AWS Politiques gérées pour les SageMaker projets et JumpStart - Amazon SageMaker AI

View a markdown version of this page

AWS Politiques gérées pour les SageMaker projets et JumpStart - Amazon SageMaker AI

Les traductions sont fournies par des outils de traduction automatique. En cas de conflit entre le contenu d'une traduction et celui de la version originale en anglais, la version anglaise prévaudra.

AWS Politiques gérées pour les SageMaker projets et JumpStart

Ces politiques AWS gérées ajoutent des autorisations pour utiliser les modèles de projets et les JumpStart solutions Amazon SageMaker AI intégrés. Les politiques sont disponibles dans votre AWS compte et sont utilisées par les rôles d'exécution créés à partir de la console SageMaker AI.

SageMaker Projetez et JumpStart utilisez le catalogue AWS de services pour provisionner AWS des ressources dans les comptes des clients. Certaines ressources créées doivent assumer un rôle d’exécution. Par exemple, si AWS Service Catalog crée un CodePipeline pipeline pour le compte d'un client pour un CI/CD projet d'apprentissage automatique basé sur l' SageMaker IA, ce pipeline nécessite un rôle IAM.

Le AmazonSageMakerServiceCatalogProductsLaunchRole rôle dispose des autorisations nécessaires pour lancer le portefeuille de produits SageMaker AI à partir de AWS Service Catalog. Le AmazonSageMakerServiceCatalogProductsUseRole rôle dispose des autorisations nécessaires pour utiliser le portefeuille de produits SageMaker AI de AWS Service Catalog. Le AmazonSageMakerServiceCatalogProductsLaunchRole rôle transmet un AmazonSageMakerServiceCatalogProductsUseRole rôle aux ressources du produit AWS Service Catalog provisionnées.

AWS stratégie gérée : AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy

Cette politique de rôle de service est utilisée par le AWS Service Catalog service pour fournir des produits du portefeuille Amazon SageMaker AI. La politique accorde des autorisations à un ensemble de AWS services associés AWS CodePipeline, notamment AWS CodeBuild AWS CodeCommit, AWS CloudFormation, AWS Glue et autres.

La AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy politique est destinée à être utilisée par le AmazonSageMakerServiceCatalogProductsLaunchRole rôle créé à partir de la console SageMaker AI. La politique ajoute des autorisations permettant de provisionner AWS des ressources pour les SageMaker projets et JumpStart d'utiliser le catalogue de services sur le compte d'un client.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • apigateway – Autorise le rôle à appeler les points de terminaison API Gateway étiquetés avec sagemaker:launch-source.

  • cloudformation— Permet AWS Service Catalog de créer, de mettre à jour et de supprimer des CloudFormation piles. Autorise également Service Catalog à ajouter des balises aux ressources et à les supprimer.

  • codebuild— Autorise le rôle assumé AWS Service Catalog et transmis CloudFormation à créer, mettre à jour et supprimer CodeBuild des projets.

  • codecommit— Autorise le rôle assumé AWS Service Catalog et transmis à créer, mettre CloudFormation à jour et supprimer des CodeCommit référentiels.

  • codepipeline— Autorise la création, la mise CloudFormation à jour AWS Service Catalog et la suppression du rôle assumé et transmis à celui-ci CodePipelines.

  • codeconnections, codestar-connections — Autorise également le transfert du rôle AWS CodeConnections et AWS CodeStar les connexions.

  • cognito-idp : autorise le rôle à créer, à mettre à jour, et à supprimer des groupes et des groupes d’utilisateurs. Autorise également le balisage des ressources.

  • ecr— Autorise le rôle assumé AWS Service Catalog et transmis à la création et CloudFormation à la suppression de référentiels Amazon ECR. Autorise également le balisage des ressources.

  • events— Autorise le rôle assumé AWS Service Catalog et transmis CloudFormation à créer et à supprimer EventBridge des règles. Utilisé pour relier les différents composants du pipeline CI/CD.

  • firehose : autorise le rôle à interagir avec les flux Firehose.

  • glue— Permet d'interagir avec le rôle AWS Glue.

  • iam – Autorise le rôle à transmettre les rôles préfixés par AmazonSageMakerServiceCatalog. Cela est nécessaire lorsque Projects alloue un produit AWS Service Catalog , car un rôle doit être transmis à AWS Service Catalog.

  • lambda : autorise le rôle à interagir avec AWS Lambda. Autorise également le balisage des ressources.

  • logs – Autorise le rôle à créer, à supprimer et à accéder à des flux de journaux.

  • s3— Autorise le rôle assumé AWS Service Catalog et transmis à accéder CloudFormation aux compartiments Amazon S3 dans lesquels le code du modèle de projet est stocké.

  • sagemaker— Permet au rôle d'interagir avec différents services d' SageMaker IA. Cela se fait à la fois CloudFormation pendant le provisionnement du modèle et CodeBuild pendant l'exécution du pipeline CICD. Elle autorise également le balisage des ressources suivantes : points de terminaison, configurations des points de terminaison, modèles, pipelines, projets et packages de modèles.

  • states : autorise le rôle à créer, à supprimer et à mettre à jour les fonctions d’étape préfixées par sagemaker.

Pour consulter les autorisations relatives à cette politique, consultez AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy le AWS Managed Policy Reference.

AWS stratégie gérée : AmazonSageMakerPartnerServiceCatalogProductsApiGatewayServiceRolePolicy

Cette politique est utilisée par Amazon API Gateway dans le cadre des produits AWS Service Catalog provisionnés du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est ensuite AmazonSageMakerServiceCatalogProductsLaunchRole transmis aux AWS ressources créées par API Gateway qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • lambda : invoquez une fonction créée par un modèle partenaire.

  • sagemaker : invoquez un point de terminaison créé par un modèle partenaire.

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "lambda:InvokeFunction", "Resource": "arn:aws:lambda:*:*:function:sagemaker-*", "Condition": { "Null": { "aws:ResourceTag/sagemaker:project-name": "false", "aws:ResourceTag/sagemaker:partner": "false" }, "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Effect": "Allow", "Action": "sagemaker:InvokeEndpoint", "Resource": "arn:aws:sagemaker:*:*:endpoint/*", "Condition": { "Null": { "aws:ResourceTag/sagemaker:project-name": "false", "aws:ResourceTag/sagemaker:partner": "false" }, "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } } ] }

AWS stratégie gérée : AmazonSageMakerPartnerServiceCatalogProductsCloudFormationServiceRolePolicy

Cette politique est utilisée par AWS CloudFormation les produits AWS Service Catalog provisionnés du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est AmazonSageMakerServiceCatalogProductsLaunchRole ensuite transmis aux AWS ressources créées CloudFormation qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • iam : transmettez les rôles AmazonSageMakerServiceCatalogProductsLambdaRole et AmazonSageMakerServiceCatalogProductsApiGatewayRole.

  • lambda— Créez, mettez à jour, supprimez et invoquez des AWS Lambda fonctions ; récupérez, publiez et supprimez des versions d'une couche Lambda.

  • apigateway : créez, mettez à jour et supprimez des ressources Amazon API Gateway.

  • s3 : récupérez le fichier lambda-auth-code/layer.zip à partir d'un compartiment Amazon Simple Storage Service (Amazon S3).

