GovCloud
Secure your government workloads with JupiterOne's AWS GovCloud integration. Our guide walks you through the installation process and showcases the integration's data model, providing you with comprehensive visibility into your GovCloud environment. Learn how AWS GovCloud integration can help you monitor and manage your security posture, ensuring that you meet government security and compliance requirements
- Installation
- Authorization
- Data Model
- Types
Installation
To install this integration, you will need to configure settings both within AWS GovCloud and on JupiterOne. Unlike the commercial AWS integration, which assumes an IAM role, the GovCloud integration authenticates with the Access Key ID and Secret Access Key of a dedicated IAM user, along with the Account ID of the GovCloud account to synchronize.
Information is ingested from the AWS GovCloud regions us-gov-east-1 and us-gov-west-1. A small number of AWS services are only offered in us-gov-west-1, and are ingested from that region only.
The GovCloud integration runs the same ingestion code as the commercial AWS integration, so it produces the same entities and relationships. See the Data Model and Types tabs for the full list. Resource ARNs use the aws-us-gov partition.
Configuration in AWS GovCloud
JupiterOne maintains the IAM policy, the CloudFormation template, and the Terraform for GovCloud in the public JupiterOne AWS CloudFormation project on GitHub. Use one of the three options below. CloudFormation is recommended, because the permission set is kept up to date there as the integration adds coverage for new services.
Option 1: CloudFormation (recommended)
- Download the latest GovCloud CloudFormation template: iam-cloudformation-govcloud.json.
- In the AWS GovCloud Console, go to CloudFormation and select Stacks.
- Select Create stack, then With new resources (standard).
- Select Template is ready and Upload a template file, upload the file you downloaded, and click Next.
- Enter
JupiterOneAccessas the stack name, then click Next. - On the Review and create page, accept the checkbox labeled I acknowledge that AWS CloudFormation might create IAM resources with custom names. JupiterOne uses this permission to create the
JupiterOneSecurityAuditmanaged policy; you can review the exact permissions it grants in managed-policy.md. - Click Submit.
The stack creates an IAM user named JupiterOneAccessUser with the AWS-managed SecurityAudit policy and the JupiterOneSecurityAudit policy attached. Continue to Create an access key.
Option 2: Terraform
- Download the latest GovCloud Terraform: terraform.tf.
- Apply it in each AWS GovCloud account you want to ingest.
The Terraform creates an IAM user named jupiterone-access-user with the same two policies attached. Continue to Create an access key.
Option 3: Manual configuration
- From the AWS GovCloud Console, search for and select IAM under Services.
- Select Policies, click Create policy, and select the JSON tab.
- Paste the policy document from managed-policy.md. This is the same document deployed by the CloudFormation template and is the authoritative permission set.
- Click Next, enter
JupiterOneSecurityAuditas the name, and click Create policy. - Go to Users and select Create user. Enter
JupiterOneAccessUseras the user name. - On the permissions step, select Attach policies directly and select both SecurityAudit (the AWS-managed policy) and the JupiterOneSecurityAudit policy you just created.
- Click Next, review the user information, and click Create user.
Keep the manually created policy in sync with managed-policy.md. A policy that drifts behind the maintained one causes individual ingestion steps to fail with access-denied errors as the integration adds coverage for new services.
Create an access key
- In the IAM console, open the user created above (
JupiterOneAccessUserfor CloudFormation and manual setups,jupiterone-access-userfor Terraform). - Select the Security credentials tab.
- Under Access keys, click Create access key.
- Select Other, then create the access key.
- Copy both the Access key ID and the Secret access key (click Show to display it). These values are needed for the JupiterOne configuration and the secret cannot be retrieved again after you leave this page.
Set Permissions
The GovCloud integration requires security auditor permissions in the target AWS GovCloud account, defined by the combination of the AWS-managed SecurityAudit policy and the additional List*, Get*, and Describe* permissions that SecurityAudit does not cover. The exact policy and permission statements are maintained in the public JupiterOne AWS CloudFormation project.
For the permissions required by each individual ingestion source, see the Authorization tab.
Configuration in JupiterOne
- From the top navigation of the J1 Search homepage, select Integrations.
- Scroll to the GovCloud integration tile and click it.
- Click New instance and configure the following settings:
- The Account Name used to identify this AWS GovCloud account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. - A Description to assist in identifying the integration instance, if desired.
- A Polling Interval that fits your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. - The Account ID of the AWS GovCloud account you are ingesting data from.
