AWS Systems Manager
(ssm)
IAM Changes
Services
2022-06-14
2022-06-14
2 new actions, 2 new conditions | 26 updated actions, 3 updated resources
Additions
Actions
GetCalendar [permission only]
Description:
Grants permission to view details of a specific calendar
Access:
Read
Resources:
Name: document
Required: Yes
PutCalendar [permission only]
Description:
Grants permission to create/edit a specific calendar
Access:
Write
Resources:
Name: document
Required: Yes
Conditions
ssm:AutoApprove
Description:
Filters access by verifying that a user has permission to start Change Manager workflows without a review step (with the exception of change freeze events)
Type:
String
ssm:resourceTag/${TagKey}
Description:
Filters access based on a tag key-value pair assigned to the Systems Manager resource
Type:
String
Updates
Actions
DescribeEffectiveInstanceAssociations
Resources
New_value: Yes
Old_value: No
DescribeInstanceAssociationsStatus
Resources
New_value: Yes
Old_value: No
ListCommandInvocations
Access
Read
⟶
List
ListCommands
Access
Read
⟶
List
ListOpsItemEvents
Access
Read
⟶
List
ListOpsItemRelatedItems
Access
Read
⟶
List
ListTagsForResource
Access
Read
⟶
List
SendCommand
Conditions
+ ssm:resourceTag/${TagKey}
- ssm:resourceTag/tag-key
StartSession
Conditions
+ ssm:resourceTag/${TagKey}
- ssm:resourceTag/tag-key
AddTagsToResource
Conditions
+ aws:RequestTag/${TagKey}
+ aws:TagKeys
CancelMaintenanceWindowExecution
Resources
+ maintenancewindow
CreateActivation
Conditions
+ aws:RequestTag/${TagKey}
+ aws:TagKeys
DeregisterManagedInstance
Conditions
+ ssm:resourceTag/tag-key
DescribeAssociationExecutionTargets
Resources
+ association
DescribeAssociationExecutions
Resources
+ association
DescribeAutomationStepExecutions
Resources
+ automation-execution
DescribeMaintenanceWindowExecutionTasks
Resources
+ maintenancewindow
GetAutomationExecution
Resources
+ automation-execution
GetConnectionStatus
Resources
+ instance
+ managed-instance
+ task
Conditions
+ ssm:resourceTag/${TagKey}
+ aws:ResourceTag/${TagKey}
ListAssociationVersions
Resources
+ association
RemoveTagsFromResource
Conditions
+ aws:TagKeys
SendAutomationSignal
Resources
+ automation-execution
StartChangeRequestExecution
Conditions
+ ssm:AutoApprove
StopAutomationExecution
Resources
+ automation-execution
UpdateInstanceInformation
Resources
+ instance
+ managed-instance
UpdateManagedInstanceRole
Conditions
+ ssm:resourceTag/tag-key
Resources
document
Conditions
+ ssm:DocumentCategories
- ssm:resourceTag/tag-key
instance
Conditions
+ ssm:resourceTag/${TagKey}
- ssm:resourceTag/tag-key
opsmetadata
Conditions
+ ssm:resourceTag/${TagKey}
- ssm:resourceTag/tag-key