openapi: 3.1.0 info: title: Amazon Web Services accessanalyzer 2012 09 25 2015 01 01 API description:

Identity and Access Management Access Analyzer helps you to set, verify, and refine your IAM policies by providing a suite of capabilities. Its features include findings for external and unused access, basic and custom policy checks for validating policies, and policy generation to generate fine-grained policies. To start using IAM Access Analyzer to identify external or unused access, you first need to create an analyzer.

External access analyzers help identify potential risks of accessing resources by enabling you to identify any resource policies that grant access to an external principal. It does this by using logic-based reasoning to analyze resource-based policies in your Amazon Web Services environment. An external principal can be another Amazon Web Services account, a root user, an IAM user or role, a federated user, an Amazon Web Services service, or an anonymous user. You can also use IAM Access Analyzer to preview public and cross-account access to your resources before deploying permissions changes.

Unused access analyzers help identify potential identity access risks by enabling you to identify unused IAM roles, unused access keys, unused console passwords, and IAM principals with unused service and action-level permissions.

Beyond findings, IAM Access Analyzer provides basic and custom policy checks to validate IAM policies before deploying permissions changes. You can use policy generation to refine permissions by attaching a policy generated using access activity logged in CloudTrail logs.

This guide describes the IAM Access Analyzer operations that you can call programmatically. For general information about IAM Access Analyzer, see Identity and Access Management Access Analyzer in the IAM User Guide.

tags: - name: 2015 01 01 paths: /2015-01-01/es/ccs/inboundConnection/{ConnectionId}/accept: PUT: summary: Amazon Web Services Acceptinboundcrossclustersearchconnection description: Allows the destination domain owner to accept an inbound cross-cluster search connection request. operationId: amazonWebServicesAcceptInboundCrossClusterSearchConnection tags: - 2015 01 01 /2015-01-01/tags: POST: summary: Amazon Web Services Addtags description: Attaches tags to an existing Elasticsearch domain. Tags are a set of case-sensitive key value pairs. An Elasticsearch domain may have up to 10 tags. See Tagging Amazon Elasticsearch Service Domains for more information. operationId: amazonWebServicesAddTags tags: - 2015 01 01 /2015-01-01/packages/associate/{PackageID}/{DomainName}: POST: summary: Amazon Web Services Associatepackage description: Associates a package with an Amazon ES domain. operationId: amazonWebServicesAssociatePackage tags: - 2015 01 01 /2015-01-01/es/domain/{DomainName}/authorizeVpcEndpointAccess: POST: summary: Amazon Web Services Authorizevpcendpointaccess description: Provides access to an Amazon OpenSearch Service domain through the use of an interface VPC endpoint. operationId: amazonWebServicesAuthorizeVpcEndpointAccess tags: - 2015 01 01 /2015-01-01/es/domain/{DomainName}/config/cancel: POST: summary: Amazon Web Services Canceldomainconfigchange description: Cancels a pending configuration change on an Amazon OpenSearch Service domain. operationId: amazonWebServicesCancelDomainConfigChange tags: - 2015 01 01 /2015-01-01/es/serviceSoftwareUpdate/cancel: POST: summary: Amazon Web Services Cancelelasticsearchservicesoftwareupdate description: Cancels a scheduled service software update for an Amazon ES domain. You can only perform this operation before the AutomatedUpdateDate and when the UpdateStatus is in the PENDING_UPDATE state. operationId: amazonWebServicesCancelElasticsearchServiceSoftwareUpdate tags: - 2015 01 01 /2015-01-01/es/domain: POST: summary: Amazon Web Services Createelasticsearchdomain description: Creates a new Elasticsearch domain. For more information, see Creating Elasticsearch Domains in the Amazon