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "iam:PassRole" ], "Resource": [ "arn:aws:iam::*:role/service-role/AmazonSageMakerServiceCatalogProductsLambdaRole" ], "Condition": { "StringEquals": { "iam:PassedToService": "lambda.amazonaws.com" } } }, { "Effect": "Allow", "Action": [ "iam:PassRole" ], "Resource": [ "arn:aws:iam::*:role/service-role/AmazonSageMakerServiceCatalogProductsApiGatewayRole" ], "Condition": { "StringEquals": { "iam:PassedToService": "apigateway.amazonaws.com" } } }, { "Effect": "Allow", "Action": [ "lambda:DeleteFunction", "lambda:UpdateFunctionCode", "lambda:ListTags", "lambda:InvokeFunction" ], "Resource": [ "arn:aws:lambda:*:*:function:sagemaker-*" ], "Condition": { "Null": { "aws:ResourceTag/sagemaker:project-name": "false", "aws:ResourceTag/sagemaker:partner": "false" } } }, { "Effect": "Allow", "Action": [ "lambda:CreateFunction", "lambda:TagResource" ], "Resource": [ "arn:aws:lambda:*:*:function:sagemaker-*" ], "Condition": { "Null": { "aws:ResourceTag/sagemaker:project-name": "false", "aws:ResourceTag/sagemaker:partner": "false" }, "ForAnyValue:StringEquals": { "aws:TagKeys": [ "sagemaker:project-name", "sagemaker:partner" ] } } }, { "Effect": "Allow", "Action": [ "lambda:PublishLayerVersion", "lambda:GetLayerVersion", "lambda:DeleteLayerVersion", "lambda:GetFunction" ], "Resource": [ "arn:aws:lambda:*:*:layer:sagemaker-*", "arn:aws:lambda:*:*:function:sagemaker-*" ] }, { "Effect": "Allow", "Action": [ "apigateway:GET", "apigateway:DELETE", "apigateway:PATCH", "apigateway:POST", "apigateway:PUT" ], "Resource": [ "arn:aws:apigateway:*::/restapis/*", "arn:aws:apigateway:*::/restapis" ], "Condition": { "Null": { "aws:ResourceTag/sagemaker:project-name": "false", "aws:ResourceTag/sagemaker:partner": "false" } } }, { "Effect": "Allow", "Action": [ "apigateway:POST", "apigateway:PUT" ], "Resource": [ "arn:aws:apigateway:*::/restapis", "arn:aws:apigateway:*::/tags/*" ], "Condition": { "Null": { "aws:ResourceTag/sagemaker:project-name": "false", "aws:ResourceTag/sagemaker:partner": "false" }, "ForAnyValue:StringEquals": { "aws:TagKeys": [ "sagemaker:project-name", "sagemaker:partner" ] } } }, { "Effect": "Allow", "Action": [ "s3:GetObject" ], "Resource": [ "arn:aws:s3:::sagemaker-*/lambda-auth-code/layer.zip" ], "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } } ] }

AWS stratégie gérée : AmazonSageMakerPartnerServiceCatalogProductsLambdaServiceRolePolicy

Cette politique est utilisée par AWS Lambda les produits AWS Service Catalog provisionnés du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est ensuite transmis AmazonSageMakerServiceCatalogProductsLaunchRole aux AWS ressources créées par Lambda qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • secretsmanager : récupérez les données des secrets fournis par le partenaire pour un modèle partenaire.

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "secretsmanager:GetSecretValue", "Resource": "arn:aws:secretsmanager:*:*:secret:*", "Condition": { "Null": { "aws:ResourceTag/sagemaker:partner": false }, "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } } ] }

AWS stratégie gérée : AmazonSageMakerServiceCatalogProductsApiGatewayServiceRolePolicy

Cette politique est utilisée par Amazon API Gateway dans le cadre des produits AWS Service Catalog provisionnés du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est ensuite AmazonSageMakerServiceCatalogProductsLaunchRole transmis aux AWS ressources créées par API Gateway qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • logs— Créez et lisez des CloudWatch journaux, des groupes, des flux et des événements ; mettez à jour les événements ; décrivez diverses ressources.

    Ces autorisations sont limitées aux ressources dont le préfixe du groupe de journaux commence par «aws/apigateway/».

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "logs:CreateLogDelivery", "logs:CreateLogGroup", "logs:CreateLogStream", "logs:DeleteLogDelivery", "logs:DescribeLogGroups", "logs:DescribeLogStreams", "logs:DescribeResourcePolicies", "logs:DescribeDestinations", "logs:DescribeExportTasks", "logs:DescribeMetricFilters", "logs:DescribeQueries", "logs:DescribeQueryDefinitions", "logs:DescribeSubscriptionFilters", "logs:GetLogDelivery", "logs:GetLogEvents", "logs:PutLogEvents", "logs:PutResourcePolicy", "logs:UpdateLogDelivery" ], "Resource": "arn:aws:logs:*:*:log-group:/aws/apigateway/*" } ] }

AWS stratégie gérée : AmazonSageMakerServiceCatalogProductsCloudformationServiceRolePolicy

Cette politique est utilisée par AWS CloudFormation les produits AWS Service Catalog provisionnés du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est AmazonSageMakerServiceCatalogProductsLaunchRole ensuite transmis aux AWS ressources créées CloudFormation qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • sagemaker— Autorisez l'accès à diverses ressources d' SageMaker IA, à l'exception des domaines, des profils utilisateur, des applications et des définitions de flux.

  • iam : transmettez les rôles AmazonSageMakerServiceCatalogProductsCodeBuildRole et AmazonSageMakerServiceCatalogProductsExecutionRole.