- The Access Key ID of the IAM user created above.
- The Secret Access Key associated with the Access Key ID.
- The Account Name used to identify this AWS GovCloud account in JupiterOne. Ingested entities will have this value stored in
- Click Create Configuration after all values are provided.
Service Control Policy Issues
Errors may occur if a Service Control Policy (SCP) is blocking specified services or regions. AWS services that JupiterOne cannot ingest are listed in the Integration Jobs logs (Integrations > Configurations > Settings > Jobs).
For each SCP that is blocking JupiterOne ingestion, add the following condition to your SCP JSON. Note the aws-us-gov partition in the ARN:
"Condition": {
"ArnNotLike": {
"aws:PrincipalARN": [
"arn:aws-us-gov:iam::*:user/JupiterOne*",
"arn:aws-us-gov:iam::*:user/jupiterone*"
]
}
}
Ensure these ARNs match the IAM user used to configure your JupiterOne GovCloud integration.
See the AWS Service control policies documentation for the latest information.
Differences from the commercial AWS integration
Both integrations ingest the same entity types, but the GovCloud integration instance offers a smaller set of configuration options:
| Capability | AWS | GovCloud |
|---|---|---|
| Authentication | Role ARN with an External ID, optionally chained through an intermediate role | Account ID with an IAM user Access Key ID and Secret Access Key |
| Regions | All AWS regions that do not require additional contractual arrangements with AWS | us-gov-east-1 and us-gov-west-1 |
| ARN partition | aws | aws-us-gov |
| Organization account management | Supported. Sub-account instances are created and managed automatically. | Not supported. Configure one integration instance per GovCloud account. |
| Ingestion window and data filtering options | Configurable per instance (ECR, Inspector V2, and Security Hub findings) | Not configurable. Defaults apply. |
| Ingestion sources | Individually toggleable | Individually toggleable |
Reference
S3 Bucket public Property
The aws_s3_bucket.public property is calculated based on the Access field in the AWS S3 console:
| Access | aws_s3_bucket.public |
|---|---|
| Public | true |
| Objects can be public | undefined |
| Bucket and objects not public | false |
AWS IAM Policies
Each aws_iam_policy entity includes a boolean admin property that indicates whether the policy grants administrative-level access. The flag is determined from the policy name: if the name contains the word "admin" (case-insensitive), the flag is set to true. Examples: AdministratorAccess, AdminPolicy, MyCustomAdminRole.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. See the Instance management guide to learn more about working with and editing integration instances.
Permissions
IAM permissions that must be granted to the integration principal for data ingestion.
Show Permissions (765)
access-analyzer:ListAnalyzersaccess-analyzer:ListFindingsaccount:GetAlternateContactaccount:GetContactInformationacm-pca:ListCertificateAuthoritiesacm-pca:ListTagsacm:DescribeCertificateacm:ListCertificatesacm:ListTagsForCertificateaidevops:DescribePrivateConnectionaidevops:GetAgentSpaceaidevops:GetOperatorAppaidevops:GetServiceaidevops:ListAgentSpacesaidevops:ListAssociationsaidevops:ListPrivateConnectionsaidevops:ListServicesairflow:GetEnvironmentairflow:ListEnvironmentsapigateway:GET arn:aws:apigateway:*::/apisapigateway:GET arn:aws:apigateway:*::/apis/*/authorizersapigateway:GET arn:aws:apigateway:*::/apis/*/integrationsapigateway:GET