AmazonRDSCustomInstanceProfileRolePolicy - AWS Política gestionada

Las traducciones son generadas a través de traducción automática. En caso de conflicto entre la traducción y la version original de inglés, prevalecerá la version en inglés.

AmazonRDSCustomInstanceProfileRolePolicy

Descripción: Permite a Amazon RDS Custom realizar diversas acciones de automatización y tareas de administración de bases de datos a través de un perfil de instancia EC2.

AmazonRDSCustomInstanceProfileRolePolicyes una política AWS gestionada.

Uso de la política

Puede asociar AmazonRDSCustomInstanceProfileRolePolicy a los usuarios, grupos y roles.

Información de la política

  • Tipo: política AWS gestionada

  • Hora de creación: 27 de febrero de 2024 a las 17:42 UTC

  • Hora editada: 27 de febrero de 2024 a las 17:42 UTC

  • ARN: arn:aws:iam::aws:policy/AmazonRDSCustomInstanceProfileRolePolicy

Versión de la política

Versión de la política: v1 (predeterminada)

La versión predeterminada de la política define qué permisos tendrá. Cuando un usuario o un rol con la política solicita el acceso a un AWS recurso, AWS comprueba la versión predeterminada de la política para determinar si permite la solicitud.

Documento de política JSON

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "ssmAgentPermission1", "Effect" : "Allow", "Action" : [ "ssm:UpdateInstanceInformation" ], "Resource" : "arn:aws:ec2:*:*:instance/*", "Condition" : { "StringLike" : { "aws:ResourceTag/AWSRDSCustom" : [ "custom-oracle", "custom-sqlserver", "custom-oracle-rac" ] } } }, { "Sid" : "ssmAgentPermission2", "Effect" : "Allow", "Action" : [ "ssm:GetManifest", "ssm:PutConfigurePackageResult" ], "Resource" : "*" }, { "Sid" : "ssmAgentPermission3", "Effect" : "Allow", "Action" : [ "ssm:GetDocument", "ssm:DescribeDocument" ], "Resource" : "arn:aws:ssm:*:*:document/*" }, { "Sid" : "ssmAgentPermission4", "Effect" : "Allow", "Action" : [ "ssmmessages:CreateControlChannel", "ssmmessages:OpenControlChannel" ], "Resource" : "*" }, { "Sid" : "ssmAgentPermission5", "Effect" : "Allow", "Action" : [ "ec2messages:AcknowledgeMessage", "ec2messages:DeleteMessage", "ec2messages:FailMessage", "ec2messages:GetEndpoint", "ec2messages:GetMessages", "ec2messages:SendReply" ], "Resource" : "*" }, { "Sid" : "createEc2SnapshotPermission1", "Effect" : "Allow", "Action" : [ "ec2:CreateSnapshot", "ec2:CreateSnapshots" ], "Resource" : [ "arn:aws:ec2:*:*:volume/*" ], "Condition" : { "StringLike" : { "aws:ResourceTag/AWSRDSCustom" : [ "custom-oracle", "custom-sqlserver", "custom-oracle-rac" ] } } }, { "Sid" : "createEc2SnapshotPermission2", "Effect" : "Allow", "Action" : [ "ec2:CreateSnapshot", "ec2:CreateSnapshots" ], "Resource" : [ "arn:aws:ec2:*::snapshot/*" ], "Condition" : { "StringLike" : { "aws:RequestTag/AWSRDSCustom" : [ "custom-oracle", "custom-sqlserver", "custom-oracle-rac" ] } } }, { "Sid" : "createEc2SnapshotPermission3", "Effect" : "Allow", "Action" : "ec2:CreateSnapshots", "Resource" : [ "arn:aws:ec2:*:*:instance/*" ], "Condition" : { "StringLike" : { "aws:ResourceTag/AWSRDSCustom" : [ "custom-oracle", "custom-sqlserver", "custom-oracle-rac" ] } } }, { "Sid" : "createTagForEc2SnapshotPermission", "Effect" : "Allow", "Action" : "ec2:CreateTags", "Resource" : "*", "Condition" : { "StringLike" : { "aws:RequestTag/AWSRDSCustom" : [ "custom-oracle", "custom-sqlserver", "custom-oracle-rac" ], "ec2:CreateAction" : [ "CreateSnapshot", "CreateSnapshots" ] } } }, { "Sid" : "rdsCustomS3ObjectPermission", "Effect" : "Allow", "Action" : [ "s3:putObject", "s3:getObject", "s3:getObjectVersion", "s3:AbortMultipartUpload", "s3:ListMultipartUploadParts" ], "Resource" : [ "arn:aws:s3:::do-not-delete-rds-custom-*/*" ], "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "rdsCustomS3BucketPermission", "Effect" : "Allow", "Action" : [ "s3:ListBucketVersions", "s3:ListBucketMultipartUploads" ], "Resource" : [ "arn:aws:s3:::do-not-delete-rds-custom-*" ], "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "readSecretsFromCpPermission", "Effect" : "Allow", "Action" : [ "secretsmanager:GetSecretValue", "secretsmanager:DescribeSecret" ], "Resource" : [ "arn:aws:secretsmanager:*:*:secret:do-not-delete-rds-custom-*" ], "Condition" : { "StringLike" : { "aws:ResourceTag/AWSRDSCustom" : [ "custom-oracle", "custom-sqlserver", "custom-oracle-rac" ] } } }, { "Sid" : "createSecretsOnDpPermission", "Effect" : "Allow", "Action" : [ "secretsmanager:CreateSecret", "secretsmanager:TagResource" ], "Resource" : [ "arn:aws:secretsmanager:*:*:secret:do-not-delete-rds-custom-*" ], "Condition" : { "StringLike" : { "aws:RequestTag/AWSRDSCustom" : "custom-oracle-rac" } } }, { "Sid" : "publishCwMetricsPermission", "Effect" : "Allow", "Action" : "cloudwatch:PutMetricData", "Resource" : "*", "Condition" : { "StringEquals" : { "cloudwatch:namespace" : [ "rdscustom/rds-custom-sqlserver-agent", "RDSCustomForOracle/Agent" ] } } }, { "Sid" : "putEventsToEventBusPermission", "Effect" : "Allow", "Action" : "events:PutEvents", "Resource" : "arn:aws:events:*:*:event-bus/default" }, { "Sid" : "cwlUploadPermission", "Effect" : "Allow", "Action" : [ "logs:PutRetentionPolicy", "logs:PutLogEvents", "logs:DescribeLogStreams", "logs:CreateLogStream", "logs:CreateLogGroup" ], "Resource" : "arn:aws:logs:*:*:log-group:rds-custom-instance-*" }, { "Sid" : "sendMessageToSqsQueuePermission", "Effect" : "Allow", "Action" : [ "sqs:SendMessage", "sqs:ReceiveMessage", "sqs:DeleteMessage", "sqs:GetQueueUrl" ], "Resource" : [ "arn:aws:sqs:*:*:do-not-delete-rds-custom-*" ], "Condition" : { "StringLike" : { "aws:ResourceTag/AWSRDSCustom" : "custom-sqlserver" } } }, { "Sid" : "managePrivateIpOnEniPermission", "Effect" : "Allow", "Action" : [ "ec2:AssignPrivateIpAddresses", "ec2:UnassignPrivateIpAddresses" ], "Resource" : "arn:aws:ec2:*:*:network-interface/*", "Condition" : { "StringLike" : { "aws:ResourceTag/AWSRDSCustom" : "custom-oracle-rac" } } }, { "Sid" : "kmsPermissionWithSecret", "Effect" : "Allow", "Action" : [ "kms:Decrypt", "kms:GenerateDataKey" ], "Resource" : "*", "Condition" : { "ArnLike" : { "kms:EncryptionContext:SecretARN" : "arn:aws:secretsmanager:*:*:secret:do-not-delete-rds-custom-*" }, "StringLike" : { "kms:ViaService" : "secretsmanager.*.amazonaws.com" } } }, { "Sid" : "kmsPermissionWithS3", "Effect" : "Allow", "Action" : [ "kms:Decrypt", "kms:GenerateDataKey" ], "Resource" : "*", "Condition" : { "ArnLike" : { "kms:EncryptionContext:aws:s3:arn" : "arn:aws:s3:::do-not-delete-rds-custom-*" }, "StringLike" : { "kms:ViaService" : "s3.*.amazonaws.com" } } } ] }

Más información