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "sagemaker:AddAssociation", "sagemaker:AddTags", "sagemaker:AssociateTrialComponent", "sagemaker:BatchDescribeModelPackage", "sagemaker:BatchGetMetrics", "sagemaker:BatchGetRecord", "sagemaker:BatchPutMetrics", "sagemaker:CreateAction", "sagemaker:CreateAlgorithm", "sagemaker:CreateApp", "sagemaker:CreateAppImageConfig", "sagemaker:CreateArtifact", "sagemaker:CreateAutoMLJob", "sagemaker:CreateCodeRepository", "sagemaker:CreateCompilationJob", "sagemaker:CreateContext", "sagemaker:CreateDataQualityJobDefinition", "sagemaker:CreateDeviceFleet", "sagemaker:CreateDomain", "sagemaker:CreateEdgePackagingJob", "sagemaker:CreateEndpoint", "sagemaker:CreateEndpointConfig", "sagemaker:CreateExperiment", "sagemaker:CreateFeatureGroup", "sagemaker:CreateFlowDefinition", "sagemaker:CreateHumanTaskUi", "sagemaker:CreateHyperParameterTuningJob", "sagemaker:CreateImage", "sagemaker:CreateImageVersion", "sagemaker:CreateInferenceRecommendationsJob", "sagemaker:CreateLabelingJob", "sagemaker:CreateLineageGroupPolicy", "sagemaker:CreateModel", "sagemaker:CreateModelBiasJobDefinition", "sagemaker:CreateModelExplainabilityJobDefinition", "sagemaker:CreateModelPackage", "sagemaker:CreateModelPackageGroup", "sagemaker:CreateModelQualityJobDefinition", "sagemaker:CreateMonitoringSchedule", "sagemaker:CreateNotebookInstance", "sagemaker:CreateNotebookInstanceLifecycleConfig", "sagemaker:CreatePipeline", "sagemaker:CreatePresignedDomainUrl", "sagemaker:CreatePresignedNotebookInstanceUrl", "sagemaker:CreateProcessingJob", "sagemaker:CreateProject", "sagemaker:CreateTrainingJob", "sagemaker:CreateTransformJob", "sagemaker:CreateTrial", "sagemaker:CreateTrialComponent", "sagemaker:CreateUserProfile", "sagemaker:CreateWorkforce", "sagemaker:CreateWorkteam", "sagemaker:DeleteAction", "sagemaker:DeleteAlgorithm", "sagemaker:DeleteApp", "sagemaker:DeleteAppImageConfig", "sagemaker:DeleteArtifact", "sagemaker:DeleteAssociation", "sagemaker:DeleteCodeRepository", "sagemaker:DeleteContext", "sagemaker:DeleteDataQualityJobDefinition", "sagemaker:DeleteDeviceFleet", "sagemaker:DeleteDomain", "sagemaker:DeleteEndpoint", "sagemaker:DeleteEndpointConfig", "sagemaker:DeleteExperiment", "sagemaker:DeleteFeatureGroup", "sagemaker:DeleteFlowDefinition", "sagemaker:DeleteHumanLoop", "sagemaker:DeleteHumanTaskUi", "sagemaker:DeleteImage", "sagemaker:DeleteImageVersion", "sagemaker:DeleteLineageGroupPolicy", "sagemaker:DeleteModel", "sagemaker:DeleteModelBiasJobDefinition", "sagemaker:DeleteModelExplainabilityJobDefinition", "sagemaker:DeleteModelPackage", "sagemaker:DeleteModelPackageGroup", "sagemaker:DeleteModelPackageGroupPolicy", "sagemaker:DeleteModelQualityJobDefinition", "sagemaker:DeleteMonitoringSchedule", "sagemaker:DeleteNotebookInstance", "sagemaker:DeleteNotebookInstanceLifecycleConfig", "sagemaker:DeletePipeline", "sagemaker:DeleteProject", "sagemaker:DeleteRecord", "sagemaker:DeleteTags", "sagemaker:DeleteTrial", "sagemaker:DeleteTrialComponent", "sagemaker:DeleteUserProfile", "sagemaker:DeleteWorkforce", "sagemaker:DeleteWorkteam", "sagemaker:DeregisterDevices", "sagemaker:DescribeAction", "sagemaker:DescribeAlgorithm", "sagemaker:DescribeApp", "sagemaker:DescribeAppImageConfig", "sagemaker:DescribeArtifact", "sagemaker:DescribeAutoMLJob", "sagemaker:DescribeCodeRepository", "sagemaker:DescribeCompilationJob", "sagemaker:DescribeContext", "sagemaker:DescribeDataQualityJobDefinition", "sagemaker:DescribeDevice", "sagemaker:DescribeDeviceFleet", "sagemaker:DescribeDomain", "sagemaker:DescribeEdgePackagingJob", "sagemaker:DescribeEndpoint", "sagemaker:DescribeEndpointConfig", "sagemaker:DescribeExperiment", "sagemaker:DescribeFeatureGroup", "sagemaker:DescribeFlowDefinition", "sagemaker:DescribeHumanLoop", "sagemaker:DescribeHumanTaskUi", "sagemaker:DescribeHyperParameterTuningJob", "sagemaker:DescribeImage", "sagemaker:DescribeImageVersion", "sagemaker:DescribeInferenceRecommendationsJob", "sagemaker:DescribeLabelingJob", "sagemaker:DescribeLineageGroup", "sagemaker:DescribeModel", "sagemaker:DescribeModelBiasJobDefinition", "sagemaker:DescribeModelExplainabilityJobDefinition", "sagemaker:DescribeModelPackage", "sagemaker:DescribeModelPackageGroup", "sagemaker:DescribeModelQualityJobDefinition", "sagemaker:DescribeMonitoringSchedule", "sagemaker:DescribeNotebookInstance", "sagemaker:DescribeNotebookInstanceLifecycleConfig", "sagemaker:DescribePipeline", "sagemaker:DescribePipelineDefinitionForExecution", "sagemaker:DescribePipelineExecution", "sagemaker:DescribeProcessingJob", "sagemaker:DescribeProject", "sagemaker:DescribeSubscribedWorkteam", "sagemaker:DescribeTrainingJob", "sagemaker:DescribeTransformJob", "sagemaker:DescribeTrial", "sagemaker:DescribeTrialComponent", "sagemaker:DescribeUserProfile", "sagemaker:DescribeWorkforce", "sagemaker:DescribeWorkteam", "sagemaker:DisableSagemakerServicecatalogPortfolio", "sagemaker:DisassociateTrialComponent", "sagemaker:EnableSagemakerServicecatalogPortfolio", "sagemaker:GetDeviceFleetReport", "sagemaker:GetDeviceRegistration", "sagemaker:GetLineageGroupPolicy", "sagemaker:GetModelPackageGroupPolicy", "sagemaker:GetRecord", "sagemaker:GetSagemakerServicecatalogPortfolioStatus", "sagemaker:GetSearchSuggestions", "sagemaker:InvokeEndpoint", "sagemaker:InvokeEndpointAsync", "sagemaker:ListActions", "sagemaker:ListAlgorithms", "sagemaker:ListAppImageConfigs", "sagemaker:ListApps", "sagemaker:ListArtifacts", "sagemaker:ListAssociations", "sagemaker:ListAutoMLJobs", "sagemaker:ListCandidatesForAutoMLJob", "sagemaker:ListCodeRepositories", "sagemaker:ListCompilationJobs", "sagemaker:ListContexts", "sagemaker:ListDataQualityJobDefinitions", "sagemaker:ListDeviceFleets", "sagemaker:ListDevices", "sagemaker:ListDomains", "sagemaker:ListEdgePackagingJobs", "sagemaker:ListEndpointConfigs", "sagemaker:ListEndpoints", "sagemaker:ListExperiments", "sagemaker:ListFeatureGroups", "sagemaker:ListFlowDefinitions", "sagemaker:ListHumanLoops", "sagemaker:ListHumanTaskUis", "sagemaker:ListHyperParameterTuningJobs", "sagemaker:ListImageVersions", "sagemaker:ListImages", "sagemaker:ListInferenceRecommendationsJobs", "sagemaker:ListLabelingJobs", "sagemaker:ListLabelingJobsForWorkteam", "sagemaker:ListLineageGroups", "sagemaker:ListModelBiasJobDefinitions", "sagemaker:ListModelExplainabilityJobDefinitions", "sagemaker:ListModelMetadata", "sagemaker:ListModelPackageGroups", "sagemaker:ListModelPackages", "sagemaker:ListModelQualityJobDefinitions", "sagemaker:ListModels", "sagemaker:ListMonitoringExecutions", "sagemaker:ListMonitoringSchedules", "sagemaker:ListNotebookInstanceLifecycleConfigs", "sagemaker:ListNotebookInstances", "sagemaker:ListPipelineExecutionSteps", "sagemaker:ListPipelineExecutions", "sagemaker:ListPipelineParametersForExecution", "sagemaker:ListPipelines", "sagemaker:ListProcessingJobs", "sagemaker:ListProjects", "sagemaker:ListSubscribedWorkteams", "sagemaker:ListTags", "sagemaker:ListTrainingJobs", "sagemaker:ListTrainingJobsForHyperParameterTuningJob", "sagemaker:ListTransformJobs", "sagemaker:ListTrialComponents", "sagemaker:ListTrials", "sagemaker:ListUserProfiles", "sagemaker:ListWorkforces", "sagemaker:ListWorkteams", "sagemaker:PutLineageGroupPolicy", "sagemaker:PutModelPackageGroupPolicy", "sagemaker:PutRecord", "sagemaker:QueryLineage", "sagemaker:RegisterDevices", "sagemaker:RenderUiTemplate", "sagemaker:Search", "sagemaker:SendHeartbeat", "sagemaker:SendPipelineExecutionStepFailure", "sagemaker:SendPipelineExecutionStepSuccess", "sagemaker:StartHumanLoop", "sagemaker:StartMonitoringSchedule", "sagemaker:StartNotebookInstance", "sagemaker:StartPipelineExecution", "sagemaker:StopAutoMLJob", "sagemaker:StopCompilationJob", "sagemaker:StopEdgePackagingJob", "sagemaker:StopHumanLoop", "sagemaker:StopHyperParameterTuningJob", "sagemaker:StopInferenceRecommendationsJob", "sagemaker:StopLabelingJob", "sagemaker:StopMonitoringSchedule", "sagemaker:StopNotebookInstance", "sagemaker:StopPipelineExecution", "sagemaker:StopProcessingJob", "sagemaker:StopTrainingJob", "sagemaker:StopTransformJob", "sagemaker:UpdateAction", "sagemaker:UpdateAppImageConfig", "sagemaker:UpdateArtifact", "sagemaker:UpdateCodeRepository", "sagemaker:UpdateContext", "sagemaker:UpdateDeviceFleet", "sagemaker:UpdateDevices", "sagemaker:UpdateDomain", "sagemaker:UpdateEndpoint", "sagemaker:UpdateEndpointWeightsAndCapacities", "sagemaker:UpdateExperiment", "sagemaker:UpdateImage", "sagemaker:UpdateModelPackage", "sagemaker:UpdateMonitoringSchedule", "sagemaker:UpdateNotebookInstance", "sagemaker:UpdateNotebookInstanceLifecycleConfig", "sagemaker:UpdatePipeline", "sagemaker:UpdatePipelineExecution", "sagemaker:UpdateProject", "sagemaker:UpdateTrainingJob", "sagemaker:UpdateTrial", "sagemaker:UpdateTrialComponent", "sagemaker:UpdateUserProfile", "sagemaker:UpdateWorkforce", "sagemaker:UpdateWorkteam" ], "NotResource": [ "arn:aws:sagemaker:*:*:domain/*", "arn:aws:sagemaker:*:*:user-profile/*", "arn:aws:sagemaker:*:*:app/*", "arn:aws:sagemaker:*:*:flow-definition/*" ] }, { "Effect": "Allow", "Action": [ "iam:PassRole" ], "Resource": [ "arn:aws:iam::*:role/service-role/AmazonSageMakerServiceCatalogProductsCodeBuildRole", "arn:aws:iam::*:role/service-role/AmazonSageMakerServiceCatalogProductsExecutionRole" ] } ] }

