

本文属于机器翻译版本。若本译文内容与英语原文存在差异，则一律以英文原文为准。

# Amazon Cloud Directory 的操作、资源和条件键
<a name="list_amazonclouddirectory"></a>

Amazon Cloud Directory（服务前缀：`clouddirectory`）提供以下服务特定的资源、操作和条件上下文键以在 IAM 权限策略中使用。

参考：
+ 了解如何[配置该服务](https://docs.aws.amazon.com/directoryservice/latest/admin-guide/directory_amazon_cd.html)。
+ 查看[适用于该服务的 API 操作列表](https://docs.aws.amazon.com/directoryservice/latest/APIReference/)。
+ 了解如何[使用 IAM](https://docs.aws.amazon.com/directoryservice/latest/admin-guide/UsingWithDS_IAM_AuthNAccess.html) 权限策略保护该服务及其资源。

**Topics**
+ [Amazon Cloud Directory 定义的操作](#amazonclouddirectory-actions-as-permissions)
+ [Amazon Cloud Directory 定义的资源类型](#amazonclouddirectory-resources-for-iam-policies)
+ [Amazon Cloud Directory 的条件键](#amazonclouddirectory-policy-keys)

## Amazon Cloud Directory 定义的操作
<a name="amazonclouddirectory-actions-as-permissions"></a>

您可以在 IAM 策略语句的 `Action` 元素中指定以下操作。可以使用策略授予在 AWS中执行操作的权限。您在策略中使用一项操作时，通常使用相同的名称允许或拒绝对 API 操作或 CLI 命令的访问。但在某些情况下，单一动作可控制对多项操作的访问。还有某些操作需要多种不同的动作。

操作表的**访问级别**列描述如何对操作进行分类（列出、读取、权限管理或标记）。此分类可以帮助您了解当您在策略中使用操作时，相应操作授予的访问级别。有关访问级别的更多信息，请参阅[策略摘要中的访问级别](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_understand-policy-summary-access-level-summaries.html)。

操作表的**资源类型**列指示每项操作是否支持资源级权限。如果该列没有任何值，您必须在策略语句的 `Resource` 元素中指定策略应用的所有资源（“\*”）。通过在 IAM policy 中使用条件来筛选访问权限，以控制是否可以在资源或请求中使用特定标签键。如果操作具有一个或多个必需资源，则调用方必须具有使用这些资源来使用该操作的权限。必需资源在表中以星号 (\*) 表示。如果您在 IAM policy 中使用 `Resource` 元素限制资源访问权限，则必须为每种必需的资源类型添加 ARN 或模式。某些操作支持多种资源类型。如果资源类型是可选的（未指示为必需），则可以选择使用一种可选资源类型。

操作表的**条件键**列包括可以在策略语句的 `Condition` 元素中指定的键。有关与服务资源关联的条件键的更多信息，请参阅资源类型表的**条件键**列。

操作表的**依赖操作**列显示成功调用操作可能需要的其他权限。除了操作本身的权限以外，可能还需要这些权限。若某个操作指定依赖操作，则这些依赖关系可能适用于为该操作定义的其他资源，而不仅仅是表中列出的第一个资源。

**注意**  
资源条件键在[资源类型](#amazonclouddirectory-resources-for-iam-policies)表中列出。您可以在操作表的**资源类型（\* 为必需）**列中找到应用于某项操作的资源类型的链接。资源类型表中的资源类型包括**条件密钥**列，这是应用于操作表中操作的资源条件键。

有关下表中各列的详细信息，请参阅[操作表](reference_policies_actions-resources-contextkeys.html#actions_table)。


