@turbot/aws

The aws mod contains resource, control and policy definitions for AWS AWS service.

Resource Types

Resource types covered by this mod:

Permissions

Taking a look at permissions and associated grant levels for each permission for AWS:

PermissionGrant LevelHelp
account:DisableRegionOwnerOwners can disable an AWS region.
account:EnableRegionOwnerOwners can enable an AWS region.
account:GetAccountInformationMetadata
account:GetAlternateContactMetadata
account:GetChallengeQuestionsMetadata
account:GetContactInformationMetadata
account:GetRegionOptStatusMetadata
account:ListRegionsMetadata
account:PutAlternateContactAdminUpdate account alternate contacts.
iam:CreateAccountAliasOwnerOwners can manage the AWS account alias.
iam:DeleteAccountAliasOwnerOwners can manage the AWS account alias.
iam:ListAccountAliasesMetadata

Learn More About Guardrails