Permissions for @turbot/aws-cloudformation
Taking a look at permissions and associated grant levels for each permission for CloudFormation:
Permission | Grant Level | Help |
---|---|---|
cloudformation:ActivateType | Admin | |
cloudformation:BatchDescribeTypeConfigurations | Metadata | |
cloudformation:CancelResourceRequest | Operator | |
cloudformation:CancelUpdateStack | Operator | |
cloudformation:ContinueUpdateRollback | Operator | |
cloudformation:CreateChangeSet | Operator | |
cloudformation:CreateResource | Admin | |
cloudformation:CreateStack | Operator | |
cloudformation:CreateStackInstances | Admin | |
cloudformation:CreateStackSet | Admin | |
cloudformation:CreateUploadBucket | Operator | Creates an S3 bucket for CFN templates |
cloudformation:DeactivateType | Admin | |
cloudformation:DeleteChangeSet | Operator | |
cloudformation:DeleteResource | Admin | |
cloudformation:DeleteStack | Operator | |
cloudformation:DeleteStackInstances | Admin | |
cloudformation:DeleteStackSet | Admin | |
cloudformation:DeregisterType | Admin | |
cloudformation:DescribeAccountLimits | Metadata | |
cloudformation:DescribeChangeSet | Metadata | |
cloudformation:DescribePublisher | Metadata | |
cloudformation:DescribeStackDriftDetectionStatus | Metadata | |
cloudformation:DescribeStackEvents | Metadata | |
cloudformation:DescribeStackInstance | Metadata | |
cloudformation:DescribeStackResource | Metadata | |
cloudformation:DescribeStackResourceDrifts | Metadata | |
cloudformation:DescribeStackResources | Metadata | |
cloudformation:DescribeStackSet | Metadata | |
cloudformation:DescribeStackSetOperation | Metadata | |
cloudformation:DescribeStacks | Metadata | |
cloudformation:DescribeType | Metadata | |
cloudformation:DescribeTypeRegistration | Metadata | |
cloudformation:DetectStackDrift | Metadata | Used to detect whether a stack’s actual configuration has been changed outside of CloudFormation. |
cloudformation:DetectStackResourceDrift | Metadata | |
cloudformation:DetectStackSetDrift | Metadata | |
cloudformation:EstimateTemplateCost | Metadata | Cost calculation does not contain data. |
cloudformation:ExecuteChangeSet | Operator | |
cloudformation:GetResource | Metadata | |
cloudformation:GetResourceRequestStatus | Metadata | |
cloudformation:GetStackPolicy | Metadata | |
cloudformation:GetTemplate | Metadata | Templates describe resources but should not contain any data or sensitive information. |
cloudformation:GetTemplateSummary | Metadata | |
cloudformation:ImportStacksToStackSet | Operator | |
cloudformation:ListChangeSets | Metadata | |
cloudformation:ListExports | Metadata | |
cloudformation:ListImports | Metadata | |
cloudformation:ListResourceRequests | Metadata | |
cloudformation:ListResources | Metadata | |
cloudformation:ListStackInstances | Metadata | |
cloudformation:ListStackResources | Metadata | |
cloudformation:ListStackSetOperationResults | Metadata | |
cloudformation:ListStackSetOperations | Metadata | |
cloudformation:ListStackSets | Metadata | |
cloudformation:ListStacks | Metadata | |
cloudformation:ListTypeRegistrations | Metadata | |
cloudformation:ListTypeVersions | Metadata | |
cloudformation:ListTypes | Metadata | |
cloudformation:PublishType | Admin | |
cloudformation:RecordHandlerProgress | Admin | |
cloudformation:RegisterType | Admin | |
cloudformation:RegisterPublisher | Admin | |
cloudformation:SetStackPolicy | Operator | Stack policies do not replace IAM but instead are used to protect resources. |
cloudformation:SetTypeConfiguration | Admin | |
cloudformation:SetTypeDefaultVersion | Admin | |
cloudformation:SignalResource | Operator | |
cloudformation:StopStackSetOperation | Admin | |
cloudformation:TagResource | Operator | |
cloudformation:TagResources | Operator | |
cloudformation:TestType | Operator | |
cloudformation:UntagResource | Operator | |
cloudformation:UntagResources | Operator | |
cloudformation:UpdateResource | Admin | |
cloudformation:UpdateStack | Operator | |
cloudformation:UpdateStackInstances | Admin | |
cloudformation:UpdateStackSet | Admin | |
cloudformation:UpdateTerminationProtection | Operator | Updates termination protection for the specified stack. If a user attempts to delete a stack with termination protection enabled the operation fails and the stack remains unchanged. |
cloudformation:ValidateTemplate | Metadata |