AWS stratégie gérée : AmazonSageMakerServiceCatalogProductsCodeBuildServiceRolePolicy

Cette politique est utilisée par AWS CodeBuild les produits AWS Service Catalog provisionnés du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est AmazonSageMakerServiceCatalogProductsLaunchRole ensuite transmis aux AWS ressources créées CodeBuild qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • sagemaker— Autorisez l'accès à diverses ressources d' SageMaker IA.

  • codecommit— Téléchargez CodeCommit des archives dans des CodeBuild pipelines, obtenez le statut des téléchargements et annulez les téléchargements ; obtenez des informations sur les branches et les validations. Ces autorisations sont limitées aux ressources dont le nom commence par « sagemaker- ».

  • ecr : créez des référentiels Amazon ECR et des images de conteneurs ; chargez des couches d'images. Ces autorisations sont limitées aux référentiels dont le nom commence par « sagemaker- ».

    ecr : lisez toutes les ressources.

  • iam : transmettez les rôles suivants :

    • AmazonSageMakerServiceCatalogProductsCloudformationRoleà AWS CloudFormation.

    • AmazonSageMakerServiceCatalogProductsCodeBuildRoleà AWS CodeBuild.

    • AmazonSageMakerServiceCatalogProductsCodePipelineRoleà AWS CodePipeline.

    • AmazonSageMakerServiceCatalogProductsEventsRoleà Amazon EventBridge.

    • AmazonSageMakerServiceCatalogProductsExecutionRoleà Amazon SageMaker AI.

  • logs— Créez et lisez des CloudWatch journaux, des groupes, des flux et des événements ; mettez à jour les événements ; décrivez diverses ressources.

    Ces autorisations sont limitées aux ressources dont le préfixe du nom commence par «aws/codebuild/».

  • s3 : créez, lisez et répertoriez les compartiments Amazon S3. Ces autorisations sont limitées aux compartiments dont le nom commence par « sagemaker- ».

  • codeconnections, codestar-connections — Utilisation AWS CodeConnections et AWS CodeStar connexions.

Pour consulter les autorisations relatives à cette politique, consultez AmazonSageMakerServiceCatalogProductsCodeBuildServiceRolePolicy le AWS Managed Policy Reference.

AWS stratégie gérée : AmazonSageMakerServiceCatalogProductsCodePipelineServiceRolePolicy

Cette politique est utilisée par AWS CodePipeline les produits AWS Service Catalog provisionnés du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est AmazonSageMakerServiceCatalogProductsLaunchRole ensuite transmis aux AWS ressources créées CodePipeline qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • cloudformation— Créez, lisez, supprimez et mettez à jour des CloudFormation piles ; créez, lisez, supprimez et exécutez des ensembles de modifications ; définissez une politique de pile ; balisez et annulez des ressources. Ces autorisations sont limitées aux ressources dont le nom commence par « sagemaker- ».

  • s3 : créez, lisez, répertoriez et supprimez des compartiments Amazon S3 ; ajoutez, lisez et supprimez des objets dans les compartiments ; lisez et définissez la configuration CORS ; lisez la liste de contrôle d'accès (ACL) et lisez la région AWS où se trouve le compartiment.

    Ces autorisations sont limitées aux compartiments dont le nom commence par « sagemaker- » ou « aws-glue- ».

  • iam : transmettez le rôle AmazonSageMakerServiceCatalogProductsCloudformationRole.

  • codebuild— Obtenez des informations sur les CodeBuild builds et lancez les builds. Ces autorisations sont limitées aux ressources de projet et de génération dont le nom commence par « sagemaker- ».

  • codecommit— Téléchargez CodeCommit des archives dans des CodeBuild pipelines, obtenez le statut des téléchargements et annulez les téléchargements ; obtenez des informations sur les branches et les validations.

  • codeconnections, codestar-connections — Utilisation AWS CodeConnections et AWS CodeStar connexions.

Pour consulter les autorisations relatives à cette politique, consultez AmazonSageMakerServiceCatalogProductsCodePipelineServiceRolePolicy le AWS Managed Policy Reference.

