Actions, resources, and condition keys for Amazon S3 on Outposts - Service Authorization Reference

Actions, resources, and condition keys for Amazon S3 on Outposts

Amazon S3 on Outposts (service prefix: s3-outposts) provides the following service-specific resources, actions, and condition context keys for use in IAM permission policies.

References:

Actions defined by Amazon S3 on Outposts

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

The Resource types column of the Actions table indicates whether each action supports resource-level permissions. If there is no value for this column, you must specify all resources ("*") to which the policy applies in the Resource element of your policy statement. If the column includes a resource type, then you can specify an ARN of that type in a statement with that action. If the action has one or more required resources, the caller must have permission to use the action with those resources. Required resources are indicated in the table with an asterisk (*). If you limit resource access with the Resource element in an IAM policy, you must include an ARN or pattern for each required resource type. Some actions support multiple resource types. If the resource type is optional (not indicated as required), then you can choose to use one of the optional resource types.

The Condition keys column of the Actions table includes keys that you can specify in a policy statement's Condition element. For more information on the condition keys that are associated with resources for the service, see the Condition keys column of the Resource types table.

Note

Resource condition keys are listed in the Resource types table. You can find a link to the resource type that applies to an action in the Resource types (*required) column of the Actions table. The resource type in the Resource types table includes the Condition keys column, which are the resource condition keys that apply to an action in the Actions table.

For details about the columns in the following table, see Actions table.

Actions Description Access level Resource types (*required) Condition keys Dependent actions
AbortMultipartUpload Grants permission to abort a multipart upload Write

object*

s3-outposts:DataAccessPointArn

s3-outposts:DataAccessPointAccount

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

CreateAccessPoint Grants permission to create a new access point Write

accesspoint*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

CreateBucket Grants permission to create a new bucket Write

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

CreateEndpoint Grants permission to create a new endpoint Write

endpoint*

DeleteAccessPoint Grants permission to delete the access point named in the URI Write

accesspoint*

s3-outposts:DataAccessPointArn

s3-outposts:DataAccessPointAccount

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

DeleteAccessPointPolicy Grants permission to delete the policy on a specified access point Permissions management

accesspoint*

s3-outposts:DataAccessPointArn

s3-outposts:DataAccessPointAccount

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

DeleteBucket Grants permission to delete the bucket named in the URI Write

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

DeleteBucketPolicy Grants permission to delete the policy on a specified bucket Permissions management

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

DeleteEndpoint Grants permission to delete the endpoint named in the URI Write

endpoint*

DeleteObject Grants permission to remove the null version of an object and insert a delete marker, which becomes the current version of the object Write

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

DeleteObjectTagging Grants permission to use the tagging subresource to remove the entire tag set from the specified object Tagging

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:ExistingObjectTag/<key>

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

DeleteObjectVersion Grants permission to remove a specific version of an object Write

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:versionid

s3-outposts:x-amz-content-sha256

DeleteObjectVersionTagging Grants permission to remove the entire tag set for a specific version of the object Tagging

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:ExistingObjectTag/<key>

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:versionid

s3-outposts:x-amz-content-sha256

GetAccessPoint Grants permission to return configuration information about the specified access point Read

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetAccessPointPolicy Grants permission to returns the access point policy associated with the specified access point Read

accesspoint*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetBucket Grants permission to return the bucket configuration associated with an Amazon S3 bucket Read

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetBucketPolicy Grants permission to return the policy of the specified bucket Read

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetBucketTagging Grants permission to return the tag set associated with an Amazon S3 bucket Read

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetBucketVersioning Grants permission to return the versioning state of an Amazon S3 bucket Read

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetLifecycleConfiguration Grants permission to return the lifecycle configuration information set on an Amazon S3 bucket Read

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetObject Grants permission to retrieve objects from Amazon S3 Read

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:ExistingObjectTag/<key>

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetObjectTagging Grants permission to return the tag set of an object Read

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:ExistingObjectTag/<key>

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetObjectVersion Grants permission to retrieve a specific version of an object Read

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:ExistingObjectTag/<key>

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:versionid

s3-outposts:x-amz-content-sha256

GetObjectVersionForReplication Grants permission to replicate both unencrypted objects and objects encrypted with SSE-KMS Read

object*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

GetObjectVersionTagging Grants permission to return the tag set for a specific version of the object Read

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:ExistingObjectTag/<key>

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:versionid

s3-outposts:x-amz-content-sha256

GetReplicationConfiguration Grants permission to get the replication configuration information set on an Amazon S3 bucket Read

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

ListAccessPoints Grants permission to list access points List

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

ListBucket Grants permission to list some or all of the objects in an Amazon S3 bucket (up to 1000) List

accesspoint*

bucket*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:delimiter

s3-outposts:max-keys

s3-outposts:prefix

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

ListBucketMultipartUploads Grants permission to list in-progress multipart uploads List

accesspoint*

bucket*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

ListBucketVersions Grants permission to list metadata about all the versions of objects in an Amazon S3 bucket List

bucket*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:delimiter

s3-outposts:max-keys

s3-outposts:prefix

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

ListEndpoints Grants permission to list endpoints List
ListMultipartUploadParts Grants permission to list the parts that have been uploaded for a specific multipart upload List

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

ListOutpostsWithS3 Grants permission to list outposts with S3 capacity List
ListRegionalBuckets Grants permission to list all buckets owned by the authenticated sender of the request List