Elasticsearch Service Developer Guide. operationId: amazonWebServicesCreateElasticsearchDomain tags: - 2015 01 01 /2015-01-01/es/ccs/outboundConnection: POST: summary: Amazon Web Services Createoutboundcrossclustersearchconnection description: Creates a new cross-cluster search connection from a source domain to a destination domain. operationId: amazonWebServicesCreateOutboundCrossClusterSearchConnection tags: - 2015 01 01 /2015-01-01/packages: POST: summary: Amazon Web Services Createpackage description: Create a package for use with Amazon ES domains. operationId: amazonWebServicesCreatePackage tags: - 2015 01 01 /2015-01-01/es/vpcEndpoints: GET: summary: Amazon Web Services Listvpcendpoints description: Retrieves all Amazon OpenSearch Service-managed VPC endpoints in the current account and Region. operationId: amazonWebServicesListVpcEndpoints tags: - 2015 01 01 /2015-01-01/es/domain/{DomainName}: GET: summary: Amazon Web Services Describeelasticsearchdomain description: Returns domain configuration information about the specified Elasticsearch domain, including the domain ID, domain endpoint, and domain ARN. operationId: amazonWebServicesDescribeElasticsearchDomain tags: - 2015 01 01 /2015-01-01/es/role: DELETE: summary: Amazon Web Services Deleteelasticsearchservicerole description: Deletes the service-linked role that Elasticsearch Service uses to manage and maintain VPC domains. Role deletion will fail if any existing VPC domains use the role. You must delete any such Elasticsearch domains before deleting the role. See Deleting Elasticsearch Service Role in VPC Endpoints for Amazon Elasticsearch Service Domains. operationId: amazonWebServicesDeleteElasticsearchServiceRole tags: - 2015 01 01 /2015-01-01/es/ccs/inboundConnection/{ConnectionId}: DELETE: summary: Amazon Web Services Deleteinboundcrossclustersearchconnection description: Allows the destination domain owner to delete an existing inbound cross-cluster search connection. operationId: amazonWebServicesDeleteInboundCrossClusterSearchConnection tags: - 2015 01 01 /2015-01-01/es/ccs/outboundConnection/{ConnectionId}: DELETE: summary: Amazon Web Services Deleteoutboundcrossclustersearchconnection description: Allows the source domain owner to delete an existing outbound cross-cluster search connection. operationId: amazonWebServicesDeleteOutboundCrossClusterSearchConnection tags: - 2015 01 01 /2015-01-01/packages/{PackageID}: DELETE: summary: Amazon Web Services Deletepackage description: Delete the package. operationId: amazonWebServicesDeletePackage tags: - 2015 01 01 /2015-01-01/es/vpcEndpoints/{VpcEndpointId}: DELETE: summary: Amazon Web Services Deletevpcendpoint description: Deletes an Amazon OpenSearch Service-managed interface VPC endpoint. operationId: amazonWebServicesDeleteVpcEndpoint tags: - 2015 01 01 /2015-01-01/es/domain/{DomainName}/autoTunes: GET: summary: Amazon Web Services Describedomainautotunes description: Provides scheduled Auto-Tune action details for the Elasticsearch domain, such as Auto-Tune action type, description, severity, and scheduled date. operationId: amazonWebServicesDescribeDomainAutoTunes tags: - 2015 01 01 /2015-01-01/es/domain/{DomainName}/progress: GET: summary: Amazon Web Services Describedomainchangeprogress description: Returns information about the current blue/green deployment happening on a domain, including a change ID, status, and progress stages. operationId: amazonWebServicesDescribeDomainChangeProgress tags: - 2015 01 01 /2015-01-01/es/domain/{DomainName}/config: POST: summary: Amazon Web Services Updateelasticsearchdomainconfig description: 'Modifies the cluster configuration of the specified Elasticsearch domain, setting as setting the instance type and the number of instances. ' operationId: amazonWebServicesUpdateElasticsearchDomainConfig tags: - 2015 01 01 /2015-01-01/es/domain-info: POST: summary: Amazon Web Services Describeelasticsearchdomains description: Returns domain configuration information about the specified Elasticsearch