****  


- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AddFacetToObject.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AddFacetToObject.html) **
  - **描述:** 授予权限以将新的 Facet 添加到对象
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ApplySchema.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ApplySchema.html) **
  - **描述:** 授予权限以将已发布的输入架构复制到与已发布架构具有相同名称和版本的目录中
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AttachObject.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AttachObject.html) **
  - **描述:** 授予权限以将一个现有对象附加到另一个现有对象
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AttachPolicy.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AttachPolicy.html) **
  - **描述:** 授予权限以将策略对象附加到任何其他对象
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AttachToIndex.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AttachToIndex.html) **
  - **描述:** 授予权限以将指定对象附加到指定索引
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AttachTypedLink.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_AttachTypedLink.html) **
  - **描述:** 授予将键入链接 b/w 附加源和目标对象引用的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_BatchRead.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_BatchRead.html) **
  - **描述:** 授予权限以执行一个批处理中的所有读取操作。内部的每个单独操作都 BatchRead 需要明确授予权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_BatchWrite.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_BatchWrite.html) **
  - **描述:** 授予权限以执行一个批处理中的所有写入操作。内部的每个单独操作都 BatchWrite 需要明确授予权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateDirectory.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateDirectory.html) **
  - **描述:** 授予权限以将已发布架构复制到目录中，以便创建目录
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateFacet.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateFacet.html) **
  - **描述:** 授予权限以在架构中创建新 Facet
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateIndex.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateIndex.html) **
  - **描述:** 授予权限以创建索引对象
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateObject.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateObject.html) **
  - **描述:** 授予权限以在目录中创建目标
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateSchema.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateSchema.html) **
  - **描述:** 授予权限以在开发状态中创建新架构
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateTypedLinkFacet.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_CreateTypedLinkFacet.html) **
  - **描述:** 授予权限以在架构中创建新 Typed Link 分面
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteDirectory.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteDirectory.html) **
  - **描述:** 授予权限以删除目录。只能删除被禁用的目录
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteFacet.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteFacet.html) **
  - **描述:** 授予权限以删除给定 Facet。与该分面关联的所有属性和规则均会被删除
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteObject.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteObject.html) **
  - **描述:** 授予权限以删除一个对象及其关联的属性
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteSchema.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteSchema.html) **
  - **描述:** 授予权限以删除给定架构
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteTypedLinkFacet.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DeleteTypedLinkFacet.html) **
  - **描述:** 授予删除给定 TypedLink Facet 的权限。与该分面关联的所有属性和规则均会被删除
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DetachFromIndex.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DetachFromIndex.html) **
  - **描述:** 授予权限以从指定索引分离指定对象
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DetachObject.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DetachObject.html) **
  - **描述:** 授予权限以将给定的对象与其父级对象分离
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DetachPolicy.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DetachPolicy.html) **
  - **描述:** 授予权限以从对象分离策略
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DetachTypedLink.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DetachTypedLink.html) **
  - **描述:** 授予在给定源和目标对象引用下分离 b/w 给定键入链接的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DisableDirectory.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_DisableDirectory.html) **
  - **描述:** 授予权限以禁用指定目录
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_EnableDirectory.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_EnableDirectory.html) **
  - **描述:** 授予权限以启用指定目录
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetAppliedSchemaVersion.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetAppliedSchemaVersion.html) **
  - **描述:** 授予权限以返回当前应用的架构版本 ARN 的权限，包括正在使用的次要版本
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetDirectory.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetDirectory.html) **
  - **描述:** 授予权限以检索有关目录的元数据
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetFacet.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetFacet.html) **
  - **描述:** 授予获取 Facet 详细信息的权限，例如分面名称、属性、规则或 ObjectType
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetLinkAttributes.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetLinkAttributes.html) **
  - **描述:** 授予权限以检索与类型化链接关联的属性
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetObjectAttributes.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetObjectAttributes.html) **
  - **描述:** 授予权限以检索与对象关联的分面中的属性
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetObjectInformation.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetObjectInformation.html) **
  - **描述:** 授予权限以检索对象的元数据
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetSchemaAsJson.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetSchemaAsJson.html) **
  - **描述:** 授予权限以检索架构的 JSON 表示
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetTypedLinkFacetInformation.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_GetTypedLinkFacetInformation.html) **
  - **描述:** 授予权限以返回与给定的类型化链接分面关联的身份属性顺序信息
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListAppliedSchemaArns.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListAppliedSchemaArns.html) **
  - **描述:** 授予权限以列出应用于目录的架构
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListAttachedIndices.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListAttachedIndices.html) **
  - **描述:** 授予权限以列出附加到对象的索引
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListDevelopmentSchemaArns.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListDevelopmentSchemaArns.html) **
