ReadonlyactionsIAM actions allowed or denied by this statement. At least one.
Optional ReadonlyconditionsIAM condition block for this statement, in the { Operator: { key: value } } shape - for example
{ StringEquals: { 'aws:PrincipalAccount': '111122223333' } }. Passed through verbatim.
This is how a statement is scoped when its principals cannot be narrowed: an endpoint policy is
evaluated with the caller's account and organization in the request context even where the calling
role's ARN is not matchable, so an account- or org-scoped condition narrows a statement that would
otherwise have to stay on "*".
ReadonlyeffectIAM effect for the statement.
Optional ReadonlyprincipalsIAM principal ARNs allowed or denied by this statement. Omit it, or use *, for an endpoint policy
that relies on identity policy and endpoint security groups for principal control.
Optional ReadonlyresourcesResources matched by this statement, each an ARN or *. Omitting it matches every resource, which a
gateway endpoint's statement may not do: it carries every subnet on its route tables, so defaulting
to * there would grant them all the statement's actions across the whole service. State ["*"] on
a gateway statement to accept that deliberately.
Optional ReadonlysidStatement identifier, so the rendered endpoint policy is readable in the console.
One statement in a VPC endpoint policy.
AWS: VPC endpoint policy statement
Validation: actions must not be empty