Skip to content

Commit c6c59f4

Browse files
committed
Updates AWS managed policies
1 parent f9c281b commit c6c59f4

File tree

5 files changed

+107
-1
lines changed

5 files changed

+107
-1
lines changed
Lines changed: 63 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,63 @@
1+
{
2+
"Version": "2012-10-17",
3+
"Statement": [
4+
{
5+
"Sid": "AmazonRoute53GlobalResolverFullAccess",
6+
"Effect": "Allow",
7+
"Action": [
8+
"ec2:DescribeRegions",
9+
"route53:GetHostedZone",
10+
"route53:ListHostedZones",
11+
"route53globalresolver:AllowVendedLogDeliveryForResource",
12+
"route53globalresolver:AssociateHostedZone",
13+
"route53globalresolver:BatchCreateFirewallRule",
14+
"route53globalresolver:BatchDeleteFirewallRule",
15+
"route53globalresolver:BatchUpdateFirewallRule",
16+
"route53globalresolver:CreateAccessSource",
17+
"route53globalresolver:CreateAccessToken",
18+
"route53globalresolver:CreateDNSView",
19+
"route53globalresolver:CreateFirewallDomainList",
20+
"route53globalresolver:CreateFirewallRule",
21+
"route53globalresolver:CreateGlobalResolver",
22+
"route53globalresolver:DeleteAccessSource",
23+
"route53globalresolver:DeleteAccessToken",
24+
"route53globalresolver:DeleteDNSView",
25+
"route53globalresolver:DeleteFirewallDomainList",
26+
"route53globalresolver:DeleteFirewallRule",
27+
"route53globalresolver:DeleteGlobalResolver",
28+
"route53globalresolver:DisableDNSView",
29+
"route53globalresolver:DisassociateHostedZone",
30+
"route53globalresolver:EnableDNSView",
31+
"route53globalresolver:GetAccessSource",
32+
"route53globalresolver:GetAccessToken",
33+
"route53globalresolver:GetDNSView",
34+
"route53globalresolver:GetFirewallDomainList",
35+
"route53globalresolver:GetFirewallRule",
36+
"route53globalresolver:GetGlobalResolver",
37+
"route53globalresolver:GetHostedZoneAssociation",
38+
"route53globalresolver:GetManagedFirewallDomainList",
39+
"route53globalresolver:ImportFirewallDomains",
40+
"route53globalresolver:ListAccessSources",
41+
"route53globalresolver:ListAccessTokens",
42+
"route53globalresolver:ListDNSViews",
43+
"route53globalresolver:ListFirewallDomainLists",
44+
"route53globalresolver:ListFirewallDomains",
45+
"route53globalresolver:ListFirewallRules",
46+
"route53globalresolver:ListGlobalResolvers",
47+
"route53globalresolver:ListHostedZoneAssociations",
48+
"route53globalresolver:ListManagedFirewallDomainLists",
49+
"route53globalresolver:ListTagsForResource",
50+
"route53globalresolver:TagResource",
51+
"route53globalresolver:UntagResource",
52+
"route53globalresolver:UpdateAccessSource",
53+
"route53globalresolver:UpdateAccessToken",
54+
"route53globalresolver:UpdateDNSView",
55+
"route53globalresolver:UpdateFirewallDomains",
56+
"route53globalresolver:UpdateFirewallRule",
57+
"route53globalresolver:UpdateGlobalResolver",
58+
"route53globalresolver:UpdateHostedZoneAssociation"
59+
],
60+
"Resource": "*"
61+
}
62+
]
63+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"Version": "2012-10-17",
3+
"Statement": [
4+
{
5+
"Sid": "AmazonRoute53GlobalResolverReadOnlyAccess",
6+
"Effect": "Allow",
7+
"Action": [
8+
"route53globalresolver:GetAccessSource",
9+
"route53globalresolver:GetAccessToken",
10+
"route53globalresolver:GetDNSView",
11+
"route53globalresolver:GetFirewallDomainList",
12+
"route53globalresolver:GetFirewallRule",
13+
"route53globalresolver:GetGlobalResolver",
14+
"route53globalresolver:GetHostedZoneAssociation",
15+
"route53globalresolver:GetManagedFirewallDomainList",
16+
"route53globalresolver:ListAccessSources",
17+
"route53globalresolver:ListAccessTokens",
18+
"route53globalresolver:ListDNSViews",
19+
"route53globalresolver:ListFirewallDomainLists",
20+
"route53globalresolver:ListFirewallDomains",
21+
"route53globalresolver:ListFirewallRules",
22+
"route53globalresolver:ListGlobalResolvers",
23+
"route53globalresolver:ListHostedZoneAssociations",
24+
"route53globalresolver:ListManagedFirewallDomainLists"
25+
],
26+
"Resource": "*"
27+
}
28+
]
29+
}

docs/source/_static/managed-policies/index.json

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

lib/generated/aws-managed-policies/cdk-iam-floyd.ts

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1959,6 +1959,16 @@ export class AwsManagedPolicy extends AwsManagedPolicyStatic {
19591959
return aws_iam.ManagedPolicy.fromAwsManagedPolicyName(AwsManagedPolicyStatic.AmazonRoute53FullAccess);
19601960
}
19611961

1962+
/** Provides full access to retrieve, list, create, update, and delete all Amazon Route 53 Global Resolver resources. */
1963+
public AmazonRoute53GlobalResolverFullAccess(): aws_iam.IManagedPolicy {
1964+
return aws_iam.ManagedPolicy.fromAwsManagedPolicyName(AwsManagedPolicyStatic.AmazonRoute53GlobalResolverFullAccess);
1965+
}
1966+
1967+
/** Provides read only access to retrieve and list all Amazon Route 53 Global Resolver resources. */
1968+
public AmazonRoute53GlobalResolverReadOnlyAccess(): aws_iam.IManagedPolicy {
1969+
return aws_iam.ManagedPolicy.fromAwsManagedPolicyName(AwsManagedPolicyStatic.AmazonRoute53GlobalResolverReadOnlyAccess);
1970+
}
1971+
19621972
/** This policy grants full access to Amazon Route 53 Profile resources. */
19631973
public AmazonRoute53ProfilesFullAccess(): aws_iam.IManagedPolicy {
19641974
return aws_iam.ManagedPolicy.fromAwsManagedPolicyName(AwsManagedPolicyStatic.AmazonRoute53ProfilesFullAccess);

lib/generated/aws-managed-policies/iam-floyd.ts

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -780,6 +780,10 @@ export class AwsManagedPolicy {
780780
public static AmazonRoute53DomainsReadOnlyAccess = 'AmazonRoute53DomainsReadOnlyAccess';
781781
/** Provides full access to all Amazon Route 53 via the AWS Management Console. */
782782
public static AmazonRoute53FullAccess = 'AmazonRoute53FullAccess';
783+
/** Provides full access to retrieve, list, create, update, and delete all Amazon Route 53 Global Resolver resources. */
784+
public static AmazonRoute53GlobalResolverFullAccess = 'AmazonRoute53GlobalResolverFullAccess';
785+
/** Provides read only access to retrieve and list all Amazon Route 53 Global Resolver resources. */
786+
public static AmazonRoute53GlobalResolverReadOnlyAccess = 'AmazonRoute53GlobalResolverReadOnlyAccess';
783787
/** This policy grants full access to Amazon Route 53 Profile resources. */
784788
public static AmazonRoute53ProfilesFullAccess = 'AmazonRoute53ProfilesFullAccess';
785789
/** This policy grants read-only access to Amazon Route 53 Profile resources. */

0 commit comments

Comments
 (0)