  - **描述:** 授予权限以检索处于开发状态的架构 ARN
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListDirectories.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListDirectories.html) **
  - **描述:** 授予权限以列出账户中创建的目录
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListFacetAttributes.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListFacetAttributes.html) **
  - **描述:** 授予权限以检索附加到分面的属性
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListFacetNames.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListFacetNames.html) **
  - **描述:** 授予权限以检索存在于架构中的分面名称
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListIncomingTypedLinks.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListIncomingTypedLinks.html) **
  - **描述:** 授予返回给定对象所有传入内容的分页列表 TypedLinks 的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListIndex.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListIndex.html) **
  - **描述:** 授予权限以列出附加到指定索引的对象
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListManagedSchemaArns.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListManagedSchemaArns.html) **
  - **描述:** 授予权限以列出每个托管式架构的主要版本系列。如果将主要版本 ARN 提供为 SchemaArn，则将改为列出该系列中的次要版本修订版
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectAttributes.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectAttributes.html) **
  - **描述:** 授予权限以列出与一个对象关联的所有属性
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectChildren.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectChildren.html) **
  - **描述:** 授予权限以返回与给定对象关联的子对象分页列表
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectParentPaths.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectParentPaths.html) **
  - **描述:** 授予权限以检索任意对象类型（例如节点、叶节点、策略节点和索引节点对象）的所有可用父级路径
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectParents.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectParents.html) **
  - **描述:** 授予权限以按分页形式列出与给定对象关联的父级对象
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectPolicies.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListObjectPolicies.html) **
  - **描述:** 授予权限以按分页形式返回一个对象附加的策略
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListOutgoingTypedLinks.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListOutgoingTypedLinks.html) **
  - **描述:** 授予返回给定对象所有传出内容的分页列表 TypedLinks 的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListPolicyAttachments.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListPolicyAttachments.html) **
  - **描述:** 授予退还给定政策所关联的所有内容的权限 ObjectIdentifiers 
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListPublishedSchemaArns.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListPublishedSchemaArns.html) **
  - **描述:** 授予权限以检索已发布的架构 ARN
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListTagsForResource.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListTagsForResource.html) **
  - **描述:** 授予权限以返回资源的标签
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListTypedLinkFacetAttributes.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListTypedLinkFacetAttributes.html) **
  - **描述:** 授予权限以返回与类型化链接分面关联的属性的分页列表
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListTypedLinkFacetNames.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_ListTypedLinkFacetNames.html) **
  - **描述:** 授予权限以返回架构中存在的类型化链接分面名称的分页列表
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_LookupPolicy.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_LookupPolicy.html) **
  - **描述:** 授予权限以列出从目录的根到指定对象的所有策略
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_PublishSchema.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_PublishSchema.html) **
  - **描述:** 授予权限以发布带有版本的开发架构
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_PutSchemaFromJson.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_PutSchemaFromJson.html) **
  - **描述:** 授予权限以更新使用 JSON 上传的架构。仅适用于开发架构
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_RemoveFacetFromObject.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_RemoveFacetFromObject.html) **
  - **描述:** 授予权限以从指定对象中删除指定分面
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_TagResource.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_TagResource.html) **
  - **描述:** 授予权限以将标签添加到资源中
  - **访问级别:** Tagging
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UntagResource.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UntagResource.html) **
  - **描述:** 授予权限以从资源中删除标签
  - **访问级别:** 标签
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateFacet.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateFacet.html) **
  - **描述:** 授予 add/update /删除现有属性、规则或 Facet ObjectType 的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-appliedSchema](#amazonclouddirectory-appliedSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateLinkAttributes.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateLinkAttributes.html) **
  - **描述:** 授予权限以更新给定的类型化链接属性。要更新的属性不得影响键入链接的身份，如其定义 IdentityAttributeOrder
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateObjectAttributes.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateObjectAttributes.html) **
  - **描述:** 授予权限以更新给定对象的属性
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateSchema.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateSchema.html) **
  - **描述:** 授予权限以使用新名称更新架构名称
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateTypedLinkFacet.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpdateTypedLinkFacet.html) **
  - **描述:** 授予 add/update /删除 Facet 的现有属性、规则、身份属性顺序的 TypedLink 权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpgradeAppliedSchema.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpgradeAppliedSchema.html) **
  - **描述:** 授予使用中的架构更新就地升级单个目录 PublishedSchemaArn 的权限。 MinorVersion Backwards-compatible 读者可以立即对目录中的所有对象进行次要版本升级
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-directory](#amazonclouddirectory-directory)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpgradePublishedSchema.html](https://docs.aws.amazon.com/directoryservice/latest/APIReference/API_UpgradePublishedSchema.html) **
  - **描述:** 授予使用当前内容在新的次要版本修订下升级已发布架构的权限 DevelopmentSchemaArn
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-developmentSchema](#amazonclouddirectory-developmentSchema)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonclouddirectory-publishedSchema](#amazonclouddirectory-publishedSchema)  / **条件键:**  / **相关操作:** 



