Actions, resources, and condition keys for Amazon CloudFront - Service Authorization Reference

Actions, resources, and condition keys for Amazon CloudFront

Amazon CloudFront (service prefix: cloudfront ) provides the following service-specific resources, actions, and condition context keys for use in IAM permission policies.

References:

Actions defined by Amazon CloudFront

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

The Resource types column indicates whether each action supports resource-level permissions. If there is no value for this column, you must specify all resources ("*") in the Resource element of your policy statement. If the column includes a resource type, then you can specify an ARN of that type in a statement with that action. Required resources are indicated in the table with an asterisk (*). If you specify a resource-level permission ARN in a statement using this action, then it must be of this type. Some actions support multiple resource types. If the resource type is optional (not indicated as required), then you can choose to use one but not the other.

For details about the columns in the following table, see The actions table .

Actions Description Access level Resource types (*required) Condition keys Dependent actions
AssociateAlias Grants permission to associate an alias to a CloudFront distribution Write

distribution*

CreateCachePolicy Grants permission to add a new cache policy to CloudFront Write
CreateCloudFrontOriginAccessIdentity Grants permission to create a new CloudFront origin access identity Write

origin-access-identity*

CreateDistribution Grants permission to create a new web distribution Write

distribution*

CreateDistributionWithTags Grants permission to create a new web distribution with tags Write

distribution*

aws:RequestTag/${TagKey}

aws:TagKeys

CreateFieldLevelEncryptionConfig Grants permission to create a new field-level encryption configuration Write
CreateFieldLevelEncryptionProfile Grants permission to create a field-level encryption profile Write
CreateFunction Grants permission to create a CloudFront function Write
CreateInvalidation Grants permission to create a new invalidation batch request Write

distribution*

CreateKeyGroup Grants permission to add a new key group to CloudFront Write
CreateMonitoringSubscription Grants permission to enable additional CloudWatch metrics for the specified CloudFront distribution. The additional metrics incur an additional cost Write
CreateOriginRequestPolicy Grants permission to add a new origin request policy to CloudFront Write
CreatePublicKey Grants permission to add a new public key to CloudFront Write
CreateRealtimeLogConfig Grants permission to create a real-time log configuration Write
CreateStreamingDistribution Grants permission to create a new RTMP distribution Write

streaming-distribution*

CreateStreamingDistributionWithTags Grants permission to create a new RTMP distribution with tags Write

streaming-distribution*

aws:RequestTag/${TagKey}

aws:TagKeys

DeleteCachePolicy Grants permission to delete a cache policy Write
DeleteCloudFrontOriginAccessIdentity Grants permission to delete a CloudFront origin access identity Write

origin-access-identity*

DeleteDistribution Grants permission to delete a web distribution Write

distribution*

DeleteFieldLevelEncryptionConfig Grants permission to delete a field-level encryption configuration Write
DeleteFieldLevelEncryptionProfile Grants permission to delete a field-level encryption profile Write
DeleteFunction Grants permission to delete a CloudFront function Write
DeleteKeyGroup Grants permission to delete a key group Write
DeleteMonitoringSubscription Grants permission to disable additional CloudWatch metrics for the specified CloudFront distribution Write
DeleteOriginRequestPolicy Grants permission to delete an origin request policy Write
DeletePublicKey Grants permission to delete a public key from CloudFront Write
DeleteRealtimeLogConfig Grants permission to delete a real-time log configuration Write
DeleteStreamingDistribution Grants permission to delete an RTMP distribution Write

streaming-distribution*

DescribeFunction Grants permission to get a CloudFront function summary Read
GetCachePolicy Grants permission to get the cache policy Read
GetCachePolicyConfig Grants permission to get the cache policy configuration Read
GetCloudFrontOriginAccessIdentity Grants permission to get the information about a CloudFront origin access identity Read

origin-access-identity*

GetCloudFrontOriginAccessIdentityConfig Grants permission to get the configuration information about a Cloudfront origin access identity Read

origin-access-identity*

GetDistribution Grants permission to get the information about a web distribution Read

distribution*

GetDistributionConfig Grants permission to get the configuration information about a distribution Read

distribution*

GetFieldLevelEncryption Grants permission to get the field-level encryption configuration information Read
GetFieldLevelEncryptionConfig Grants permission to get the field-level encryption configuration information Read
GetFieldLevelEncryptionProfile Grants permission to get the field-level encryption configuration information Read
GetFieldLevelEncryptionProfileConfig Grants permission to get the field-level encryption profile configuration information Read
GetFunction Grants permission to get a CloudFront function's code Read
GetInvalidation Grants permission to get the information about an invalidation Read

distribution*

GetKeyGroup Grants permission to get a key group Read
GetKeyGroupConfig Grants permission to get a key group configuration Read
GetMonitoringSubscription Grants permission to get information about whether additional CloudWatch metrics are enabled for the specified CloudFront distribution Read
GetOriginRequestPolicy Grants permission to get the origin request policy Read
GetOriginRequestPolicyConfig Grants permission to get the origin request policy configuration Read
GetPublicKey Grants permission to get the public key information Read
GetPublicKeyConfig Grants permission to get the public key configuration information Read
GetRealtimeLogConfig Grants permission to get a real-time log configuration Read
GetStreamingDistribution Grants permission to get the information about an RTMP distribution Read