AWS stratégie gérée : AmazonSageMakerServiceCatalogProductsEventsServiceRolePolicy

Cette politique est utilisée par Amazon EventBridge dans le cadre des produits AWS Service Catalog provisionnés du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est AmazonSageMakerServiceCatalogProductsLaunchRole ensuite transmis aux AWS ressources créées EventBridge qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • codepipeline— Lancer une CodeBuild exécution. Ces autorisations sont limitées aux pipelines dont le nom commence par « sagemaker- ».

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "codepipeline:StartPipelineExecution", "Resource": "arn:aws:codepipeline:*:*:sagemaker-*" } ] }

AWS stratégie gérée : AmazonSageMakerServiceCatalogProductsFirehoseServiceRolePolicy

Cette politique est utilisée par Amazon Data Firehose dans le cadre AWS Service Catalog des produits fournis du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est ensuite AmazonSageMakerServiceCatalogProductsLaunchRole transmis aux AWS ressources créées par Firehose qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • firehose : envoie les enregistrements Firehose. Ces autorisations sont limitées aux ressources dont le nom du flux de diffusion commence par « sagemaker- ».

JSON
{ "Version":"2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "firehose:PutRecord", "firehose:PutRecordBatch" ], "Resource": "arn:aws:firehose:*:*:deliverystream/sagemaker-*" } ] }

AWS stratégie gérée : AmazonSageMakerServiceCatalogProductsGlueServiceRolePolicy

Cette politique est utilisée par AWS Glue dans les produits fournis par le catalogue de AWS services du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est ensuite AmazonSageMakerServiceCatalogProductsLaunchRole transmis aux AWS ressources créées par Glue qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • glue— Créez, lisez et supprimez des partitions, des tableaux et des versions de tableaux AWS Glue. Ces autorisations sont limitées aux ressources dont le nom commence par « sagemaker- ». Créez et lisez des bases AWS de données Glue. Ces autorisations sont limitées aux bases de données dont le nom est « default » ou « global_temp », ou dont le nom commence par « sagemaker- ». Obtenez des fonctions définies par l'utilisateur.

  • s3 : créez, lisez, répertoriez et supprimez des compartiments Amazon S3 ; ajoutez, lisez et supprimez des objets dans les compartiments ; lisez et définissez la configuration CORS ; lisez la liste de contrôle d'accès (ACL) et lisez la région AWS où se trouve le compartiment.

    Ces autorisations sont limitées aux compartiments dont le nom commence par « sagemaker- » ou « aws-glue- ».

  • logs— Créez, lisez et supprimez le groupe de CloudWatch journaux, les flux et les livraisons ; et créez une politique de ressources.

    Ces autorisations sont limitées aux ressources dont le préfixe du nom commence par «aws/glue/».

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "glue:BatchCreatePartition", "glue:BatchDeletePartition", "glue:BatchDeleteTable", "glue:BatchDeleteTableVersion", "glue:BatchGetPartition", "glue:CreateDatabase", "glue:CreatePartition", "glue:CreateTable", "glue:DeletePartition", "glue:DeleteTable", "glue:DeleteTableVersion", "glue:GetDatabase", "glue:GetPartition", "glue:GetPartitions", "glue:GetTable", "glue:GetTables", "glue:GetTableVersion", "glue:GetTableVersions", "glue:SearchTables", "glue:UpdatePartition", "glue:UpdateTable", "glue:GetUserDefinedFunctions" ], "Resource": [ "arn:aws:glue:*:*:catalog", "arn:aws:glue:*:*:database/default", "arn:aws:glue:*:*:database/global_temp", "arn:aws:glue:*:*:database/sagemaker-*", "arn:aws:glue:*:*:table/sagemaker-*", "arn:aws:glue:*:*:tableVersion/sagemaker-*" ] }, { "Effect": "Allow", "Action": [ "s3:CreateBucket", "s3:DeleteBucket", "s3:GetBucketAcl", "s3:GetBucketCors", "s3:GetBucketLocation", "s3:ListAllMyBuckets", "s3:ListBucket", "s3:ListBucketMultipartUploads", "s3:PutBucketCors" ], "Resource": [ "arn:aws:s3:::aws-glue-*", "arn:aws:s3:::sagemaker-*" ] }, { "Effect": "Allow", "Action": [ "s3:AbortMultipartUpload", "s3:DeleteObject", "s3:GetObject", "s3:GetObjectVersion", "s3:PutObject" ], "Resource": [ "arn:aws:s3:::aws-glue-*", "arn:aws:s3:::sagemaker-*" ] }, { "Effect": "Allow", "Action": [ "logs:CreateLogDelivery", "logs:CreateLogGroup", "logs:CreateLogStream", "logs:DeleteLogDelivery", "logs:Describe*", "logs:GetLogDelivery", "logs:GetLogEvents", "logs:ListLogDeliveries", "logs:PutLogEvents", "logs:PutResourcePolicy", "logs:UpdateLogDelivery" ], "Resource": "arn:aws:logs:*:*:log-group:/aws/glue/*" } ] }

AWS stratégie gérée : AmazonSageMakerServiceCatalogProductsLambdaServiceRolePolicy

Cette politique est utilisée par AWS Lambda les produits AWS Service Catalog provisionnés du portefeuille Amazon SageMaker AI. La politique est destinée à être attachée à un rôle IAM qui est ensuite transmis AmazonSageMakerServiceCatalogProductsLaunchRole aux AWS ressources créées par Lambda qui nécessitent un rôle.

Détails de l’autorisation

Cette politique inclut les autorisations suivantes.

  • sagemaker— Autorisez l'accès à diverses ressources d' SageMaker IA.

  • ecr : créez et supprimez des référentiels Amazon ECR ; créez, lisez et supprimez des images de conteneurs ; chargez des couches d’images. Ces autorisations sont limitées aux référentiels dont le nom commence par « sagemaker- ».

  • events— Créez, lisez et supprimez des EventBridge règles Amazon ; créez et supprimez des cibles. Ces autorisations sont limitées aux règles dont le nom commence par « sagemaker- ».

  • s3 : créez, lisez, répertoriez et supprimez des compartiments Amazon S3 ; ajoutez, lisez et supprimez des objets dans les compartiments ; lisez et définissez la configuration CORS ; lisez la liste de contrôle d’accès (ACL) et lisez la région AWS où se trouve le compartiment.

    Ces autorisations sont limitées aux compartiments dont le nom commence par « sagemaker- » ou « aws-glue- ».

  • iam : transmettez le rôle AmazonSageMakerServiceCatalogProductsExecutionRole.

  • logs— Créez, lisez et supprimez le groupe de CloudWatch journaux, les flux et les livraisons ; et créez une politique de ressources.

    Ces autorisations sont limitées aux ressources dont le préfixe du nom commence par «aws/lambda/».

  • codebuild— Commencez et obtenez des informations sur les AWS CodeBuild builds.

