翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。
AWSCleanRoomsFullAccess
説明: AWS クリーンルームリソースへのフルアクセスおよび関連する AWS のサービスへのアクセスを許可します。
AWSCleanRoomsFullAccess
は AWS マネージドポリシーです。
このポリシーを使用すると
ユーザー、グループおよびロールに AWSCleanRoomsFullAccess
をアタッチできます。
ポリシーの詳細
-
タイプ: AWS マネージドポリシー
-
作成日時: 2023 年 1 月 12 日 16:10 UTC
-
編集日時: 2024 年 3 月 21 日 15:35 UTC
-
ARN:
arn:aws:iam::aws:policy/AWSCleanRoomsFullAccess
ポリシーのバージョン
ポリシーのバージョン: v2 (デフォルト)
ポリシーのデフォルトバージョンは、ポリシーのアクセス許可を定義するバージョンです。ポリシーを適用したユーザーまたはロールが AWS リソースへのアクセスをリクエストすると、AWS はポリシーのデフォルトバージョンを確認し、リクエストを許可するかどうかを判断します。
JSON ポリシードキュメント
{
"Version" : "2012-10-17",
"Statement" : [
{
"Sid" : "CleanRoomsAccess",
"Effect" : "Allow",
"Action" : [
"cleanrooms:*"
],
"Resource" : "*"
},
{
"Sid" : "PassServiceRole",
"Effect" : "Allow",
"Action" : [
"iam:PassRole"
],
"Resource" : "arn:aws:iam::*:role/service-role/*cleanrooms*",
"Condition" : {
"StringEquals" : {
"iam:PassedToService" : "cleanrooms.amazonaws.com"
}
}
},
{
"Sid" : "ListRolesToPickServiceRole",
"Effect" : "Allow",
"Action" : [
"iam:ListRoles"
],
"Resource" : "*"
},
{
"Sid" : "GetRoleAndListRolePoliciesToInspectServiceRole",
"Effect" : "Allow",
"Action" : [
"iam:GetRole",
"iam:ListRolePolicies",
"iam:ListAttachedRolePolicies"
],
"Resource" : "arn:aws:iam::*:role/service-role/*cleanrooms*"
},
{
"Sid" : "ListPoliciesToInspectServiceRolePolicy",
"Effect" : "Allow",
"Action" : [
"iam:ListPolicies"
],
"Resource" : "*"
},
{
"Sid" : "GetPolicyToInspectServiceRolePolicy",
"Effect" : "Allow",
"Action" : [
"iam:GetPolicy",
"iam:GetPolicyVersion"
],
"Resource" : "arn:aws:iam::*:policy/*cleanrooms*"
},
{
"Sid" : "ConsoleDisplayTables",
"Effect" : "Allow",
"Action" : [
"glue:GetDatabase",
"glue:GetDatabases",
"glue:GetTable",
"glue:GetTables",
"glue:GetPartition",
"glue:GetPartitions",
"glue:GetSchema",
"glue:GetSchemaVersion",
"glue:BatchGetPartition"
],
"Resource" : "*"
},
{
"Sid" : "ConsolePickQueryResultsBucketListAll",
"Effect" : "Allow",
"Action" : [
"s3:ListAllMyBuckets"
],
"Resource" : "*"
},
{
"Sid" : "SetQueryResultsBucket",
"Effect" : "Allow",
"Action" : [
"s3:GetBucketLocation",
"s3:ListBucketVersions"
],
"Resource" : "arn:aws:s3:::cleanrooms-queryresults*"
},
{
"Sid" : "WriteQueryResults",
"Effect" : "Allow",
"Action" : [
"s3:ListBucket",
"s3:PutObject"
],
"Resource" : "arn:aws:s3:::cleanrooms-queryresults*",
"Condition" : {
"ForAnyValue:StringEquals" : {
"aws:CalledVia" : "cleanrooms.amazonaws.com"
}
}
},
{
"Sid" : "ConsoleDisplayQueryResults",
"Effect" : "Allow",
"Action" : [
"s3:GetObject"
],
"Resource" : "arn:aws:s3:::cleanrooms-queryresults*"
},
{
"Sid" : "EstablishLogDeliveries",
"Effect" : "Allow",
"Action" : [
"logs:CreateLogDelivery",
"logs:GetLogDelivery",
"logs:UpdateLogDelivery",
"logs:DeleteLogDelivery",
"logs:ListLogDeliveries"
],
"Resource" : "*",
"Condition" : {
"ForAnyValue:StringEquals" : {
"aws:CalledVia" : "cleanrooms.amazonaws.com"
}
}
},
{
"Sid" : "SetupLogGroupsDescribe",
"Effect" : "Allow",
"Action" : [
"logs:DescribeLogGroups"
],
"Resource" : "*",
"Condition" : {
"ForAnyValue:StringEquals" : {
"aws:CalledVia" : "cleanrooms.amazonaws.com"
}
}
},
{
"Sid" : "SetupLogGroupsCreate",
"Effect" : "Allow",
"Action" : [
"logs:CreateLogGroup"
],
"Resource" : "arn:aws:logs:*:*:log-group:/aws/cleanrooms*",
"Condition" : {
"ForAnyValue:StringEquals" : {
"aws:CalledVia" : "cleanrooms.amazonaws.com"
}
}
},
{
"Sid" : "SetupLogGroupsResourcePolicy",
"Effect" : "Allow",
"Action" : [
"logs:DescribeResourcePolicies",
"logs:PutResourcePolicy"
],
"Resource" : "*",
"Condition" : {
"ForAnyValue:StringEquals" : {
"aws:CalledVia" : "cleanrooms.amazonaws.com"
}
}
},
{
"Sid" : "ConsoleLogSummaryQueryLogs",
"Effect" : "Allow",
"Action" : [
"logs:StartQuery"
],
"Resource" : "arn:aws:logs:*:*:log-group:/aws/cleanrooms*"
},
{
"Sid" : "ConsoleLogSummaryObtainLogs",
"Effect" : "Allow",
"Action" : [
"logs:GetQueryResults"
],
"Resource" : "*"
}
]
}