| Column Name | Column Data Type |
resource_share_arn Required Input Column
Specifies the Amazon Resource Name (ARN) of the resource share for which you want to retrieve the associated permissions. | VARCHAR |
max_results Input Column
Specifies the total number of results that you want included on each page of the response. If you do not include this parameter, it defaults to a value that is specific to the operation. If additional items exist beyond the number you specify, the NextToken response element is returned with a value (not null). Include the specified value as the NextToken request parameter in the next call to the operation to get the next part of the results. Note that the service might return fewer results than the maximum even when there are more results available. You should check NextToken after every operation to ensure that you receive all of the results. | BIGINT |
next_token Input Column
If present, this value indicates that more output is available than is included in the current response. Use this value in the NextToken request parameter in a subsequent call to the operation to get the next part of the output. You should repeat this until the NextToken response element comes back as null. This indicates that this is the last page of results. | VARCHAR |
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
_aws_region Input Column
The AWS region to use. | VARCHAR |
permissions
An array of objects that describe the permissions associated with the resource share. | STRUCT( "arn" VARCHAR, "version" VARCHAR, "default_version" BOOLEAN, "name" VARCHAR, "resource_type" VARCHAR, "status" VARCHAR, "creation_time" TIMESTAMP_S, "last_updated_time" TIMESTAMP_S, "is_resource_type_default" BOOLEAN, "permission_type" VARCHAR, "feature_set" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] |
Show child fields- permissions[]
Show child fields- permissions[].arn
The Amazon Resource Name (ARN) of the permission you want information about.
- permissions[].creation_time
The date and time when the permission was created.
- permissions[].default_version
Specifies whether the version of the managed permission used by this resource share is the default version for this managed permission.
- permissions[].feature_set
Indicates what features are available for this resource share. This parameter can have one of the following values: -
STANDARD – A resource share that supports all functionality. These resource shares are visible to all principals you share the resource share with. You can modify these resource shares in RAM using the console or APIs. This resource share might have been created by RAM, or it might have been CREATED_FROM_POLICY and then promoted. -
CREATED_FROM_POLICY – The customer manually shared a resource by attaching a resource-based policy. That policy did not match any existing managed permissions, so RAM created this customer managed permission automatically on the customer's behalf based on the attached policy document. This type of resource share is visible only to the Amazon Web Services account that created it. You can't modify it in RAM unless you promote it. For more information, see PromoteResourceShareCreatedFromPolicy. -
PROMOTING_TO_STANDARD – This resource share was originally CREATED_FROM_POLICY, but the customer ran the PromoteResourceShareCreatedFromPolicy and that operation is still in progress. This value changes to STANDARD when complete.
- permissions[].is_resource_type_default
Specifies whether the managed permission associated with this resource share is the default managed permission for all resources of this resource type.
- permissions[].last_updated_time
The date and time when the permission was last updated.
- permissions[].name
The name of this managed permission.
- permissions[].permission_type
The type of managed permission. This can be one of the following values: -
AWS_MANAGED – Amazon Web Services created and manages this managed permission. You can associate it with your resource shares, but you can't modify it. -
CUSTOMER_MANAGED – You, or another principal in your account created this managed permission. You can associate it with your resource shares and create new versions that have different permissions.
- permissions[].resource_type
The type of resource to which this permission applies. This takes the form of: service-code:resource-code, and is case-insensitive. For example, an Amazon EC2 Subnet would be represented by the string ec2:subnet.
- permissions[].status
The current status of the permission.
- permissions[].tags[]
Show child fields- permissions[].tags[].key
The key, or name, attached to the tag. Every tag must have a key. Key names are case sensitive.
- permissions[].tags[].value
The string value attached to the tag. The value can be an empty string. Key values are case sensitive.
- permissions[].version
The version of the permission associated with this resource share.
|