JSON
{ "Version":"2012-10-17", "Statement": [ { "Sid" : "AmazonSageMakerLambdaECRPermission", "Effect": "Allow", "Action": [ "ecr:DescribeImages", "ecr:BatchDeleteImage", "ecr:CompleteLayerUpload", "ecr:CreateRepository", "ecr:DeleteRepository", "ecr:InitiateLayerUpload", "ecr:PutImage", "ecr:UploadLayerPart" ], "Resource": [ "arn:aws:ecr:*:*:repository/sagemaker-*" ] }, { "Sid" : "AmazonSageMakerLambdaEventBridgePermission", "Effect": "Allow", "Action": [ "events:DeleteRule", "events:DescribeRule", "events:PutRule", "events:PutTargets", "events:RemoveTargets" ], "Resource": [ "arn:aws:events:*:*:rule/sagemaker-*" ] }, { "Sid" : "AmazonSageMakerLambdaS3BucketPermission", "Effect": "Allow", "Action": [ "s3:CreateBucket", "s3:DeleteBucket", "s3:GetBucketAcl", "s3:GetBucketCors", "s3:GetBucketLocation", "s3:ListAllMyBuckets", "s3:ListBucket", "s3:ListBucketMultipartUploads", "s3:PutBucketCors" ], "Resource": [ "arn:aws:s3:::aws-glue-*", "arn:aws:s3:::sagemaker-*" ] }, { "Sid" : "AmazonSageMakerLambdaS3ObjectPermission", "Effect": "Allow", "Action": [ "s3:AbortMultipartUpload", "s3:DeleteObject", "s3:GetObject", "s3:GetObjectVersion", "s3:PutObject" ], "Resource": [ "arn:aws:s3:::aws-glue-*", "arn:aws:s3:::sagemaker-*" ] }, { "Sid" : "AmazonSageMakerLambdaSageMakerPermission", "Effect": "Allow", "Action": [ "sagemaker:AddAssociation", "sagemaker:AddTags", "sagemaker:AssociateTrialComponent", "sagemaker:BatchDescribeModelPackage", "sagemaker:BatchGetMetrics", "sagemaker:BatchGetRecord", "sagemaker:BatchPutMetrics", "sagemaker:CreateAction", "sagemaker:CreateAlgorithm", "sagemaker:CreateApp", "sagemaker:CreateAppImageConfig", "sagemaker:CreateArtifact", "sagemaker:CreateAutoMLJob", "sagemaker:CreateCodeRepository", "sagemaker:CreateCompilationJob", "sagemaker:CreateContext", "sagemaker:CreateDataQualityJobDefinition", "sagemaker:CreateDeviceFleet", "sagemaker:CreateDomain", "sagemaker:CreateEdgePackagingJob", "sagemaker:CreateEndpoint", "sagemaker:CreateEndpointConfig", "sagemaker:CreateExperiment", "sagemaker:CreateFeatureGroup", "sagemaker:CreateFlowDefinition", "sagemaker:CreateHumanTaskUi", "sagemaker:CreateHyperParameterTuningJob", "sagemaker:CreateImage", "sagemaker:CreateImageVersion", "sagemaker:CreateInferenceRecommendationsJob", "sagemaker:CreateLabelingJob", "sagemaker:CreateLineageGroupPolicy", "sagemaker:CreateModel", "sagemaker:CreateModelBiasJobDefinition", "sagemaker:CreateModelExplainabilityJobDefinition", "sagemaker:CreateModelPackage", "sagemaker:CreateModelPackageGroup", "sagemaker:CreateModelQualityJobDefinition", "sagemaker:CreateMonitoringSchedule", "sagemaker:CreateNotebookInstance", "sagemaker:CreateNotebookInstanceLifecycleConfig", "sagemaker:CreatePipeline", "sagemaker:CreatePresignedDomainUrl", "sagemaker:CreatePresignedNotebookInstanceUrl", "sagemaker:CreateProcessingJob", "sagemaker:CreateProject", "sagemaker:CreateTrainingJob", "sagemaker:CreateTransformJob", "sagemaker:CreateTrial", "sagemaker:CreateTrialComponent", "sagemaker:CreateUserProfile", "sagemaker:CreateWorkforce", "sagemaker:CreateWorkteam", "sagemaker:DeleteAction", "sagemaker:DeleteAlgorithm", "sagemaker:DeleteApp", "sagemaker:DeleteAppImageConfig", "sagemaker:DeleteArtifact", "sagemaker:DeleteAssociation", "sagemaker:DeleteCodeRepository", "sagemaker:DeleteContext", "sagemaker:DeleteDataQualityJobDefinition", "sagemaker:DeleteDeviceFleet", "sagemaker:DeleteDomain", "sagemaker:DeleteEndpoint", "sagemaker:DeleteEndpointConfig", "sagemaker:DeleteExperiment", "sagemaker:DeleteFeatureGroup", "sagemaker:DeleteFlowDefinition", "sagemaker:DeleteHumanLoop", "sagemaker:DeleteHumanTaskUi", "sagemaker:DeleteImage", "sagemaker:DeleteImageVersion", "sagemaker:DeleteLineageGroupPolicy", "sagemaker:DeleteModel", "sagemaker:DeleteModelBiasJobDefinition", "sagemaker:DeleteModelExplainabilityJobDefinition", "sagemaker:DeleteModelPackage", "sagemaker:DeleteModelPackageGroup", "sagemaker:DeleteModelPackageGroupPolicy", "sagemaker:DeleteModelQualityJobDefinition", "sagemaker:DeleteMonitoringSchedule", "sagemaker:DeleteNotebookInstance", "sagemaker:DeleteNotebookInstanceLifecycleConfig", "sagemaker:DeletePipeline", "sagemaker:DeleteProject", "sagemaker:DeleteRecord", "sagemaker:DeleteTags", "sagemaker:DeleteTrial", "sagemaker:DeleteTrialComponent", "sagemaker:DeleteUserProfile", "sagemaker:DeleteWorkforce", "sagemaker:DeleteWorkteam", "sagemaker:DeregisterDevices", "sagemaker:DescribeAction", "sagemaker:DescribeAlgorithm", "sagemaker:DescribeApp", "sagemaker:DescribeAppImageConfig", "sagemaker:DescribeArtifact", "sagemaker:DescribeAutoMLJob", "sagemaker:DescribeCodeRepository", "sagemaker:DescribeCompilationJob", "sagemaker:DescribeContext", "sagemaker:DescribeDataQualityJobDefinition", "sagemaker:DescribeDevice", "sagemaker:DescribeDeviceFleet", "sagemaker:DescribeDomain", "sagemaker:DescribeEdgePackagingJob", "sagemaker:DescribeEndpoint", "sagemaker:DescribeEndpointConfig", "sagemaker:DescribeExperiment", "sagemaker:DescribeFeatureGroup", "sagemaker:DescribeFlowDefinition", "sagemaker:DescribeHumanLoop", "sagemaker:DescribeHumanTaskUi", "sagemaker:DescribeHyperParameterTuningJob", "sagemaker:DescribeImage", "sagemaker:DescribeImageVersion", "sagemaker:DescribeInferenceRecommendationsJob", "sagemaker:DescribeLabelingJob", "sagemaker:DescribeLineageGroup", "sagemaker:DescribeModel", "sagemaker:DescribeModelBiasJobDefinition", "sagemaker:DescribeModelExplainabilityJobDefinition", "sagemaker:DescribeModelPackage", "sagemaker:DescribeModelPackageGroup", "sagemaker:DescribeModelQualityJobDefinition", "sagemaker:DescribeMonitoringSchedule", "sagemaker:DescribeNotebookInstance", "sagemaker:DescribeNotebookInstanceLifecycleConfig", "sagemaker:DescribePipeline", "sagemaker:DescribePipelineDefinitionForExecution", "sagemaker:DescribePipelineExecution", "sagemaker:DescribeProcessingJob", "sagemaker:DescribeProject", "sagemaker:DescribeSubscribedWorkteam", "sagemaker:DescribeTrainingJob", "sagemaker:DescribeTransformJob", "sagemaker:DescribeTrial", "sagemaker:DescribeTrialComponent", "sagemaker:DescribeUserProfile", "sagemaker:DescribeWorkforce", "sagemaker:DescribeWorkteam", "sagemaker:DisableSagemakerServicecatalogPortfolio", "sagemaker:DisassociateTrialComponent", "sagemaker:EnableSagemakerServicecatalogPortfolio", "sagemaker:GetDeviceFleetReport", "sagemaker:GetDeviceRegistration", "sagemaker:GetLineageGroupPolicy", "sagemaker:GetModelPackageGroupPolicy", "sagemaker:GetRecord", "sagemaker:GetSagemakerServicecatalogPortfolioStatus", "sagemaker:GetSearchSuggestions", "sagemaker:InvokeEndpoint", "