AWS Secrets Manager
(secretsmanager)
IAM Changes
Services
2021-11-10
2021-11-10
3 new conditions | 20 updated actions, 1 updated resource, 4 updated conditions
Additions
Conditions
aws:ResourceTag/${TagKey}
Description:
Filters access by the tags associated with the resource
Type:
String
secretsmanager:AddReplicaRegions
Description:
Filters access by the list of Regions in which to replicate the secret
Type:
ArrayOfString
secretsmanager:ForceOverwriteReplicaSecret
Description:
Filters access by whether to overwrite a secret with the same name in the destination Region
Type:
Bool
Updates
Actions
CancelRotateSecret
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
CreateSecret
Conditions
+ aws:RequestTag/${TagKey}
+ aws:ResourceTag/${TagKey}
+ secretsmanager:AddReplicaRegions
+ secretsmanager:ForceOverwriteReplicaSecret
- aws:RequestTag/tag-key
DeleteResourcePolicy
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
DeleteSecret
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
DescribeSecret
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
GetResourcePolicy
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
GetSecretValue
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
ListSecretVersionIds
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
PutResourcePolicy
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
PutSecretValue
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
RemoveRegionsFromReplication
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
ReplicateSecretToRegions
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
+ secretsmanager:AddReplicaRegions
+ secretsmanager:ForceOverwriteReplicaSecret
RestoreSecret
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
RotateSecret
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
StopReplicationToReplica
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
TagResource
Conditions
+ aws:RequestTag/${TagKey}
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
- aws:RequestTag/tag-key
UntagResource
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
UpdateSecret
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
UpdateSecretVersionStage
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
ValidateResourcePolicy
Conditions
+ aws:ResourceTag/${TagKey}
+ secretsmanager:SecretPrimaryRegion
Resources
Secret
Conditions
+ aws:RequestTag/${TagKey}
+ aws:ResourceTag/${TagKey}
- aws:RequestTag/tag-key
Conditions
secretsmanager:BlockPublicPolicy
Type
Boolean
⟶
Bool
secretsmanager:ForceDeleteWithoutRecovery
Type
Boolean
⟶
Bool
secretsmanager:RecoveryWindowInDays
Type
Long
⟶
Numeric
aws:RequestTag/${TagKey}
Description
Old:
Filters access by a key that is present in the request the user makes to the Secrets Manager service.
New:
Filters access by a key that is present in the request the user makes to the Secrets Manager service