AWS managed policies for Amazon Application Recovery Controller (ARC) - Amazon Application Recovery Controller (ARC)

AWS managed policies for Amazon Application Recovery Controller (ARC)

For information about the AWS managed policies for the Amazon Route 53 Application Recovery Controller capabilities with managed policies, including a managed policy for a service-linked role, see the following topics:

Updates to AWS managed policies for Amazon Application Recovery Controller (ARC)

View details about updates to AWS managed policies for capabilities in ARC since this service began tracking these changes. For automatic alerts about changes to this page, subscribe to the RSS feed on the ARC Document history page.

Change Description Date

AWSServiceRoleForPercPracticePolicy – New policy

Route 53 ARC added a new service-linked role for autoshift and practice runs.

Route 53 ARC uses the permissions enabled by the service-linked role to monitor customer-provided Amazon CloudWatch alarms and customer AWS Health Dashboard events for practice runs, and to start practice runs.

To learn more about the new service-linked role, see Service-linked role permissions for AWSServiceRoleForZonalAutoshiftPracticeRun.

November 30, 2023

AmazonRoute53RecoveryControlConfigReadOnlyAccess – Updated policy

Adds permissions for GetResourcePolicy, to support returning details about AWS Resource Access Manager resource policies for shared resources.

October 18, 2023

Route53RecoveryReadinessServiceRolePolicy – Updated policy

Route 53 ARC added new permissions to query information about Amazon EC2 instances.

Route 53 ARC uses the following permissions to support polling Amazon EC2 instances, to run readiness checks and determine the readiness status for the instances.

ec2:DescribeVpnGateways

ec2:DescribeCustomerGateways

February 17, 2023

Route53RecoveryReadinessServiceRolePolicy – Updated policy

Route 53 ARC added a new permission to query information about Lambda functions.

Route 53 ARC uses the following permission to query information about Lambda functions to run readiness checks and determine the readiness status for the functions.

lambda:ListProvisionedConcurrencyConfigs

August 31, 2022

AmazonRoute53RecoveryControlConfigFullAccess – Updated policy

Removed Amazon Route 53 permissions from the policy and added note listing the optional permissions.

May 26, 2022

AmazonRoute53RecoveryControlConfigFullAccess – Updated policy

Added missing required Amazon Route 53 permissions to the policy.

April 15, 2022

AmazonRoute53RecoveryClusterReadOnlyAccess – Updated policy

ARC added a new permission, route53-recovery-cluster:ListRoutingControls, to allow listing routing control ARNs with high availability.

March 15, 2022

AmazonRoute53RecoveryControlConfigReadOnlyAccess – Updated policy

ARC added a new permission, route53-recovery-control-config:ListTagsForResources, to allow listing tags for a resource.

December 20, 2021

Route53RecoveryReadinessServiceRolePolicy – Updated policy

Route 53 ARC added a new permission to query information about Amazon API Gateway.

Route 53 ARC uses the permission, apigateway:GET, to query information about API Gateway to run readiness checks and determine the readiness status.

October 28, 2021

AmazonRoute53RecoveryReadinessReadOnlyAccess – Added new permissions

ARC added two new permissions to AmazonRoute53RecoveryReadinessReadOnlyAccess:

ARC uses route53-recovery-readiness:GetArchitectureRecommendations and route53-recovery-readiness:GetCellReadinessSummary to allow read-only access to these actions for working with recovery readiness.

October 15, 2021

Route53RecoveryReadinessServiceRolePolicy – Updated policy

Route 53 ARC added new permissions to query information about Lambda functions.

Route 53 ARC uses the following permissions to query information about Lambda functions to run readiness checks and determine the readiness status for those functions.

lambda:GetFunctionConcurrency

lambda:GetFunctionConfiguration

lambda:GetProvisionedConcurrencyConfig

lambda:ListAliases

lambda:ListVersionsByFunction

lambda:ListEventSourceMappings

lambda:ListFunctions

October 8, 2021

Route53RecoveryReadinessServiceRolePolicy – Added new managed policies

ARC added the following new managed policies:

AmazonRoute53RecoveryReadinessFullAccess

AmazonRoute53RecoveryReadinessReadOnlyAccess

AmazonRoute53RecoveryClusterFullAccess

AmazonRoute53RecoveryClusterReadOnlyAccess

AmazonRoute53RecoveryControlConfigFullAccess

AmazonRoute53RecoveryControlConfigReadOnlyAccess

August 18, 2021

ARC started tracking changes

ARC started tracking changes for its AWS managed policies.

July 27, 2021