sagemaker:InvokeEndpointAsync", "sagemaker:ListActions", "sagemaker:ListAlgorithms", "sagemaker:ListAppImageConfigs", "sagemaker:ListApps", "sagemaker:ListArtifacts", "sagemaker:ListAssociations", "sagemaker:ListAutoMLJobs", "sagemaker:ListCandidatesForAutoMLJob", "sagemaker:ListCodeRepositories", "sagemaker:ListCompilationJobs", "sagemaker:ListContexts", "sagemaker:ListDataQualityJobDefinitions", "sagemaker:ListDeviceFleets", "sagemaker:ListDevices", "sagemaker:ListDomains", "sagemaker:ListEdgePackagingJobs", "sagemaker:ListEndpointConfigs", "sagemaker:ListEndpoints", "sagemaker:ListExperiments", "sagemaker:ListFeatureGroups", "sagemaker:ListFlowDefinitions", "sagemaker:ListHumanLoops", "sagemaker:ListHumanTaskUis", "sagemaker:ListHyperParameterTuningJobs", "sagemaker:ListImageVersions", "sagemaker:ListImages", "sagemaker:ListInferenceRecommendationsJobs", "sagemaker:ListLabelingJobs", "sagemaker:ListLabelingJobsForWorkteam", "sagemaker:ListLineageGroups", "sagemaker:ListModelBiasJobDefinitions", "sagemaker:ListModelExplainabilityJobDefinitions", "sagemaker:ListModelMetadata", "sagemaker:ListModelPackageGroups", "sagemaker:ListModelPackages", "sagemaker:ListModelQualityJobDefinitions", "sagemaker:ListModels", "sagemaker:ListMonitoringExecutions", "sagemaker:ListMonitoringSchedules", "sagemaker:ListNotebookInstanceLifecycleConfigs", "sagemaker:ListNotebookInstances", "sagemaker:ListPipelineExecutionSteps", "sagemaker:ListPipelineExecutions", "sagemaker:ListPipelineParametersForExecution", "sagemaker:ListPipelines", "sagemaker:ListProcessingJobs", "sagemaker:ListProjects", "sagemaker:ListSubscribedWorkteams", "sagemaker:ListTags", "sagemaker:ListTrainingJobs", "sagemaker:ListTrainingJobsForHyperParameterTuningJob", "sagemaker:ListTransformJobs", "sagemaker:ListTrialComponents", "sagemaker:ListTrials", "sagemaker:ListUserProfiles", "sagemaker:ListWorkforces", "sagemaker:ListWorkteams", "sagemaker:PutLineageGroupPolicy", "sagemaker:PutModelPackageGroupPolicy", "sagemaker:PutRecord", "sagemaker:QueryLineage", "sagemaker:RegisterDevices", "sagemaker:RenderUiTemplate", "sagemaker:Search", "sagemaker:SendHeartbeat", "sagemaker:SendPipelineExecutionStepFailure", "sagemaker:SendPipelineExecutionStepSuccess", "sagemaker:StartHumanLoop", "sagemaker:StartMonitoringSchedule", "sagemaker:StartNotebookInstance", "sagemaker:StartPipelineExecution", "sagemaker:StopAutoMLJob", "sagemaker:StopCompilationJob", "sagemaker:StopEdgePackagingJob", "sagemaker:StopHumanLoop", "sagemaker:StopHyperParameterTuningJob", "sagemaker:StopInferenceRecommendationsJob", "sagemaker:StopLabelingJob", "sagemaker:StopMonitoringSchedule", "sagemaker:StopNotebookInstance", "sagemaker:StopPipelineExecution", "sagemaker:StopProcessingJob", "sagemaker:StopTrainingJob", "sagemaker:StopTransformJob", "sagemaker:UpdateAction", "sagemaker:UpdateAppImageConfig", "sagemaker:UpdateArtifact", "sagemaker:UpdateCodeRepository", "sagemaker:UpdateContext", "sagemaker:UpdateDeviceFleet", "sagemaker:UpdateDevices", "sagemaker:UpdateDomain", "sagemaker:UpdateEndpoint", "sagemaker:UpdateEndpointWeightsAndCapacities", "sagemaker:UpdateExperiment", "sagemaker:UpdateImage", "sagemaker:UpdateModelPackage", "sagemaker:UpdateMonitoringSchedule", "sagemaker:UpdateNotebookInstance", "sagemaker:UpdateNotebookInstanceLifecycleConfig", "sagemaker:UpdatePipeline", "sagemaker:UpdatePipelineExecution", "sagemaker:UpdateProject", "sagemaker:UpdateTrainingJob", "sagemaker:UpdateTrial", "sagemaker:UpdateTrialComponent", "sagemaker:UpdateUserProfile", "sagemaker:UpdateWorkforce", "sagemaker:UpdateWorkteam" ], "Resource": [ "arn:aws:sagemaker:*:*:action/*", "arn:aws:sagemaker:*:*:algorithm/*", "arn:aws:sagemaker:*:*:app-image-config/*", "arn:aws:sagemaker:*:*:artifact/*", "arn:aws:sagemaker:*:*:automl-job/*", "arn:aws:sagemaker:*:*:code-repository/*", "arn:aws:sagemaker:*:*:compilation-job/*", "arn:aws:sagemaker:*:*:context/*", "arn:aws:sagemaker:*:*:data-quality-job-definition/*", "arn:aws:sagemaker:*:*:device-fleet/*/device/*", "arn:aws:sagemaker:*:*:device-fleet/*", "arn:aws:sagemaker:*:*:edge-packaging-job/*", "arn:aws:sagemaker:*:*:endpoint/*", "arn:aws:sagemaker:*:*:endpoint-config/*", "arn:aws:sagemaker:*:*:experiment/*", "arn:aws:sagemaker:*:*:experiment-trial/*", "arn:aws:sagemaker:*:*:experiment-trial-component/*", "arn:aws:sagemaker:*:*:feature-group/*", "arn:aws:sagemaker:*:*:human-loop/*", "arn:aws:sagemaker:*:*:human-task-ui/*", "arn:aws:sagemaker:*:*:hyper-parameter-tuning-job/*", "arn:aws:sagemaker:*:*:image/*", "arn:aws:sagemaker:*:*:image-version/*/*", "arn:aws:sagemaker:*:*:inference-recommendations-job/*", "arn:aws:sagemaker:*:*:labeling-job/*", "arn:aws:sagemaker:*:*:model/*", "arn:aws:sagemaker:*:*:model-bias-job-definition/*", "arn:aws:sagemaker:*:*:model-explainability-job-definition/*", "arn:aws:sagemaker:*:*:model-package/*", "arn:aws:sagemaker:*:*:model-package-group/*", "arn:aws:sagemaker:*:*:model-quality-job-definition/*", "arn:aws:sagemaker:*:*:monitoring-schedule/*", "arn:aws:sagemaker:*:*:notebook-instance/*", "arn:aws:sagemaker:*:*:notebook-instance-lifecycle-config/*", "arn:aws:sagemaker:*:*:pipeline/*", "arn:aws:sagemaker:*:*:pipeline/*/execution/*", "arn:aws:sagemaker:*:*:processing-job/*", "arn:aws:sagemaker:*:*:project/*", "arn:aws:sagemaker:*:*:training-job/*", "arn:aws:sagemaker:*:*:transform-job/*", "arn:aws:sagemaker:*:*:workforce/*", "arn:aws:sagemaker:*:*:workteam/*" ] }, { "Sid" : "AmazonSageMakerLambdaPassRolePermission", "Effect": "Allow", "Action": [ "iam:PassRole" ], "Resource": [ "arn:aws:iam::*:role/service-role/AmazonSageMakerServiceCatalogProductsExecutionRole" ] }, { "Sid" : "AmazonSageMakerLambdaLogPermission", "Effect": "Allow", "Action": [ "logs:CreateLogDelivery", "logs:CreateLogGroup", "logs:CreateLogStream", "logs:DeleteLogDelivery", "logs:DescribeLogGroups", "logs:DescribeLogStreams", "logs:DescribeResourcePolicies", "logs:DescribeDestinations", "logs:DescribeExportTasks", "logs:DescribeMetricFilters", "logs:DescribeQueries", "logs:DescribeQueryDefinitions", "logs:DescribeSubscriptionFilters", "logs:GetLogDelivery", "logs:GetLogEvents", "logs:ListLogDeliveries", "logs:PutLogEvents", "logs:PutResourcePolicy", "logs:UpdateLogDelivery" ], "Resource": "arn:aws:logs:*:*:log-group:/aws/lambda/*" }, { "Sid" : "AmazonSageMakerLambdaCodeBuildPermission", "Effect": "Allow", "Action": [ "codebuild:StartBuild", "codebuild:BatchGetBuilds" ], "Resource": "arn:aws:codebuild:*:*:project/sagemaker-*", "Condition": { "StringLike": { "aws:ResourceTag/sagemaker:project-name": "*" } } } ] }

