コンテンツにスキップ

opswitch が作成したIAM Role の権限に関して(v.12.0)

opswitchがAWSアカウント連携時に作成したIAM Roleの権限は以下になります。v.12.0ではKMS:ListKeys, KMS:ListKeyPolicies, KMS:GetKeyPolicy, CloudFormation:Get*の権限が削除され、EC2とRDSのDescribeから始まる権限が、opswitchが利用するものだけの個別指定に変更されました。

  • DescribeImages
  • DescribeInstances
  • DescribeSnapshots
  • DescribeVolumes
  • CreateSnapshot
  • DeleteSnapshot
  • CreateImage
  • DeregisterImage
  • CreateTags
  • StartInstances
  • StopInstances
  • ModifyInstanceAttribute
  • CopySnapshot
  • CopyImage
  • DescribeAutoScalingGroups
  • UpdateAutoScalingGroup
  • DescribeServices
  • ListClusters
  • ListServices
  • UpdateService
  • DescribeDBClusters
  • DescribeDBClusterSnapshots
  • DescribeDBInstances
  • DescribeDBSnapshots
  • CreateDBSnapshot
  • DeleteDBSnapshot
  • ListTagsForResource
  • AddTagsToResource
  • StartDBInstance
  • StopDBInstance
  • CreateDBClusterSnapshot
  • DeleteDBClusterSnapshot
  • StartDBCluster
  • StopDBCluster
  • CopyDBSnapshot
  • CopyDBClusterSnapshot
  • StartWorkspaces
  • DescribeWorkspaces
  • DescribeTags
  • CreateTags
  • DescribeClusters
  • CreateTags
  • SendCommand
    • AWSEC2-CreateVssSnapshotドキュメントの実行を全てのEC2インスタンスに許可します。
  • GetCommandInvocation
  • CreateGrant
  • ListAliases
  • 先頭にDescribeが付く権限
  • ListStacks
  • CreateChangeSet