instance-ssm-policy.json 1.4 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546
  1. {
  2. "Version": "2012-10-17",
  3. "Statement": [
  4. {
  5. "Effect": "Allow",
  6. "Action": [
  7. "ssm:DescribeAssociation",
  8. "ssm:GetDeployablePatchSnapshotForInstance",
  9. "ssm:GetDocument",
  10. "ssm:DescribeDocument",
  11. "ssm:GetManifest",
  12. "ssm:ListAssociations",
  13. "ssm:ListInstanceAssociations",
  14. "ssm:PutInventory",
  15. "ssm:PutComplianceItems",
  16. "ssm:PutConfigurePackageResult",
  17. "ssm:UpdateAssociationStatus",
  18. "ssm:UpdateInstanceAssociationStatus",
  19. "ssm:UpdateInstanceInformation"
  20. ],
  21. "Resource": "*"
  22. },
  23. {
  24. "Effect": "Allow",
  25. "Action": [
  26. "ssmmessages:CreateControlChannel",
  27. "ssmmessages:CreateDataChannel",
  28. "ssmmessages:OpenControlChannel",
  29. "ssmmessages:OpenDataChannel"
  30. ],
  31. "Resource": "*"
  32. },
  33. {
  34. "Effect": "Allow",
  35. "Action": [
  36. "ec2messages:AcknowledgeMessage",
  37. "ec2messages:DeleteMessage",
  38. "ec2messages:FailMessage",
  39. "ec2messages:GetEndpoint",
  40. "ec2messages:GetMessages",
  41. "ec2messages:SendReply"
  42. ],
  43. "Resource": "*"
  44. }
  45. ]
  46. }