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

ListSharedEndpoints Grants permission to list shared endpoints List
PutAccessPointPolicy Grants permission to associate an access policy with a specified access point Permissions management

accesspoint*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

PutBucketPolicy Grants permission to add or replace a bucket policy on a bucket Permissions management

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

PutBucketTagging Grants permission to add a set of tags to an existing Amazon S3 bucket Tagging

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

PutBucketVersioning Grants permission to set the versioning state of an existing Amazon S3 bucket Write

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

PutLifecycleConfiguration Grants permission to create a new lifecycle configuration for the bucket or replace an existing lifecycle configuration Write

bucket*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

PutObject Grants permission to add an object to a bucket Write

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:RequestObjectTag/<key>

s3-outposts:RequestObjectTagKeys

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-acl

s3-outposts:x-amz-content-sha256

s3-outposts:x-amz-copy-source

s3-outposts:x-amz-metadata-directive

s3-outposts:x-amz-server-side-encryption

s3-outposts:x-amz-storage-class

PutObjectAcl Grants permission to set the access control list (ACL) permissions for an object that already exists in a bucket Permissions management

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:ExistingObjectTag/<key>

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-acl

s3-outposts:x-amz-content-sha256

s3-outposts:x-amz-storage-class

PutObjectTagging Grants permission to set the supplied tag-set to an object that already exists in a bucket Tagging

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:ExistingObjectTag/<key>

s3-outposts:RequestObjectTag/<key>

s3-outposts:RequestObjectTagKeys

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

PutObjectVersionTagging Grants permission to set the supplied tag-set for a specific version of an object Tagging

object*

s3-outposts:DataAccessPointAccount

s3-outposts:DataAccessPointArn

s3-outposts:AccessPointNetworkOrigin

s3-outposts:ExistingObjectTag/<key>

s3-outposts:RequestObjectTag/<key>

s3-outposts:RequestObjectTagKeys

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:versionid

s3-outposts:x-amz-content-sha256

PutReplicationConfiguration Grants permission to create a new replication configuration or replace an existing one Write

bucket*

iam:PassRole

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

ReplicateDelete Grants permission to replicate delete markers to the destination bucket Write

object*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

ReplicateObject Grants permission to replicate objects and object tags to the destination bucket Write

object*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

s3-outposts:x-amz-server-side-encryption

ReplicateTags Grants permission to replicate object tags to the destination bucket Tagging

object*

s3-outposts:authType

s3-outposts:signatureAge

s3-outposts:signatureversion

s3-outposts:x-amz-content-sha256

Resource types defined by Amazon S3 on Outposts

The following resource types are defined by this service and can be used in the Resource element of IAM permission policy statements. Each action in the Actions table identifies the resource types that can be specified with that action. A resource type can also define which condition keys you can include in a policy. These keys are displayed in the last column of the Resource types table. For details about the columns in the following table, see Resource types table.

Resource types ARN Condition keys
accesspoint arn:${Partition}:s3-outposts:${Region}:${Account}:outpost/${OutpostId}/accesspoint/${AccessPointName}
bucket arn:${Partition}:s3-outposts:${Region}:${Account}:outpost/${OutpostId}/bucket/${BucketName}
endpoint arn:${Partition}:s3-outposts:${Region}:${Account}:outpost/${OutpostId}/endpoint/${EndpointId}
object arn:${Partition}:s3-outposts:${Region}:${Account}:outpost/${OutpostId}/bucket/${BucketName}/object/${ObjectName}

Condition keys for Amazon S3 on Outposts

Amazon S3 on Outposts defines the following condition keys that can be used in the Condition element of an IAM policy. You can use these keys to further refine the conditions under which the policy statement applies. For details about the columns in the following table, see Condition keys table.

To view the global condition keys that are available to all services, see Available global condition keys.

Condition keys Description Type
s3-outposts:AccessPointNetworkOrigin Filters access by the network origin (Internet or VPC) String
s3-outposts:DataAccessPointAccount Filters access by the AWS Account ID that owns the access point String
s3-outposts:DataAccessPointArn Filters access by an access point Amazon Resource Name (ARN) ARN
s3-outposts:ExistingObjectTag/<key> Filters access by requiring that an existing object tag has a specific tag key and value String
s3-outposts:RequestObjectTag/<key> Filters access by restricting the tag keys and values allowed on objects String
s3-outposts:RequestObjectTagKeys Filters access by restricting the tag keys allowed on objects String
s3-outposts:authType Filters access by restricting incoming requests to a specific authentication method String
s3-outposts:delimiter Filters access by requiring the delimiter parameter String
s3-outposts:max-keys Filters access by limiting the maximum number of keys returned in a ListBucket request Numeric
s3-outposts:prefix Filters access by key name prefix String
s3-outposts:signatureAge Filters access by identifying the length of time, in milliseconds, that a signature is valid in an authenticated request Numeric
s3-outposts:signatureversion Filters access by identifying the version of AWS Signature that is supported for authenticated requests String
s3-outposts:versionid Filters access by a specific object version String
s3-outposts:x-amz-acl Filters access by requiring the x-amz-acl header with a specific canned ACL in a request String
s3-outposts:x-amz-content-sha256 Filters access by disallowing unsigned content in your bucket String
s3-outposts:x-amz-copy-source Filters access by restricting the copy source to a specific bucket, prefix, or object String
s3-outposts:x-amz-metadata-directive Filters access by enabling enforcement of object metadata behavior (COPY or REPLACE) when objects are copied String
s3-outposts:x-amz-server-side-encryption Filters access by requiring server-side encryption String
s3-outposts:x-amz-storage-class Filters access by storage class String