Attach Amazon Bedrock permissions to a user or role
-
Select Users or Roles and then select your user or role.
-
In the Permissions tab, choose Add permissions and then choose Add AWS managed policy.
Choose2.1theAmazon Bedrock APIs (BedrockAPIs)PermissionDescriptionbedrock:Get*Read any Bedrock resourcebedrock:List*List any Bedrock resourcebedrock:CallWithBearerTokenAuthenticate using bearer tokenbedrock:BatchDeleteEvaluationJobBatch delete evaluation jobsbedrock:CreateEvaluationJobCreate a model evaluation jobbedrock:CreateGuardrailCreate a guardrailbedrock:CreateGuardrailVersionVersion a guardrailbedrock:CreateInferenceProfileCreate an inference profilebedrock:CreateModelCopyJobCopy a modelbedrock:CreateModelCustomizationJobFine-tune or customize a modelbedrock:CreateModelImportJobImport an external modelbedrock:CreateModelInvocationJobCreate a batch invocation jobbedrock:CreatePromptRouterCreate a prompt routerbedrock:CreateProvisionedModelThroughputProvision dedicated model capacitybedrock:DeleteCustomModelDelete a custom modelbedrock:DeleteGuardrailDelete a guardrailbedrock:DeleteImportedModelDelete an imported modelbedrock:DeleteInferenceProfileDelete an inference profilebedrock:DeletePromptRouterDelete a prompt routerbedrock:DeleteProvisionedModelThroughputRemove provisioned model capacitybedrock:StopEvaluationJobStop a running evaluation jobbedrock:StopModelCustomizationJobStop a model customization jobbedrock:StopModelInvocationJobStop a model invocation jobbedrock:TagResourceAdd tags to a resourcebedrock:UntagResourceRemove tags from a resourcebedrock:UpdateGuardrailModify an existing guardrailbedrock:UpdateProvisionedModelThroughputModify provisioned capacitybedrock:ApplyGuardrailApply a guardrail to contentbedrock:InvokeModelInvoke a model for inferencebedrock:InvokeModelWithResponseStreamInvoke a model with streaming outputResource:*(All resources)2.2 KMS Key Access (DescribeKey)PermissionDescriptionkms:DescribeKeyLook up details of a KMS encryption keyResource:arn:*:kms:*:::*(All KMS keys across all accounts and regions)2.3 Supporting Infrastructure Access (APIsWithAllResourceAccess)PermissionDescriptioniam:ListRolesList all IAM rolesec2:DescribeVpcsDescribe VPC configurationsec2:DescribeSubnetsDescribe subnet configurationsec2:DescribeSecurityGroupsDescribe security group configurationsResource:*(All resources)2.4 Bedrock Mantle APIs (BedrockMantleAPIs)PermissionDescriptionbedrock-mantle:CallWithBearerTokenAuthenticate using bearer tokenbedrock-mantle:Get*Read any Bedrock Mantle resourcebedrock-mantle:List*List any Bedrock Mantle resourcebedrock-mantle:CreateInferenceCreate an inference requestResource:*(All resources)2.5AmazonBedrockFullAccess AWSMarketplacemanaged– Third-Party Models (MarketplaceOperationsFromBedrockFor3pModels)PermissionDescriptionaws-marketplace:SubscribeSubscribe to a marketplace listingaws-marketplace:ViewSubscriptionsView existing subscriptionsaws-marketplace:UnsubscribeUnsubscribe from a listingResource:*(All resources)Condition:Only allowed when the request is madeviabedrock.amazonaws.com
policy.
References: