Permissions for @turbot/aws-storagegateway

Taking a look at permissions and associated grant levels for each permission for Storage Gateway:

PermissionGrant LevelHelp
storagegateway:ActivateGatewayAdminAdmins manage gateways.
storagegateway:AddCacheAdminAdmins manage caches for cached-volume gateways.
storagegateway:AddTagsToResourceOperatorOperators can add tags to all resources.
storagegateway:AddUploadBufferAdminAdmins manage upload buffers for gateways.
storagegateway:AddWorkingStorageAdminDeprecated and replaced by AddUploadBuffer by AWS. Set to Whitelist instead of None to consolidate characters in lockdown whitelist policy.
storagegateway:AssignTapePoolAdmin
storagegateway:AttachVolumeAdmin
storagegateway:CancelArchivalOperatorOperators can cancel archivals.
storagegateway:CancelRetrievalOperatorOperators can cancel retrievals.
storagegateway:CreateCachediSCSIVolumeAdminAdmins manage caches for cached-volume gateways.
storagegateway:CreateNFSFileShareAdminAdmins manage NFS file shares.
storagegateway:CreateSMBFileShareAdmin
storagegateway:CreateSnapshotOperatorOperators can create volume snapshots.
storagegateway:CreateSnapshotFromVolumeRecoveryPointOperatorOperators can create volume snapshots.
storagegateway:CreateStorediSCSIVolumeAdminAdmins manage volumes for gateway-stored gateways.
storagegateway:CreateTapePoolAdmin
storagegateway:CreateTapeWithBarcodeAdminAdmins manage tapes.
storagegateway:CreateTapesAdminAdmins manage tapes.
storagegateway:DeleteAutomaticTapeCreationPolicyAdmin
storagegateway:DeleteBandwidthRateLimitOperatorOperators manage gateway bandwidth rate limits.
storagegateway:DeleteChapCredentialsAdminAdmins manage Challenge-Handshake Authentication Protocol (CHAP) credentials.
storagegateway:DeleteFileShareAdminAdmins manage NFS file shares.
storagegateway:DeleteGatewayAdminAdmins manage gateways.
storagegateway:DeleteSnapshotScheduleOperatorDeleting a volume's snapshot schedule does not delete snapshots.
storagegateway:DeleteTapeAdminAdmins manage tapes.
storagegateway:DeleteTapeArchiveAdminAdmins manage tapes.
storagegateway:DeleteTapePoolAdmin
storagegateway:DeleteVolumeAdminAdmins manage volumes.
storagegateway:DescribeAvailabilityMonitorTestMetadata
storagegateway:DescribeBandwidthRateLimitMetadata
storagegateway:DescribeCacheMetadata
storagegateway:DescribeCachediSCSIVolumesMetadata
storagegateway:DescribeChapCredentialsMetadataEven though initiator-target secret keys are returned; low risk as admin actions are still needed to setup connection.
storagegateway:DescribeGatewayInformationMetadata
storagegateway:DescribeMaintenanceStartTimeMetadata
storagegateway:DescribeNFSFileSharesMetadata
storagegateway:DescribeSMBFileSharesMetadata
storagegateway:DescribeSMBSettingsMetadata
storagegateway:DescribeSnapshotScheduleMetadata
storagegateway:DescribeStorediSCSIVolumesMetadata
storagegateway:DescribeTapeArchivesMetadata
storagegateway:DescribeTapeRecoveryPointsMetadata
storagegateway:DescribeTapesMetadata
storagegateway:DescribeUploadBufferMetadata
storagegateway:DescribeVTLDevicesMetadata
storagegateway:DescribeWorkingStorageMetadataDeprecated and replaced by DescribeUploadBuffer by AWS. Retained by Guardrails since it's a read permission.
storagegateway:DetachVolumeAdmin
storagegateway:DisableGatewayOperatorCan only disable gateways that are no longer functioning. Disabled gateways cannot be re-enabled.
storagegateway:JoinDomainAdmin
storagegateway:ListAutomaticTapeCreationPoliciesMetadata
storagegateway:ListFileSharesMetadata
storagegateway:ListGatewaysMetadata
storagegateway:ListLocalDisksMetadata
storagegateway:ListTagsForResourceMetadata
storagegateway:ListTapePoolsMetadata
storagegateway:ListTapesMetadata
storagegateway:ListVolumeInitiatorsMetadata
storagegateway:ListVolumeRecoveryPointsMetadata
storagegateway:ListVolumesMetadata
storagegateway:NotifyWhenUploadedOperatorOperators can enable the NotifyWhenUploaded action.
storagegateway:RefreshCacheOperator
storagegateway:RemoveTagsFromResourceOperatorOperators can remove tags from all resources.
storagegateway:ResetCacheOperatorCan only reset caches that have experienced errors.
storagegateway:RetrieveTapeArchiveOperatorOperators can retrieve archived tapes.
storagegateway:RetrieveTapeRecoveryPointOperatorOperators can retrieve recovery points for the specific tape. The retrieved tape is read only.
storagegateway:SetLocalConsolePasswordAdminConsole passwords are managed by admins.
storagegateway:SetSMBGuestPasswordAdmin
storagegateway:ShutdownGatewayOperatorShutdown gateways can be started again.
storagegateway:StartAvailabilityMonitorTestOperator
storagegateway:StartGatewayOperatorOperators can restart shutdown gateways.
storagegateway:UpdateAutomaticTapeCreationPolicyAdmin
storagegateway:UpdateBandwidthRateLimitOperatorGateway bandwidth rate limits are managed by operators.
storagegateway:UpdateChapCredentialsAdminAdmins manage CHAP credentials.
storagegateway:UpdateGatewayInformationAdminAdmins manage gateway names and timezones.
storagegateway:UpdateGatewaySoftwareNowOperatorOperators can update gateway software.
storagegateway:UpdateMaintenanceStartTimeOperatorOperators can set weekly maintenance start times.
storagegateway:UpdateNFSFileShareAdminAdmins manage NFS file shares.
storagegateway:UpdateSMBFileShareAdmin
storagegateway:UpdateSMBSecurityStrategyAdmin
storagegateway:UpdateSnapshotScheduleOperatorOperators can manage when snapshots are created. Old snapshots are not deleted according to this schedule.
storagegateway:UpdateVTLDeviceTypeOperatorUpdate medium changer in an already activated gateway-VTL.