domains, including the domain ID, domain endpoint, and domain ARN. operationId: amazonWebServicesDescribeElasticsearchDomains tags: - 2015 01 01 /2015-01-01/es/instanceTypeLimits/{ElasticsearchVersion}/{InstanceType}: GET: summary: Amazon Web Services Describeelasticsearchinstancetypelimits description: ' Describe Elasticsearch Limits for a given InstanceType and ElasticsearchVersion. When modifying existing Domain, specify the DomainName to know what Limits are supported for modifying. ' operationId: amazonWebServicesDescribeElasticsearchInstanceTypeLimits tags: - 2015 01 01 /2015-01-01/es/ccs/inboundConnection/search: POST: summary: Amazon Web Services Describeinboundcrossclustersearchconnections description: Lists all the inbound cross-cluster search connections for a destination domain. operationId: amazonWebServicesDescribeInboundCrossClusterSearchConnections tags: - 2015 01 01 /2015-01-01/es/ccs/outboundConnection/search: POST: summary: Amazon Web Services Describeoutboundcrossclustersearchconnections description: Lists all the outbound cross-cluster search connections for a source domain. operationId: amazonWebServicesDescribeOutboundCrossClusterSearchConnections tags: - 2015 01 01 /2015-01-01/packages/describe: POST: summary: Amazon Web Services Describepackages description: Describes all packages available to Amazon ES. Includes options for filtering, limiting the number of results, and pagination. operationId: amazonWebServicesDescribePackages tags: - 2015 01 01 /2015-01-01/es/reservedInstanceOfferings: GET: summary: Amazon Web Services Describereservedelasticsearchinstanceofferings description: Lists available reserved Elasticsearch instance offerings. operationId: amazonWebServicesDescribeReservedElasticsearchInstanceOfferings tags: - 2015 01 01 /2015-01-01/es/reservedInstances: GET: summary: Amazon Web Services Describereservedelasticsearchinstances description: Returns information about reserved Elasticsearch instances for this account. operationId: amazonWebServicesDescribeReservedElasticsearchInstances tags: - 2015 01 01 /2015-01-01/es/vpcEndpoints/describe: POST: summary: Amazon Web Services Describevpcendpoints description: Describes one or more Amazon OpenSearch Service-managed VPC endpoints. operationId: amazonWebServicesDescribeVpcEndpoints tags: - 2015 01 01 /2015-01-01/packages/dissociate/{PackageID}/{DomainName}: POST: summary: Amazon Web Services Dissociatepackage description: Dissociates a package from the Amazon ES domain. operationId: amazonWebServicesDissociatePackage tags: - 2015 01 01 /2015-01-01/es/compatibleVersions: GET: summary: Amazon Web Services Getcompatibleelasticsearchversions description: ' Returns a list of upgrade compatible Elastisearch versions. You can optionally pass a DomainName to get all upgrade compatible Elasticsearch versions for that specific domain. ' operationId: amazonWebServicesGetCompatibleElasticsearchVersions tags: - 2015 01 01 /2015-01-01/packages/{PackageID}/history: GET: summary: Amazon Web Services Getpackageversionhistory description: Returns a list of versions of the package, along with their creation time and commit message. operationId: amazonWebServicesGetPackageVersionHistory tags: - 2015 01 01 /2015-01-01/es/upgradeDomain/{DomainName}/history: GET: summary: Amazon Web Services Getupgradehistory description: Retrieves the complete history of the last 10 upgrades that were performed on the domain. operationId: amazonWebServicesGetUpgradeHistory tags: - 2015 01 01 /2015-01-01/es/upgradeDomain/{DomainName}/status: GET: summary: Amazon Web Services Getupgradestatus description: Retrieves the latest status of the last upgrade or upgrade eligibility check that was performed on the domain. operationId: amazonWebServicesGetUpgradeStatus tags: - 2015 01 01 /2015-01-01/domain: GET: summary: Amazon Web Services Listdomainnames description: 'Returns the name of all Elasticsearch domains owned by the current user''s account. ' operationId: amazonWebServicesListDomainNames tags: - 2015 