streaming-distribution*

GetStreamingDistributionConfig Grants permission to get the configuration information about a streaming distribution Read

streaming-distribution*

ListCachePolicies Grants permission to list all cache policies that have been created in CloudFront for this account List
ListCloudFrontOriginAccessIdentities Grants permission to list your CloudFront origin access identities List
ListConflictingAliases Grants permission to list all aliases that conflict with the given alias in CloudFront List

distribution*

ListDistributions Grants permission to list the distributions associated with your AWS account List
ListDistributionsByCachePolicyId Grants permission to list distribution IDs for distributions that have a cache behavior that's associated with the specified cache policy List
ListDistributionsByKeyGroup Grants permission to list distribution IDs for distributions that have a cache behavior that's associated with the specified key group List
ListDistributionsByOriginRequestPolicyId Grants permission to list distribution IDs for distributions that have a cache behavior that's associated with the specified origin request policy List
ListDistributionsByRealtimeLogConfig Grants permission to get a list of distributions that have a cache behavior that’s associated with the specified real-time log configuration List
ListDistributionsByWebACLId Grants permission to list the distributions associated with your AWS account with given AWS WAF web ACL List
ListFieldLevelEncryptionConfigs Grants permission to list all field-level encryption configurations that have been created in CloudFront for this account List
ListFieldLevelEncryptionProfiles Grants permission to list all field-level encryption profiles that have been created in CloudFront for this account List
ListFunctions Grants permission to get a list of CloudFront functions List
ListInvalidations Grants permission to list your invalidation batches List

distribution*

ListKeyGroups Grants permission to list all key groups that have been created in CloudFront for this account List
ListOriginRequestPolicies Grants permission to list all origin request policies that have been created in CloudFront for this account List
ListPublicKeys Grants permission to list all public keys that have been added to CloudFront for this account List
ListRealtimeLogConfigs Grants permission to get a list of real-time log configurations List
ListStreamingDistributions Grants permission to list your RTMP distributions List
ListTagsForResource Grants permission to list tags for a CloudFront resource Read

distribution

streaming-distribution

PublishFunction Grants permission to publish a CloudFront function Write
TagResource Grants permission to add tags to a CloudFront resource Tagging

distribution

streaming-distribution

aws:RequestTag/${TagKey}

aws:TagKeys

TestFunction Grants permission to test a CloudFront function Write
UntagResource Grants permission to remove tags from a CloudFront resource Tagging

distribution

streaming-distribution

aws:TagKeys

UpdateCachePolicy Grants permission to update a cache policy Write
UpdateCloudFrontOriginAccessIdentity Grants permission to set the configuration for a CloudFront origin access identity Write

origin-access-identity*

UpdateDistribution Grants permission to update the configuration for a web distribution Write

distribution*

UpdateFieldLevelEncryptionConfig Grants permission to update a field-level encryption configuration Write
UpdateFieldLevelEncryptionProfile Grants permission to update a field-level encryption profile Write
UpdateFunction Grants permission to update a CloudFront function Write
UpdateKeyGroup Grants permission to update a key group Write
UpdateOriginRequestPolicy Grants permission to update an origin request policy Write
UpdatePublicKey Grants permission to update public key information Write
UpdateRealtimeLogConfig Grants permission to update a real-time log configuration Write
UpdateStreamingDistribution Grants permission to update the configuration for an RTMP distribution Write

streaming-distribution*

Resource types defined by Amazon CloudFront

The following resource types are defined by this service and can be used in the Resource element of IAM permission policy statements. Each action in the Actions table identifies the resource types that can be specified with that action. A resource type can also define which condition keys you can include in a policy. These keys are displayed in the last column of the table. For details about the columns in the following table, see The resource types table .

Resource types ARN Condition keys
distribution arn:$ { Partition}:cloudfront::$ { Account}:distribution/$ { DistributionId}

aws:ResourceTag/${TagKey}

streaming-distribution arn:$ { Partition}:cloudfront::$ { Account}:streaming-distribution/$ { DistributionId}

aws:ResourceTag/${TagKey}

origin-access-identity arn:$ { Partition}:cloudfront::$ { Account}:origin-access-identity/$ { Id}
field-level-encryption arn:$ { Partition}:cloudfront::$ { Account}:field-level-encryption/$ { Id}
field-level-encryption-profile arn:$ { Partition}:cloudfront::$ { Account}:field-level-encryption-profile/$ { Id}
cache-policy arn:$ { Partition}:cloudfront::$ { Account}:cache-policy/$ { Id}
origin-request-policy arn:$ { Partition}:cloudfront::$ { Account}:origin-request-policy/$ { Id}
realtime-log-config arn:$ { Partition}:cloudfront::$ { Account}:realtime-log-config/$ { Name}
function arn:$ { Partition}:cloudfront::$ { Account}:function/$ { Name}

Condition keys for Amazon CloudFront

Amazon CloudFront defines the following condition keys that can be used in the Condition element of an IAM policy. You can use these keys to further refine the conditions under which the policy statement applies. For details about the columns in the following table, see The condition keys table .

To view the global condition keys that are available to all services, see Available global condition keys .

Condition keys Description Type
aws:RequestTag/${TagKey} Filters access based on the presence of tag key-value pairs in the request String
aws:ResourceTag/${TagKey} Filters access based on tag key-value pairs attached to the resource String
aws:TagKeys Filters access based on the presence of tag keys in the request String