Mises à jour d'Amazon SageMaker AI pour AWS Service Catalog AWS stratégies gérées

Consultez les informations relatives aux mises à jour des politiques AWS gérées pour Amazon SageMaker AI depuis que ce service a commencé à suivre ces modifications.

Politique Version Modifier Date

AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy – Mise à jour de politique

10

Mise à jour codestar-connections:PassConnection et codeconnections:PassConnection autorisations.

27 septembre 2025

AmazonSageMakerServiceCatalogProductsCodePipelineServiceRolePolicy – Mise à jour de politique

3

Mise à jour codestar-connections:UseConnection et codeconnections:UseConnection autorisations.

27 septembre 2025

AmazonSageMakerServiceCatalogProductsCodeBuildServiceRolePolicy – Mise à jour de politique

3

Mise à jour codestar-connections:UseConnection et codeconnections:UseConnection autorisations.

27 septembre 2025

AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy – Mise à jour de politique

9

Ajoutez les autorisations cloudformation:TagResource, cloudformation:UntagResource et codeconnections:PassConnection.

1er juillet 2024

AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy - Politique mise à jour

7

Restauration de la politique à la version 7 (v7). Suppression des autorisations cloudformation:TagResource, cloudformation:UntagResource et codeconnections:PassConnection.

12 juin 2024

AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy - Politique mise à jour

8

Ajoutez les autorisations cloudformation:TagResource, cloudformation:UntagResource et codeconnections:PassConnection.

11 juin 2024

AmazonSageMakerServiceCatalogProductsCodeBuildServiceRolePolicy : politique mise à jour

2

Ajoutez les autorisations codestar-connections:UseConnection et codeconnections:UseConnection.

11 juin 2024

AmazonSageMakerServiceCatalogProductsCodePipelineServiceRolePolicy : politique mise à jour

2

Ajout des autorisations cloudformation:TagResource, cloudformation:UntagResource, codestar-connections:UseConnection et codeconnections:UseConnection.

11 juin 2024

AmazonSageMakerServiceCatalogProductsLambdaServiceRolePolicy : politique mise à jour

2

Ajoutez les autorisations codebuild:StartBuild et codebuild:BatchGetBuilds.

11 juin 2024

AmazonSageMakerPartnerServiceCatalogProductsApiGatewayServiceRolePolicy

1

Politique initiale

1er août 2023

AmazonSageMakerPartnerServiceCatalogProductsCloudFormationServiceRolePolicy

1

Politique initiale

1er août 2023

AmazonSageMakerPartnerServiceCatalogProductsLambdaServiceRolePolicy

1

Politique initiale

1er août 2023

AmazonSageMakerServiceCatalogProductsGlueServiceRolePolicy : politique mise à jour

2

Ajout d’une nouvelle autorisation pour glue:GetUserDefinedFunctions.

26 août 2022

AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy - Politique mise à jour

7

Ajout d’une nouvelle autorisation pour sagemaker:AddTags.

2 août 2022
AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy - Politique mise à jour 6

Ajout d'une nouvelle autorisation pour lambda:TagResource.

14 juillet 2022

AmazonSageMakerServiceCatalogProductsLambdaServiceRolePolicy

1

Politique initiale

4 avril 2022

AmazonSageMakerServiceCatalogProductsApiGatewayServiceRolePolicy

1

Politique initiale

24 mars 2022

AmazonSageMakerServiceCatalogProductsCloudformationServiceRolePolicy

1

Politique initiale

24 mars 2022

AmazonSageMakerServiceCatalogProductsCodeBuildServiceRolePolicy

1

Politique initiale

24 mars 2022
AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy - Politique mise à jour 5

Ajout d’une nouvelle autorisation pour ecr-idp:TagResource.

21 mars 2022

AmazonSageMakerServiceCatalogProductsCodePipelineServiceRolePolicy

1

Politique initiale

22 février 2022

AmazonSageMakerServiceCatalogProductsEventsServiceRolePolicy

1

Politique initiale

22 février 2022

AmazonSageMakerServiceCatalogProductsFirehoseServiceRolePolicy

1

Politique initiale

22 février 2022
AmazonSageMakerServiceCatalogProductsGlueServiceRolePolicy 1

Politique initiale

22 février 2022
AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy - Politique mise à jour 4

Ajout d'autorisations pour cognito-idp:TagResource et s3:PutBucketCORS.

16 février 2022
AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy - Politique mise à jour 3

Ajout de nouvelles autorisations pour sagemaker.

Créez, lisez, mettez à jour et supprimez SageMaker des images.

15 septembre 2021
AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy - Politique mise à jour 2

Ajout d'autorisations pour sagemaker et codestar-connections.

Création, lecture, mise à jour et suppression des référentiels de code.

Transmettez AWS CodeStar les connexions vers AWS CodePipeline.

1er juillet 2021
AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy 1

Politique initiale

27 novembre 2020