arn:aws:apigateway:*::/apis/*/routesapigateway:GET arn:aws:apigateway:*::/apis/*/stagesapigateway:GET arn:aws:apigateway:*::/domainnamesapigateway:GET arn:aws:apigateway:*::/domainnames/*/apimappingsapigateway:GET arn:aws:apigateway:*::/restapisapigateway:GET arn:aws:apigateway:*::/restapis/*/authorizersapigateway:GET arn:aws:apigateway:*::/restapis/*/authorizers/*apigateway:GET arn:aws:apigateway:*::/restapis/*/resourcesapigateway:GET arn:aws:apigateway:*::/restapis/*/resources/*apigateway:GET arn:aws:apigateway:*::/restapis/*/resources/*/methods/*apigateway:GET arn:aws:apigateway:*::/restapis/*/resources/*/methods/*/integrationapigateway:GET arn:aws:apigateway:*::/restapis/*/stagesapigateway:GET arn:aws:apigateway:*::/restapis/*/stages/*appconfig:GetAccountSettingsappconfig:GetConfigurationProfileappconfig:GetDeploymentappconfig:ListApplicationsappconfig:ListConfigurationProfilesappconfig:ListDeploymentStrategiesappconfig:ListDeploymentsappconfig:ListEnvironmentsappconfig:ListHostedConfigurationVersionsappconfig:ListTagsForResourceapplication-autoscaling:DescribeScalableTargetsapplication-autoscaling:DescribeScalingPoliciesaps:DescribeLoggingConfigurationaps:DescribeQueryLoggingConfigurationaps:DescribeResourcePolicyaps:DescribeScraperaps:DescribeWorkspaceaps:DescribeWorkspaceConfigurationaps:ListScrapersaps:ListWorkspacesathena:GetWorkGroupathena:ListTagsForResourceathena:ListWorkGroupsauditmanager:GetAssessmentauditmanager:GetAssessmentFrameworkauditmanager:GetControlauditmanager:GetDelegationsauditmanager:GetEvidenceFoldersByAssessmentControlauditmanager:GetSettingsauditmanager:ListAssessmentFrameworksauditmanager:ListAssessmentsauditmanager:ListControlsauditmanager:ListTagsForResourceautoscaling:DescribeAutoScalingGroupsautoscaling:DescribeLaunchConfigurationsautoscaling:DescribePoliciesaws-marketplace:GetEntitlementsaws-marketplace:ListEntitiesbackup:GetBackupVaultAccessPolicybackup:ListBackupJobsbackup:ListBackupPlansbackup:ListBackupVaultsbackup:ListCopyJobsbackup:ListRecoveryPointsByBackupVaultbackup:ListRestoreJobsbackup:ListRestoreTestingPlansbackup:ListTagsbackup:ListTagsForResourcebatch:DescribeComputeEnvironmentsbatch:DescribeJobDefinitionsbatch:DescribeJobQueuesbatch:ListJobsbedrock-agentcore:GetAgentRuntimebedrock-agentcore:GetCodeInterpreterbedrock-agentcore:ListAgentRuntimesbedrock-agentcore:ListCodeInterpretersbedrock:GetAgentbedrock:GetAgentActionGroupbedrock:GetCustomModelbedrock:GetDataSourcebedrock:GetEvaluationJobbedrock:GetFlowbedrock:GetFoundationModelAvailabilitybedrock:GetGuardrailbedrock:GetImportedModelbedrock:GetInferenceProfilebedrock:GetKnowledgeBasebedrock:GetModelCustomizationJobbedrock:GetModelInvocationLoggingConfigurationbedrock:GetProvisionedModelThroughputbedrock:ListAgentActionGroupsbedrock:ListAgentsbedrock:ListCustomModelsbedrock:ListDataSourcesbedrock:ListEvaluationJobsbedrock:ListFlowsbedrock:ListFoundationModelsbedrock:ListGuardrailsbedrock:ListImportedModelsbedrock:ListInferenceProfilesbedrock:ListKnowledgeBasesbedrock:ListModelCustomizationJobsbedrock:ListModelInvocationJobsbedrock:ListProvisionedModelThroughputsbedrock:ListTagsForResourcecassandra:Selectcloudformation:DescribeStackscloudformation:ListStackscloudfront:GetDistributionConfigcloudfront:ListDistributionscloudfront:ListKeyGroupscloudfront:ListPublicKeyscloudfront:ListTagsForResourcecloudhsm:DescribeBackupscloudhsm:DescribeClusterscloudhsm:ListTagscloudtrail:DescribeTrailscloudtrail:GetEventSelectorscloudtrail:GetTrailStatuscloudtrail:ListTagscloudwatch:DescribeAlarmscloudwatch:GetMetricDatacloudwatch:ListTagsForResourcecodeartifact:DescribeDomaincodeartifact:DescribeRepositorycodeartifact:GetDomainPermissionsPolicycodeartifact:GetRepositoryEndpointcodeartifact:GetRepositoryPermissionsPolicycodeartifact:ListDomainscodeartifact:ListPackageGroupscodeartifact:ListPackagescodeartifact:ListRepositoriescodeartifact:ListTagsForResourcecodebuild:BatchGetProjectscodebuild:BatchGetReportGroupscodebuild:GetResourcePolicycodebuild:ListProjectscodebuild:ListReportGroupscodecommit:GetRepositorycodecommit:ListRepositoriescodecommit:ListTagsForResourcecodedeploy:BatchGetApplicationscodedeploy:BatchGetDeploymentGroupscodedeploy:GetDeploymentConfigcodedeploy:ListApplicationscodedeploy:ListDeploymentConfigscodedeploy:ListDeploymentGroupscodedeploy:ListTagsForResourcecodeguru-profiler:ListProfilingGroupscodeguru-reviewer:DescribeRepositoryAssociationcodeguru-reviewer:ListRepositoryAssociationscodeguru-reviewer:ListTagsForResourcecodepipeline:GetPipelinecodepipeline:ListPipelinescognito-identity:DescribeIdentityPoolcognito-identity:ListIdentityPoolscognito-idp:DescribeRiskConfigurationcognito-idp:DescribeUserPoolcognito-idp:DescribeUserPoolClientcognito-idp:DescribeUserPoolDomaincognito-idp:ListUserPoolClientscognito-idp:ListUserPoolscognito-idp:ListUsersconfig:BatchGetResourceConfigconfig:DescribeComplianceByConfigRuleconfig:DescribeConfigRulesconfig:GetComplianceDetailsByConfigRuledatasync:DescribeLocationEfsdatasync:DescribeLocationFsxLustredatasync:DescribeLocationFsxOntapdatasync:DescribeLocationFsxOpenZfsdatasync:DescribeLocationFsxWindowsdatasync:DescribeLocationHdfsdatasync:DescribeLocationNfsdatasync:DescribeLocationObjectStoragedatasync:DescribeLocationS3datasync:DescribeLocationSmbdatasync:DescribeTaskdatasync:ListLocationsdatasync:ListTagsForResourcedatasync:ListTasksdax:DescribeClustersdetective:GetInvestigationdetective:ListGraphsdetective:ListInvestigationsdetective:ListTagsForResourcedevops-guru:DescribeAccountHealthdevops-guru:DescribeServiceIntegrationdevops-guru:ListAnomaliesForInsightdevops-guru:ListInsightsdevops-guru:ListNotificationChannelsdirectconnect:DescribeConnectionsdirectconnect:DescribeDirectConnectGatewaysdirectconnect:DescribeLagsdirectconnect:DescribeVirtualInterfacesdms:DescribeEndpointsdms:DescribeReplicationInstancesdms:ListTagsForResourceds:DescribeDirectoriesdynamodb:DescribeContinuousBackupsdynamodb:DescribeGlobalTabledynamodb:DescribeTabledynamodb:ListBackupsdynamodb:ListGlobalTablesdynamodb:ListTablesdynamodb:ListTagsOfResourceec2:DescribeAddressesec2:DescribeCustomerGatewaysec2:DescribeFlowLogsec2:DescribeHostsec2:DescribeIamInstanceProfileAssociationsec2:DescribeImageAttributeec2:DescribeImagesec2:DescribeInstanceAttributeec2:DescribeInstancesec2:DescribeInternetGatewaysec2:DescribeKeyPairsec2:DescribeLaunchTemplateVersionsec2:DescribeLaunchTemplatesec2:DescribeManagedPrefixListsec2:DescribeNatGatewaysec2:DescribeNetworkAclsec2:DescribeNetworkInterfacesec2:DescribeRegionsec2:DescribeRouteTablesec2:DescribeSecurityGroupRulesec2:DescribeSecurityGroupsec2:DescribeSnapshotAttributeec2:DescribeSnapshotsec2:DescribeSubnetsec2:DescribeTransitGatewayAttachmentsec2:DescribeTransitGatewayRouteTablesec2:DescribeTransitGatewayVpcAttachmentsec2:DescribeTransitGatewaysec2:DescribeVolumesec2:DescribeVpcEndpointConnectionsec2:DescribeVpcEndpointServiceConfigurationsec2:DescribeVpcEndpointServicePermissionsec2:DescribeVpcEndpointServicesec2:DescribeVpcEndpointsec2:DescribeVpcPeeringConnectionsec2:DescribeVpcsec2:DescribeVpnConnectionsec2:DescribeVpnGatewaysec2:GetEbsDefaultKmsKeyIdec2:GetEbsEncryptionByDefaultec2:GetManagedPrefixListEntriesecr:DescribeImageScanFindingsecr:DescribeImagesecr:DescribeRepositoriesecr:GetLifecyclePolicyecr:GetRepositoryPolicyecr:ListTagsForResourceecs:DescribeClustersecs:DescribeContainerInstancesecs:DescribeServicesecs:DescribeTaskDefinitionecs:DescribeTasksecs:ListClustersecs:ListContainerInstancesecs:ListServicesecs:ListTaskDefinitionFamiliesecs:ListTaskseks:DescribeClustereks:DescribeClusterVersionseks:DescribeNodegroupeks:ListClusterseks:ListNodegroupselasticache:DescribeCacheClusterselasticache:DescribeCacheSubnetGroupselasticache:DescribeReplicationGroupselasticache:DescribeSnapshotselasticache:ListTagsForResourceelasticfilesystem:DescribeFileSystemPolicyelasticfilesystem:DescribeFileSystemselasticfilesystem:DescribeMountTargetSecurityGroupselasticfilesystem:DescribeMountTargetselasticloadbalancing:DescribeListenerselasticloadbalancing:DescribeLoadBalancerAttributeselasticloadbalancing:DescribeLoadBalancerselasticloadbalancing:DescribeRuleselasticloadbalancing:DescribeTagselasticloadbalancing:DescribeTargetGroupselasticloadbalancing:DescribeTargetHealthelasticmapreduce:DescribeClusterelasticmapreduce:DescribeSecurityConfigurationelasticmapreduce:ListClusterselasticmapreduce:ListInstanceselasticmapreduce:ListSecurityConfigurationsemr-serverless:GetApplicationemr-serverless:ListApplicationses:DescribeDomainses:DescribeElasticsearchDomainses:ListDomainNameses:ListTagsevents:DescribeApiDestinationevents:DescribeArchiveevents:DescribeConnectionevents:DescribeEventBusevents:ListApiDestinationsevents:ListArchivesevents:ListConnectionsevents:ListEndpointsevents:ListEventBusesevents:ListRulesevents:ListTagsForResourceevents:ListTargetsByRulefirehose:DescribeDeliveryStreamfirehose:ListDeliveryStreamsfirehose:ListTagsForDeliveryStreamfms:ListAppsListsfms:ListPoliciesfms:ListProtocolsListsfms:ListResourceSetResourcesfms:ListResourceSetsfms:ListTagsForResourcefsx:DescribeFileSystemsglacier:GetVaultAccessPolicyglacier:GetVaultLockglacier:ListTagsForVaultglacier:ListVaultsglobalaccelerator:ListAcceleratorsglobalaccelerator:ListCustomRoutingAcceleratorsglobalaccelerator:ListCustomRoutingEndpointGroupsglobalaccelerator:ListCustomRoutingListenersglobalaccelerator:ListEndpointGroupsglobalaccelerator:ListListenersglobalaccelerator:ListTagsForResourceglue:GetConnectionglue:GetConnectionsglue:GetDataCatalogEncryptionSettingsglue:GetDatabaseglue:GetDatabasesglue:GetDevEndpointglue:GetDevEndpointsglue:GetJobglue:GetResourcePolicyglue:GetSecurityConfigurationsglue:GetTagsglue:ListJobsglue:ListSessionsgrafana:DescribeWorkspacegrafana:ListWorkspacesguardduty:DescribeOrganizationConfigurationguardduty:DescribePublishingDestinationguardduty:GetDetectorguardduty:GetFindingsguardduty:ListDetectorsguardduty:ListFindingsguardduty:ListOrganizationAdminAccountsguardduty:ListPublishingDestinationshealth:DescribeEventDetailshealth:DescribeEventsiam:GenerateCredentialReportiam:GetAccessKeyLastUsediam:GetAccountPasswordPolicyiam:GetAccountSummaryiam:GetCredentialReportiam:GetGroupiam:GetGroupPolicyiam:GetOpenIDConnectProvideriam:GetPolicyVersioniam:GetRoleiam:GetRolePolicyiam:GetSAMLProvideriam:GetServerCertificateiam:GetUseriam:GetUserPolicyiam:ListAccessKeysiam:ListAccountAliasesiam:ListEntitiesForPolicyiam:ListGroupPoliciesiam:ListGroupsiam:ListInstanceProfilesiam:ListMFADevicesiam:ListOpenIDConnectProviderTagsiam:ListOpenIDConnectProvidersiam:ListPoliciesiam:ListRolePoliciesiam:ListRoleTagsiam:ListRolesiam:ListSAMLProvidersiam:ListServerCertificatesiam:ListServiceSpecificCredentialsiam:ListUserPoliciesiam:ListUserTagsiam:ListUsersidentitystore:ListGroupMembershipsidentitystore:ListGroupsidentitystore:ListUsersimagebuilder:GetComponentimagebuilder:GetContainerRecipeimagebuilder:GetDistributionConfigurationimagebuilder:GetImageimagebuilder:GetImagePipelineimagebuilder:GetInfrastructureConfigurationimagebuilder:GetLifecyclePolicyimagebuilder:GetWorkflowimagebuilder:ListComponentsimagebuilder:ListContainerRecipesimagebuilder:ListDistributionConfigurationsimagebuilder:ListImageBuildVersionsimagebuilder:ListImagePipelinesimagebuilder:ListImagesimagebuilder:ListInfrastructureConfigurationsimagebuilder:ListLifecyclePoliciesimagebuilder:ListWorkflowsinspector2:DescribeOrganizationConfigurationinspector2:GetConfigurationinspector2:GetDelegatedAdminAccountinspector2:GetEncryptionKeyinspector2:ListCisScanResultsAggregatedByTargetResourceinspector2:ListCisScansinspector2:ListCoverageinspector2:ListFiltersinspector2:ListFindingsinspector2:ListTagsForResourceinspector:DescribeAssessmentRunsinspector:DescribeFindingsinspector:DescribeRulesPackagesinspector:ListAssessmentRunsinspector:ListFindingskafka:GetBootstrapBrokerskafka:ListClustersV2kafka:ListTagsForResourcekinesis:DescribeStreamSummarykinesis:ListStreamConsumerskinesis:ListStreamskinesis:ListTagsForStreamkms:DescribeKeykms:GetKeyPolicykms:GetKeyRotationStatuskms:ListAliaseskms:ListKeyskms:ListResourceTagslambda:GetFunctionlambda:GetFunctionUrlConfiglambda:GetPolicylambda:ListCodeSigningConfigslambda:ListFunctionslambda:ListFunctionsByCodeSigningConfiglambda:ListTagslex:DescribeResourcePolicylex:ListBotAliaseslex:ListBotslicense-manager:ListLicenseslicense-manager:ListReceivedLicenseslogs:DescribeDestinationslogs:DescribeLogGroupslogs:DescribeMetricFilterslogs:DescribeSubscriptionFiltersmacie2:DescribeClassificationJobmacie2:DescribeOrganizationConfigurationmacie2:GetAutomatedDiscoveryConfigurationmacie2:GetClassificationExportConfigurationmacie2:GetFindingsmacie2:GetFindingsPublicationConfigurationmacie2:ListAutomatedDiscoveryAccountsmacie2:ListClassificationJobsmacie2:ListFindingsmacie2:ListOrganizationAdminAccountsmq:DescribeBrokermq:ListBrokersneptune-graph:GetGraphneptune-graph:GetImportTaskneptune-graph:ListExportTasksneptune-graph:ListGraphSnapshotsneptune-graph:ListGraphsneptune-graph:ListImportTasksneptune-graph:ListPrivateGraphEndpointsneptune-graph:ListTagsForResourceneptune:DescribeDBClustersneptune:DescribeDBInstancesnetwork-firewall:DescribeFirewallnetwork-firewall:DescribeFirewallPolicynetwork-firewall:DescribeRuleGroupnetwork-firewall:ListFirewallPoliciesnetwork-firewall:ListFirewallsnetwork-firewall:ListRuleGroupsnetworkmanager:GetConnectPeernetworkmanager:GetCoreNetworknetworkmanager:GetCoreNetworkPolicynetworkmanager:ListAttachmentRoutingPolicyAssociationsnetworkmanager:ListAttachmentsnetworkmanager:ListConnectPeersnetworkmanager:ListCoreNetworkPolicyVersionsnetworkmanager:ListCoreNetworkRoutingInformationnetworkmanager:ListCoreNetworksnova-act:GetWorkflowDefinitionnova-act:GetWorkflowRunnova-act:ListModelsnova-act:ListWorkflowDefinitionsnova-act:ListWorkflowRunsorganizations:DescribeAccountorganizations:DescribeOrganizationorganizations:DescribeOrganizationalUnitorganizations:DescribePolicyorganizations:ListAccountsorganizations:ListChildrenorganizations:ListPoliciesorganizations:ListRootsorganizations:ListTagsForResourceorganizations:ListTargetsForPolicyquicksight:DescribeAccountSettingsquicksight:DescribeAccountSubscriptionquicksight:DescribeDashboardquicksight:DescribeDashboardPermissionsquicksight:DescribeDataSetquicksight:DescribeDataSourcequicksight:DescribeIpRestrictionquicksight:DescribeKeyRegistrationquicksight:DescribeVpcConnectionquicksight:ListCustomPermissionsquicksight:ListDashboardsquicksight:ListDataSetsquicksight:ListDataSourcesquicksight:ListGroupMembershipsquicksight:ListGroupsquicksight:ListNamespacesquicksight:ListTagsForResourcequicksight:ListUsersquicksight:ListVpcConnectionsram:GetResourceShareAssociationsram:GetResourceShareInvitationsram:GetResourceSharesram:ListResourcesrds:DescribeDBClusterParameterGroupsrds:DescribeDBClusterParametersrds:DescribeDBClusterSnapshotsrds:DescribeDBClustersrds:DescribeDBInstancesrds:DescribeDBParameterGroupsrds:DescribeDBParametersrds:DescribeDBProxiesrds:DescribeDBProxyTargetGroupsrds:DescribeDBProxyTargetsrds:DescribeDBSnapshotsrds:DescribeDBSubnetGroupsrds:DescribeOptionGroupsredshift-serverless:ListEndpointAccessredshift-serverless:ListNamespacesredshift-serverless:ListRecoveryPointsredshift-serverless:ListSnapshotsredshift-serverless:ListTagsForResourceredshift-serverless:ListUsageLimitsredshift-serverless:ListWorkgroupsredshift:DescribeClusterParameterGroupsredshift:DescribeClusterParametersredshift:DescribeClustersredshift:DescribeDataSharesredshift:DescribeLoggingStatusresource-explorer-2:GetDefaultViewresource-explorer-2:GetIndexresource-explorer-2:GetViewresource-explorer-2:ListIndexesresource-explorer-2:ListTagsForResourceresource-explorer-2:ListViewsrolesanywhere:GetProfilerolesanywhere:GetTrustAnchorrolesanywhere:ListProfilesrolesanywhere:ListTagsForResourcerolesanywhere:ListTrustAnchorsroute53:GetHostedZoneroute53:ListHostedZonesroute53:ListResourceRecordSetsroute53domains:GetDomainDetailroute53domains:ListDomainsroute53domains:ListTagsForDomainroute53resolver:ListResolverRuleAssociationsroute53resolver:ListResolverRulesroute53resolver:ListTagsForResources3:GetAccountPublicAccessBlocks3:GetBucketAcls3:GetBucketLocations3:GetBucketLoggings3:GetBucketNotifications3:GetBucketObjectLockConfigurations3:GetBucketOwnershipControlss3:GetBucketPolicys3:GetBucketPolicyStatuss3:GetBucketPublicAccessBlocks3:GetBucketTaggings3:GetBucketVersionings3:GetBucketWebsites3:GetEncryptionConfigurations3:GetInventoryConfigurations3:GetLifecycleConfigurations3:GetReplicationConfigurations3:ListAccessPointss3:ListAllMyBucketssagemaker:DescribeDomainsagemaker:DescribeEndpointsagemaker:DescribeEndpointConfigsagemaker:DescribeFeatureGroupsagemaker:DescribeInferenceRecommendationsJobsagemaker:DescribeModelsagemaker:DescribeModelBiasJobDefinitionsagemaker:DescribeModelQualityJobDefinitionsagemaker:DescribeNotebookInstancesagemaker:DescribePipelineExecutionsagemaker:DescribeProcessingJobsagemaker:DescribeTrainingJobsagemaker:DescribeTransformJobsagemaker:ListDomainssagemaker:ListEndpointssagemaker:ListFeatureGroupssagemaker:ListInferenceRecommendationsJobssagemaker:ListModelBiasJobDefinitionssagemaker:ListModelQualityJobDefinitionssagemaker:ListModelssagemaker:ListNotebookInstancessagemaker:ListPipelineExecutionssagemaker:ListPipelinessagemaker:ListProcessingJobssagemaker:ListTagssagemaker:ListTrainingJobssagemaker:ListTransformJobssecretsmanager:DescribeSecretsecretsmanager:GetResourcePolicysecretsmanager:ListSecretVersionIdssecretsmanager:ListSecretssecurityagent:BatchGetAgentSpacessecurityagent:BatchGetArtifactMetadatasecurityagent:BatchGetTargetDomainssecurityagent:BatchGetThreatModelssecurityagent:ListAgentSpacessecurityagent:ListApplicationssecurityagent:ListArtifactssecurityagent:ListPrivateConnectionssecurityagent:ListTagsForResourcesecurityagent:ListTargetDomainssecurityagent:ListThreatModelssecurityhub:DescribeHubsecurityhub:DescribeStandardssecurityhub:DescribeStandardsControlssecurityhub:GetEnabledStandardssecurityhub:GetFindingsservicecatalog:DescribeConstraintservicecatalog:DescribePortfolioservicecatalog:DescribeProductAsAdminservicecatalog:ListConstraintsForPortfolioservicecatalog:ListLaunchPathsservicecatalog:ListPortfoliosservicecatalog:ListPortfoliosForProductservicecatalog:ListPrincipalsForPortfolioservicecatalog:ListProvisioningArtifactsservicecatalog:ListResourcesForTagOptionservicecatalog:ListTagOptionsservicecatalog:SearchProductsAsAdminservicediscovery:GetInstanceservicediscovery:ListInstancesservicediscovery:ListNamespacesservicediscovery:ListServicesservicediscovery:ListTagsForResourceses:GetConfigurationSetses:GetEmailIdentityses:ListConfigurationSetsses:ListEmailIdentitiesses:ListReceiptFiltersshield:DescribeDRTAccessshield:DescribeEmergencyContactSettingsshield:DescribeSubscriptionshield:GetSubscriptionStateshield:ListProtectionGroupsshield:ListProtectionsshield:ListResourcesInProtectionGroupshield:ListTagsForResourcesigner:GetSigningProfilesigner:ListProfilePermissionssigner:ListSigningJobssigner:ListSigningProfilessns:GetSubscriptionAttributessns:GetTopicAttributessns:ListSubscriptionssns:ListTagsForResourcesns:ListTopicssqs:GetQueueAttributessqs:ListQueueTagssqs:ListQueuesssm:DescribeDocumentPermissionssm:DescribeInstanceInformationssm:DescribeInstancePatchStatesssm:DescribeParametersssm:DescribePatchBaselinesssm:DescribePatchGroupStatessm:DescribePatchGroupsssm:GetDocumentssm:GetServiceSettingssm:ListAssociationsssm:ListComplianceItemsssm:ListComplianceSummariesssm:ListDocumentsssm:ListInventoryEntriesssm:ListTagsForResourcesso:DescribePermissionSetsso:GetInlinePolicyForPermissionSetsso:ListAccountAssignmentssso:ListAccountAssignmentsForPrincipalsso:ListAccountsForProvisionedPermissionSetsso:ListApplicationssso:ListCustomerManagedPolicyReferencesInPermissionSetsso:ListInstancessso:ListManagedPoliciesInPermissionSetsso:ListPermissionSetssso:ListTagsForResourcestates:DescribeStateMachinestates:ListStateMachinesstates:ListTagsForResourcestoragegateway:DescribeCachediSCSIVolumesstoragegateway:DescribeGatewayInformationstoragegateway:DescribeNFSFileSharesstoragegateway:DescribeSMBFileSharesstoragegateway:DescribeStorediSCSIVolumesstoragegateway:DescribeTapeArchivesstoragegateway:ListFileSharesstoragegateway:ListGatewaysstoragegateway:ListTagsForResourcestoragegateway:ListTapePoolsstoragegateway:ListTapesstoragegateway:ListVolumestag:GetResourcestransfer:DescribeServertransfer:ListServerstransfer:ListTagsForResourcetransfer:ListUsersvpc-lattice:ListListenersvpc-lattice:ListServiceNetworkServiceAssociationsvpc-lattice:ListServiceNetworkVpcAssociationsvpc-lattice:ListServiceNetworkVpcEndpointAssociationsvpc-lattice:ListServiceNetworksvpc-lattice:ListServicesvpc-lattice:ListTargetGroupswaf:GetWebACLwaf:ListWebACLswafv2:GetIPSetwafv2:GetLoggingConfigurationwafv2:GetRuleGroupwafv2:GetWebACLwafv2:ListIPSetswafv2:ListResourcesForWebACLwafv2:ListRuleGroupswafv2:ListTagsForResourcewafv2:ListWebACLsworkspaces:DescribeTagsworkspaces:DescribeWorkspaceBundlesworkspaces:DescribeWorkspacesxray:GetEncryptionConfigxray:GetGroupsxray:ListResourcePoliciesxray:ListTagsForResource