Permissions for @turbot/aws-ecs
Taking a look at permissions and associated grant levels for each permission for ECS:
Permission | Grant Level | Help |
---|---|---|
ecs:CreateCluster | Admin | |
ecs:CreateService | Admin | |
ecs:DeleteAccountSetting | Admin | |
ecs:DeleteAttributes | Admin | |
ecs:DeleteCluster | Admin | |
ecs:DeleteService | Admin | |
ecs:DeregisterContainerInstance | Admin | |
ecs:DeregisterTaskDefinition | Admin | |
ecs:DescribeClusters | Metadata | |
ecs:DescribeContainerInstances | Metadata | |
ecs:DescribeServices | Metadata | |
ecs:DescribeTaskDefinition | Metadata | |
ecs:DescribeTasks | Metadata | |
ecs:DiscoverPollEndpoint | Admin | "This action is only used by the Amazon EC2 Container Service agent |
ecs:ExecuteCommand | Admin | |
ecs:ListAccountSettings | Metadata | |
ecs:ListAttributes | Metadata | |
ecs:ListClusters | Metadata | |
ecs:ListContainerInstances | Metadata | |
ecs:ListServices | Metadata | |
ecs:ListTagsForResource | Metadata | |
ecs:ListTaskDefinitionFamilies | Metadata | |
ecs:ListTaskDefinitions | Metadata | |
ecs:ListTasks | Metadata | |
ecs:Poll | Admin | "This action is only used by the Amazon EC2 Container Service agent |
ecs:PutAccountSetting | Admin | The root user has the ability to opt in or opt out any specific IAM role or user on the account. |
ecs:PutAttributes | Admin | |
ecs:RegisterContainerInstance | Admin | "This action is only used by the Amazon EC2 Container Service agent |
ecs:RegisterTaskDefinition | Admin | |
ecs:RunTask | Operator | |
ecs:StartTask | Operator | |
ecs:StartTelemetrySession | Admin | "This action is only used by the Amazon EC2 Container Service agent |
ecs:StopTask | Operator | |
ecs:SubmitContainerStateChange | Admin | "This action is only used by the Amazon EC2 Container Service agent |
ecs:SubmitTaskStateChange | Admin | "This action is only used by the Amazon EC2 Container Service agent |
ecs:TagResource | Operator | |
ecs:UntagResource | Operator | |
ecs:UpdateContainerAgent | Admin | |
ecs:UpdateContainerInstancesState | Admin | |
ecs:UpdateService | Admin | |
ecs:DeregisterContainerInstance | Admin | Container instances deleted by auto scaling only have ec2:TerminateInstances event |