AmazonRedshiftQueryEditorV2ReadWriteSharing - AWS 托管策略

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

AmazonRedshiftQueryEditorV2ReadWriteSharing

描述:允许使用 Amazon Redshift 查询编辑器 V2 进行资源共享。获得授权的主体可读取、写入和共享自己的资源。授予主体可以读取和更新与其团队共享的资源。此策略还授予访问其他所需服务的访问权限。这包括在 Secrets Man AWS ager 中列出 Amazon Redshift 集群和管理委托人的查询编辑器 V2 密钥的权限。

AmazonRedshiftQueryEditorV2ReadWriteSharing是一个AWS 托管策略

使用此策略

您可以将 AmazonRedshiftQueryEditorV2ReadWriteSharing 附加到您的用户、组和角色。

策略详细信息

  • 类型: AWS 托管策略

  • 创建时间:2021 年 9 月 24 日 14:25 UTC

  • 编辑时间:世界标准时间 2024 年 2 月 21 日 17:30

  • ARN: arn:aws:iam::aws:policy/AmazonRedshiftQueryEditorV2ReadWriteSharing

策略版本

策略版本:v9(默认)

此策略的默认版本是定义策略权限的版本。当使用该策略的用户或角色请求访问 AWS 资源时, AWS 会检查策略的默认版本以确定是否允许该请求。

JSON 策略文档

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "RedshiftPermissions", "Effect" : "Allow", "Action" : [ "redshift:DescribeClusters", "redshift-serverless:ListNamespaces", "redshift-serverless:ListWorkgroups" ], "Resource" : "*" }, { "Sid" : "SecretsManagerPermissions", "Effect" : "Allow", "Action" : [ "secretsmanager:CreateSecret", "secretsmanager:GetSecretValue", "secretsmanager:DeleteSecret", "secretsmanager:TagResource" ], "Resource" : "arn:aws:secretsmanager:*:*:sqlworkbench!*", "Condition" : { "StringEquals" : { "secretsmanager:ResourceTag/sqlworkbench-resource-owner" : "${aws:userid}" } } }, { "Sid" : "ResourceGroupsTaggingPermissions", "Effect" : "Allow", "Action" : [ "tag:GetResources" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:CalledViaLast" : "sqlworkbench.amazonaws.com" } } }, { "Sid" : "AmazonRedshiftQueryEditorV2NonResourceLevelPermissions", "Effect" : "Allow", "Action" : [ "sqlworkbench:CreateFolder", "sqlworkbench:PutTab", "sqlworkbench:BatchDeleteFolder", "sqlworkbench:DeleteTab", "sqlworkbench:GenerateSession", "sqlworkbench:GetAccountInfo", "sqlworkbench:GetAccountSettings", "sqlworkbench:GetUserInfo", "sqlworkbench:GetUserWorkspaceSettings", "sqlworkbench:PutUserWorkspaceSettings", "sqlworkbench:ListConnections", "sqlworkbench:ListFiles", "sqlworkbench:ListTabs", "sqlworkbench:UpdateFolder", "sqlworkbench:ListRedshiftClusters", "sqlworkbench:DriverExecute", "sqlworkbench:ListTaggedResources", "sqlworkbench:ListQueryExecutionHistory", "sqlworkbench:GetQueryExecutionHistory", "sqlworkbench:ListNotebooks", "sqlworkbench:GetSchemaInference", "sqlworkbench:GetAutocompletionMetadata", "sqlworkbench:GetAutocompletionResource" ], "Resource" : "*" }, { "Sid" : "AmazonRedshiftQueryEditorV2CreateOwnedResourcePermissions", "Effect" : "Allow", "Action" : [ "sqlworkbench:CreateConnection", "sqlworkbench:CreateSavedQuery", "sqlworkbench:CreateChart", "sqlworkbench:CreateNotebook", "sqlworkbench:DuplicateNotebook", "sqlworkbench:CreateNotebookFromVersion", "sqlworkbench:ImportNotebook" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestTag/sqlworkbench-resource-owner" : "${aws:userid}" } } }, { "Sid" : "AmazonRedshiftQueryEditorV2OwnerSpecificPermissions", "Effect" : "Allow", "Action" : [ "sqlworkbench:DeleteChart", "sqlworkbench:DeleteConnection", "sqlworkbench:DeleteSavedQuery", "sqlworkbench:GetChart", "sqlworkbench:GetConnection", "sqlworkbench:GetSavedQuery", "sqlworkbench:ListSavedQueryVersions", "sqlworkbench:UpdateChart", "sqlworkbench:UpdateConnection", "sqlworkbench:UpdateSavedQuery", "sqlworkbench:AssociateConnectionWithTab", "sqlworkbench:AssociateQueryWithTab", "sqlworkbench:AssociateConnectionWithChart", "sqlworkbench:AssociateNotebookWithTab", "sqlworkbench:UpdateFileFolder", "sqlworkbench:ListTagsForResource", "sqlworkbench:GetNotebook", "sqlworkbench:UpdateNotebook", "sqlworkbench:DeleteNotebook", "sqlworkbench:DuplicateNotebook", "sqlworkbench:CreateNotebookCell", "sqlworkbench:DeleteNotebookCell", "sqlworkbench:UpdateNotebookCellContent", "sqlworkbench:UpdateNotebookCellLayout", "sqlworkbench:BatchGetNotebookCell", "sqlworkbench:ListNotebookVersions", "sqlworkbench:CreateNotebookVersion", "sqlworkbench:GetNotebookVersion", "sqlworkbench:DeleteNotebookVersion", "sqlworkbench:RestoreNotebookVersion", "sqlworkbench:CreateNotebookFromVersion", "sqlworkbench:ExportNotebook", "sqlworkbench:ImportNotebook" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:ResourceTag/sqlworkbench-resource-owner" : "${aws:userid}" } } }, { "Sid" : "AmazonRedshiftQueryEditorV2TagOnlyUserIdPermissions", "Effect" : "Allow", "Action" : "sqlworkbench:TagResource", "Resource" : "*", "Condition" : { "ForAllValues:StringEquals" : { "aws:TagKeys" : "sqlworkbench-resource-owner" }, "StringEquals" : { "aws:ResourceTag/sqlworkbench-resource-owner" : "${aws:userid}", "aws:RequestTag/sqlworkbench-resource-owner" : "${aws:userid}" } } }, { "Sid" : "AmazonRedshiftQueryEditorV2TeamReadWriteAccessPermissions", "Effect" : "Allow", "Action" : [ "sqlworkbench:GetChart", "sqlworkbench:GetConnection", "sqlworkbench:GetSavedQuery", "sqlworkbench:ListSavedQueryVersions", "sqlworkbench:ListTagsForResource", "sqlworkbench:UpdateChart", "sqlworkbench:UpdateConnection", "sqlworkbench:UpdateSavedQuery", "sqlworkbench:AssociateConnectionWithTab", "sqlworkbench:AssociateQueryWithTab", "sqlworkbench:AssociateConnectionWithChart", "sqlworkbench:AssociateNotebookWithTab", "sqlworkbench:GetNotebook", "sqlworkbench:DuplicateNotebook", "sqlworkbench:BatchGetNotebookCell", "sqlworkbench:ListNotebookVersions", "sqlworkbench:GetNotebookVersion", "sqlworkbench:CreateNotebookFromVersion", "sqlworkbench:ExportNotebook" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:ResourceTag/sqlworkbench-team" : "${aws:PrincipalTag/sqlworkbench-team}" } } }, { "Sid" : "AmazonRedshiftQueryEditorV2TagOnlyTeamPermissions", "Effect" : "Allow", "Action" : "sqlworkbench:TagResource", "Resource" : "*", "Condition" : { "ForAllValues:StringEquals" : { "aws:TagKeys" : "sqlworkbench-team" }, "StringEquals" : { "aws:ResourceTag/sqlworkbench-resource-owner" : "${aws:userid}", "aws:RequestTag/sqlworkbench-team" : "${aws:PrincipalTag/sqlworkbench-team}" } } }, { "Sid" : "AmazonRedshiftQueryEditorV2UntagOnlyTeamPermissions", "Effect" : "Allow", "Action" : "sqlworkbench:UntagResource", "Resource" : "*", "Condition" : { "ForAllValues:StringEquals" : { "aws:TagKeys" : "sqlworkbench-team" }, "StringEquals" : { "aws:ResourceTag/sqlworkbench-resource-owner" : "${aws:userid}" } } } ] }

了解更多信息