AWS CloudWatch RUM (rum)

2021-12-04

10 new actions, 1 new resource, 3 new conditions

Additions

    Actions
  • CreateAppMonitor
    • Description:  Grants permission to create appMonitor metadata
    • Access:  Write
    • Resources: 

      Name: AppMonitorResource

      Required: Yes

    • Conditions: 

      aws:RequestTag/${TagKey}

      aws:TagKeys

    • Dependents: 

      iam:CreateServiceLinkedRole

      iam:GetRole

  • DeleteAppMonitor
    • Description:  Grants permission to delete appMonitor metadata
    • Access:  Write
    • Resources: 

      Name: AppMonitorResource

      Required: Yes

  • GetAppMonitor
    • Description:  Grants permission to get appMonitor metadata
    • Access:  Read
    • Resources: 

      Name: AppMonitorResource

      Required: Yes

  • GetAppMonitorData
    • Description:  Grants permission to get appMonitor data
    • Access:  Read
    • Resources: 

      Name: AppMonitorResource

      Required: Yes

  • ListAppMonitors
    • Description:  Grants permission to list appMonitors metadata
    • Access:  List
  • ListTagsForResource
    • Description:  Grants permission to list tags for resources
    • Access:  Read
  • PutRumEvents
    • Description:  Grants permission to put RUM events for appmonitor
    • Access:  Write
  • TagResource
    • Description:  Grants permission to tag resources
    • Access:  Tagging
  • UntagResource
    • Description:  Grants permission to untag resources
    • Access:  Tagging
  • UpdateAppMonitor
    • Description:  Grants permission to update appmonitor metadata
    • Access:  Write
    • Resources: 

      Name: AppMonitorResource

      Required: Yes

    • Dependents: 

      iam:CreateServiceLinkedRole

      iam:GetRole

    Resources
  • AppMonitorResource
    • Arn:  arn:${Partition}:rum:${Region}:${Account}:appmonitor/${Name}
    • Conditions: 

      aws:ResourceTag/${TagKey}

    Conditions
  • aws:RequestTag/${TagKey}
    • Description:  Filters access by the tags that are passed the request on behalf of the IAM principal
    • Type:  String
  • aws:ResourceTag/${TagKey}
    • Description:  Filters access by the tags associated with the resource that make the request on behalf of the IAM principal
    • Type:  String
  • aws:TagKeys
    • Description:  Filters access by the tag keys that are passed in the request on behalf of the IAM principal
    • Type:  String