01 01 /2015-01-01/packages/{PackageID}/domains: GET: summary: Amazon Web Services Listdomainsforpackage description: Lists all Amazon ES domains associated with the package. operationId: amazonWebServicesListDomainsForPackage tags: - 2015 01 01 /2015-01-01/es/instanceTypes/{ElasticsearchVersion}: GET: summary: Amazon Web Services Listelasticsearchinstancetypes description: List all Elasticsearch instance types that are supported for given ElasticsearchVersion operationId: amazonWebServicesListElasticsearchInstanceTypes tags: - 2015 01 01 /2015-01-01/es/versions: GET: summary: Amazon Web Services Listelasticsearchversions description: List all supported Elasticsearch versions operationId: amazonWebServicesListElasticsearchVersions tags: - 2015 01 01 /2015-01-01/domain/{DomainName}/packages: GET: summary: Amazon Web Services Listpackagesfordomain description: Lists all packages associated with the Amazon ES domain. operationId: amazonWebServicesListPackagesForDomain tags: - 2015 01 01 /2015-01-01/tags/: GET: summary: Amazon Web Services Listtags description: Returns all tags for the given Elasticsearch domain. operationId: amazonWebServicesListTags tags: - 2015 01 01 /2015-01-01/es/domain/{DomainName}/listVpcEndpointAccess: GET: summary: Amazon Web Services Listvpcendpointaccess description: Retrieves information about each principal that is allowed to access a given Amazon OpenSearch Service domain through the use of an interface VPC endpoint. operationId: amazonWebServicesListVpcEndpointAccess tags: - 2015 01 01 /2015-01-01/es/domain/{DomainName}/vpcEndpoints: GET: summary: Amazon Web Services Listvpcendpointsfordomain description: Retrieves all Amazon OpenSearch Service-managed VPC endpoints associated with a particular domain. operationId: amazonWebServicesListVpcEndpointsForDomain tags: - 2015 01 01 /2015-01-01/es/purchaseReservedInstanceOffering: POST: summary: Amazon Web Services Purchasereservedelasticsearchinstanceoffering description: Allows you to purchase reserved Elasticsearch instances. operationId: amazonWebServicesPurchaseReservedElasticsearchInstanceOffering tags: - 2015 01 01 /2015-01-01/es/ccs/inboundConnection/{ConnectionId}/reject: PUT: summary: Amazon Web Services Rejectinboundcrossclustersearchconnection description: Allows the destination domain owner to reject an inbound cross-cluster search connection request. operationId: amazonWebServicesRejectInboundCrossClusterSearchConnection tags: - 2015 01 01 /2015-01-01/tags-removal: POST: summary: Amazon Web Services Removetags description: Removes the specified set of tags from the specified Elasticsearch domain. operationId: amazonWebServicesRemoveTags tags: - 2015 01 01 /2015-01-01/es/domain/{DomainName}/revokeVpcEndpointAccess: POST: summary: Amazon Web Services Revokevpcendpointaccess description: Revokes access to an Amazon OpenSearch Service domain that was provided through an interface VPC endpoint. operationId: amazonWebServicesRevokeVpcEndpointAccess tags: - 2015 01 01 /2015-01-01/es/serviceSoftwareUpdate/start: POST: summary: Amazon Web Services Startelasticsearchservicesoftwareupdate description: Schedules a service software update for an Amazon ES domain. operationId: amazonWebServicesStartElasticsearchServiceSoftwareUpdate tags: - 2015 01 01 /2015-01-01/packages/update: POST: summary: Amazon Web Services Updatepackage description: Updates a package for use with Amazon ES domains. operationId: amazonWebServicesUpdatePackage tags: - 2015 01 01 /2015-01-01/es/vpcEndpoints/update: POST: summary: Amazon Web Services Updatevpcendpoint description: Modifies an Amazon OpenSearch Service-managed interface VPC endpoint. operationId: amazonWebServicesUpdateVpcEndpoint tags: - 2015 01 01 /2015-01-01/es/upgradeDomain: POST: summary: Amazon Web Services Upgradeelasticsearchdomain description: Allows you to either upgrade your domain or perform an Upgrade eligibility check to a compatible Elasticsearch version. operationId: amazonWebServicesUpgradeElasticsearchDomain tags: - 2015 01 01