2025-08-07
          
        8 new actions, 2 new resources | 3 updated actions
  
    
        
          
            Additions
          
              
                Actions
                
                    - 
                        CreateServiceEnvironment
                        
 
                              - 
                                Description: 
                                
                                    Grants permission to create an AWS Batch service environment in your account
                                
                              
- 
                                Access: 
                                
                                    Write
                                
                              
- 
                                Resources: 
                                
      
        Name: service-environment
       
        Required: Yes
       
- 
                                Conditions: 
                                
    aws:RequestTag/${TagKey} aws:TagKeys 
- 
                                Dependents: 
                                
    iam:CreateServiceLinkedRole 
 
- 
                        DeleteServiceEnvironment
                        
 
                              - 
                                Description: 
                                
                                    Grants permission to delete an AWS Batch service environment in your account
                                
                              
- 
                                Access: 
                                
                                    Write
                                
                              
- 
                                Resources: 
                                
      
        Name: service-environment
       
        Required: Yes
       
 
- 
                        DescribeServiceEnvironments
                        
 
                              - 
                                Description: 
                                
                                    Grants permission to describe one or more AWS Batch service environments in your account
                                
                              
- 
                                Access: 
                                
                                    Read
                                
                              
 
- 
                        DescribeServiceJob
                        
 
                              - 
                                Description: 
                                
                                    Grants permission to describe a AWS Batch service job in your account
                                
                              
- 
                                Access: 
                                
                                    Read
                                
                              
 
- 
                        ListServiceJobs
                        
 
                              - 
                                Description: 
                                
                                    Grants permission to list service jobs for a specified AWS Batch job queue in your account
                                
                              
- 
                                Access: 
                                
                                    List
                                
                              
 
- 
                        SubmitServiceJob
                        
 
                              - 
                                Description: 
                                
                                    Grants permission to submit an AWS Batch service job
                                
                              
- 
                                Access: 
                                
                                    Write
                                
                              
- 
                                Resources: 
                                
      
        Name: job-queue
       
        Required: Yes
       
        Name: service-job
       
        Required: Yes
       
- 
                                Conditions: 
                                
    batch:ShareIdentifier aws:RequestTag/${TagKey} aws:TagKeys 
 
- 
                        TerminateServiceJob
                        
 
                              - 
                                Description: 
                                
                                    Grants permission to terminate a service job in an AWS Batch job queue in your account
                                
                              
- 
                                Access: 
                                
                                    Write
                                
                              
- 
                                Resources: 
                                
      
        Name: service-job
       
        Required: Yes
       
 
- 
                        UpdateServiceEnvironment
                        
 
                              - 
                                Description: 
                                
                                    Grants permission to update an AWS Batch service environment in your account
                                
                              
- 
                                Access: 
                                
                                    Write
                                
                              
- 
                                Resources: 
                                
      
        Name: service-environment
       
        Required: Yes
       
 
                Resources
                
                    - 
                        service-environment
                        
 
                              - 
                                Arn: 
                                
                                    arn:${Partition}:batch:${Region}:${Account}:service-environment/${ServiceEnvironmentName}
                                
                              
- 
                                Conditions: 
                                
    aws:ResourceTag/${TagKey} 
 
- 
                        service-job
                        
 
                              - 
                                Arn: 
                                
                                    arn:${Partition}:batch:${Region}:${Account}:service-job/${JobId}
                                
                              
- 
                                Conditions: 
                                
    aws:ResourceTag/${TagKey}