry::AttributeGroup

Create

Read

Update

Delete

List

AWS::ServiceCatalogAppRegistry::AttributeGroupAssociation

Create

Read

Delete

List

AWS::ServiceCatalogAppRegistry::ResourceAssociation

Create

Read

Delete

List

AWS::SES::ConfigurationSet

Create

Read

Update

Delete

List

AWS::SES::ConfigurationSetEventDestination

Create

Read

Update

Delete

AWS::SES::ContactList

Create

Read

Update

Delete

List

AWS::SES::DedicatedIpPool

Create

Read

Update

Delete

List

AWS::SES::EmailIdentity

Create

Read

Update

Delete

List

AWS::SES::Template

Create

Read

Update

Delete

List

AWS::SES::VdmAttributes

Create

Read

Update

Delete

AWS::Shield::DRTAccess

Create

Read

Update

Delete

List

AWS::Shield::ProactiveEngagement

Create

Read

Update

Delete

List

AWS::Shield::Protection

Create

Read

Update

Delete

List

AWS::Shield::ProtectionGroup

Create

Read

Update

Delete

List

AWS::Signer::ProfilePermission

Create

Read

Delete

List

AWS::Signer::SigningProfile

Create

Read

Update

Delete

List

AWS::SimSpaceWeaver::Simulation

Create

Read

Update

Delete

List

AWS::SNS::Topic

Create

Read

Update

Delete

List

AWS::SNS::TopicInlinePolicy

Create

Read

Update

Delete

AWS::SNS::TopicPolicy

Create

Update

Delete

AWS::SQS::Queue

Create

Read

Update

Delete

List

AWS::SQS::QueueInlinePolicy

Create

Read

Update

Delete

AWS::SQS::QueuePolicy

Create

Update

Delete

AWS::SSM::Association

Create

Read

Update

Delete

List

AWS::SSM::Document

Create

Read

Update

Delete

List

AWS::SSM::Parameter

Create

Read

Update

Delete

List

AWS::SSM::PatchBaseline

Create

Read

Update

Delete

List

AWS::SSM::ResourceDataSync

Create

Read

Update

Delete

List

AWS::SSM::ResourcePolicy

Create

Read

Update

Delete

List

AWS::SSMContacts::Contact

Create

Read

Update

Delete

List

AWS::SSMContacts::ContactChannel

Create

Read

Update

Delete

List

AWS::SSMContacts::Plan

Create

Read

Update

Delete

AWS::SSMContacts::Rotation

Create

Read

Update

Delete

List

AWS::SSMGuiConnect::Preferences

Create

Read

Update

Delete

List

AWS::SSMIncidents::ReplicationSet

Create

Read

Update

Delete

List

AWS::SSMIncidents::ResponsePlan

Create

Read

Update

Delete

List

AWS::SSO::Assignment

Create

Read

Delete

List

AWS::SSO::InstanceAccessControlAttributeConfiguration

Create

Read

Update

Delete

List

AWS::SSO::PermissionSet

Create

Read

Update

Delete

List

AWS::StepFunctions::Activity

Create

Read

Update

Delete

AWS::StepFunctions::StateMachine

Create

Read

Update

Delete

List

AWS::StepFunctions::StateMachineAlias

Create

Read

Update

Delete

List

AWS::StepFunctions::StateMachineVersion

Create

Read

Delete

List

AWS::SupportApp::AccountAlias

Create

Read

Update

Delete

List

AWS::SupportApp::SlackChannelConfiguration

Create

Read

Update

Delete

List

AWS::SupportApp::SlackWorkspaceConfiguration

Create

Read

Update

Delete

List

AWS::Synthetics::Canary

Create

Read

Update

Delete

List

AWS::Synthetics::Group

Create

Read

Update

Delete

List

AWS::SystemsManagerSAP::Application

Create

Read

Update

Delete

List

AWS::Timestream::Database

Create

Read

Update

Delete

List

AWS::Timestream::ScheduledQuery

Create

Read

Update

Delete

List

AWS::Timestream::Table

Create

Read

Update

Delete

List

AWS::Transfer::Agreement

Create

Read

Update

Delete

List

AWS::Transfer::Certificate

Create

Read

Update

Delete

List

AWS::Transfer::Connector

Create

Read

Update

Delete

List

AWS::Transfer::Profile

Create

Read

Update

Delete

List

AWS::Transfer::Workflow

Create

Read

Update

Delete

List

AWS::VerifiedPermissions::IdentitySource

Create

Read

Update

Delete

List

AWS::VerifiedPermissions::Policy

Create

Read

Update

Delete

List

AWS::VerifiedPermissions::PolicyStore

Create

Read

Update

Delete

List

AWS::VerifiedPermissions::PolicyTemplate

Create

Read

Update

Delete

List

AWS::VoiceID::Domain

Create

Read

Update

Delete

List

AWS::VpcLattice::AccessLogSubscription

Create

Read

Update

Delete

List

AWS::VpcLattice::AuthPolicy

Create

Read

Update

Delete

AWS::VpcLattice::Listener

Create

Read

Update

Delete

List

AWS::VpcLattice::ResourcePolicy

Create

Read

Update

Delete

AWS::VpcLattice::Rule

Create

Read

Update

Delete

List

AWS::VpcLattice::Service

Create

Read

Update

Delete

List

AWS::VpcLattice::ServiceNetwork

Create

Read

Update

Delete

List

AWS::VpcLattice::ServiceNetworkServiceAssociation

Create

Read

Update

Delete

List

AWS::VpcLattice::ServiceNetworkVpcAssociation

Create

Read

Update

Delete

List

AWS::VpcLattice::TargetGroup

Create

Read

Update

Delete

List

AWS::WAFv2::IPSet

Create

Read

Update

Delete

List

AWS::WAFv2::LoggingConfiguration

Create

Read

Update

Delete

List

AWS::WAFv2::RegexPatternSet

Create

Read

Update

Delete

List

AWS::WAFv2::RuleGroup

Create

Read

Update

Delete

List

AWS::WAFv2::WebACL

Create

Read

Update

Delete

List

AWS::WAFv2::WebACLAssociation

Create

Read

Update

Delete

AWS::Wisdom::Assistant

Create

Read

Update

Delete

List

AWS::Wisdom::AssistantAssociation

Create

Read

Update

Delete

List

AWS::Wisdom::KnowledgeBase

Create

Read

Update

Delete

List

AWS::WorkSpaces::ConnectionAlias

Create

Read

Delete

AWS::WorkSpacesThinClient::Environment

Create

Read

Update

Delete

List

AWS::WorkSpacesWeb::BrowserSettings

Create

Read

Update

Delete

List

AWS::WorkSpacesWeb::IdentityProvider

Create

Read

Update

Delete

List

AWS::WorkSpacesWeb::IpAccessSettings

Create

Read

Update

Delete

List

AWS::WorkSpacesWeb::NetworkSettings

Create

Read

Update

Delete

List

AWS::WorkSpacesWeb::Portal

Create

Read

Update

Delete

List

AWS::WorkSpacesWeb::TrustStore

Create

Read

Update

Delete

List

AWS::WorkSpacesWeb::UserAccessLoggingSettings

Create

Read

Update

Delete

List

AWS::WorkSpacesWeb::UserSettings

Create

Read

Update

Delete

List

AWS::XRay::Group

Create

Read

Update

Delete

List

AWS::XRay::ResourcePolicy

Create

Read

Update

Delete

List

AWS::XRay::SamplingRule

Create

Read

Update

Delete

List