## Amazon Cloud Directory 定义的资源类型
<a name="amazonclouddirectory-resources-for-iam-policies"></a>

以下资源类型是由该服务定义的，可以在 IAM 权限策略语句的 `Resource` 元素中使用这些资源类型。[操作表](#amazonclouddirectory-actions-as-permissions)中的每个操作指定了可以使用该操作指定的资源类型。您也可以在策略中包含条件键，从而定义资源类型。这些键显示在资源类型表的最后一列。有关下表中各列的详细信息，请参阅[资源类型表](reference_policies_actions-resources-contextkeys.html#resources_table)。


****  

| 资源类型 | ARN | 条件键 | 
| --- | --- | --- | 
|   [https://docs.aws.amazon.com/directoryservice/latest/admin-guide/cd_key_concepts.html#whatisdirectory](https://docs.aws.amazon.com/directoryservice/latest/admin-guide/cd_key_concepts.html#whatisdirectory)  |  arn:${Partition}:clouddirectory:${Region}:${Account}:directory/${DirectoryId}/schema/${SchemaName}/${Version}  |  | 
|   [https://docs.aws.amazon.com/directoryservice/latest/admin-guide/cd_key_concepts.html#whatisdirectory](https://docs.aws.amazon.com/directoryservice/latest/admin-guide/cd_key_concepts.html#whatisdirectory)  |  arn:${Partition}:clouddirectory:${Region}:${Account}:schema/development/${SchemaName}  |  | 
|   [https://docs.aws.amazon.com/directoryservice/latest/admin-guide/cd_key_concepts.html#whatisdirectory](https://docs.aws.amazon.com/directoryservice/latest/admin-guide/cd_key_concepts.html#whatisdirectory)  |  arn:${Partition}:clouddirectory:${Region}:${Account}:directory/${DirectoryId}  |  | 
|   [https://docs.aws.amazon.com/directoryservice/latest/admin-guide/cd_key_concepts.html#whatisdirectory](https://docs.aws.amazon.com/directoryservice/latest/admin-guide/cd_key_concepts.html#whatisdirectory)  |  arn:${Partition}:clouddirectory:${Region}:${Account}:schema/published/${SchemaName}/${Version}  |  | 

## Amazon Cloud Directory 的条件键
<a name="amazonclouddirectory-policy-keys"></a>

Cloud Directory 没有可以在策略语句的 `Condition` 元素中使用的服务特定上下文键。有关适用于所有服务的全局上下文键列表，请参阅 [AWS 全局条件上下文键](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html)。