MDAA TS Docs
    Preparing search index...

    One statement in a VPC endpoint policy.

    AWS: VPC endpoint policy statement

    Validation: actions must not be empty

    interface VpcEndpointPolicyStatementProperty {
        actions: string[];
        conditions?: { [operator: string]: unknown };
        effect: VpcEndpointPolicyEffect;
        principals?: string[];
        resources?: string[];
        sid?: string;
    }
    Index

    Properties

    actions: string[]

    IAM actions allowed or denied by this statement. At least one.

    conditions?: { [operator: string]: unknown }

    IAM condition block for this statement, in the { Operator: { key: value } } shape - for example { StringEquals: { 'aws:PrincipalAccount': '111122223333' } }. Passed through verbatim.

    This is how a statement is scoped when its principals cannot be narrowed: an endpoint policy is evaluated with the caller's account and organization in the request context even where the calling role's ARN is not matchable, so an account- or org-scoped condition narrows a statement that would otherwise have to stay on "*".

    IAM effect for the statement.

    principals?: string[]

    IAM principal ARNs allowed or denied by this statement. Omit it, or use *, for an endpoint policy that relies on identity policy and endpoint security groups for principal control.

    resources?: string[]

    Resources matched by this statement, each an ARN or *. Omitting it matches every resource, which a gateway endpoint's statement may not do: it carries every subnet on its route tables, so defaulting to * there would grant them all the statement's actions across the whole service. State ["*"] on a gateway statement to accept that deliberately.

    sid?: string

    Statement identifier, so the rendered endpoint policy is readable in the console.