openapi: 3.1.0
info:
title: Amazon Web Services accessanalyzer 2012 09 25 Core Networks API
description: <p>Identity and Access Management Access Analyzer helps you to set, verify, and refine your IAM policies by providing a suite of capabilities. Its features include findings for external and unused access, basic and custom policy checks for validating policies, and policy generation to generate fine-grained policies. To start using IAM Access Analyzer to identify external or unused access, you first need to create an analyzer.</p> <p> <b>External access analyzers</b> help identify potential risks of accessing resources by enabling you to identify any resource policies that grant access to an external principal. It does this by using logic-based reasoning to analyze resource-based policies in your Amazon Web Services environment. An external principal can be another Amazon Web Services account, a root user, an IAM user or role, a federated user, an Amazon Web Services service, or an anonymous user. You can also use IAM Access Analyzer to preview public and cross-account access to your resources before deploying permissions changes.</p> <p> <b>Unused access analyzers</b> help identify potential identity access risks by enabling you to identify unused IAM roles, unused access keys, unused console passwords, and IAM principals with unused service and action-level permissions.</p> <p>Beyond findings, IAM Access Analyzer provides basic and custom policy checks to validate IAM policies before deploying permissions changes. You can use policy generation to refine permissions by attaching a policy generated using access activity logged in CloudTrail logs. </p> <p>This guide describes the IAM Access Analyzer operations that you can call programmatically. For general information about IAM Access Analyzer, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html">Identity and Access Management Access Analyzer</a> in the <b>IAM User Guide</b>.</p>
tags:
- name: Core Networks
paths:
/core-networks:
GET:
summary: Amazon Web Services Listcorenetworks
description: Returns a list of owned and shared core networks.
operationId: amazonWebServicesListCoreNetworks
tags:
- Core Networks
/core-networks/{coreNetworkId}:
PATCH:
summary: Amazon Web Services Updatecorenetwork
description: Updates the description of a core network.
operationId: amazonWebServicesUpdateCoreNetwork
tags:
- Core Networks
/core-networks/{coreNetworkId}/core-network-policy-versions/{policyVersionId}:
DELETE:
summary: Amazon Web Services Deletecorenetworkpolicyversion
description: Deletes a policy version from a core network. You can't delete the current LIVE policy.
operationId: amazonWebServicesDeleteCoreNetworkPolicyVersion
tags:
- Core Networks
/core-networks/{coreNetworkId}/core-network-change-sets/{policyVersionId}/execute:
POST:
summary: Amazon Web Services Executecorenetworkchangeset
description: Executes a change set on your core network. Deploys changes globally based on the policy submitted..
operationId: amazonWebServicesExecuteCoreNetworkChangeSet
tags:
- Core Networks
/core-networks/{coreNetworkId}/core-network-change-events/{policyVersionId}:
GET:
summary: Amazon Web Services Getcorenetworkchangeevents
description: Returns information about a core network change event.
operationId: amazonWebServicesGetCoreNetworkChangeEvents
tags:
- Core Networks
/core-networks/{coreNetworkId}/core-network-change-sets/{policyVersionId}:
GET:
summary: Amazon Web Services Getcorenetworkchangeset
description: Returns a change set between the LIVE core network policy and a submitted policy.
operationId: amazonWebServicesGetCoreNetworkChangeSet
tags:
- Core Networks
/core-networks/{coreNetworkId}/core-network-policy:
POST:
summary: Amazon Web Services Putcorenetworkpolicy
description: Creates a new, immutable version of a core network policy. A subsequent change set is created showing the differences between the LIVE policy and the submitted policy.
operationId: amazonWebServicesPutCoreNetworkPolicy
tags:
- Core Networks
/core-networks/{coreNetworkId}/core-network-policy-versions:
GET:
summary: Amazon Web Services Listcorenetworkpolicyversions
description: Returns a list of core network policy versions.
operationId: amazonWebServicesListCoreNetworkPolicyVersions
tags:
- Core Networks
/core-networks/{coreNetworkId}/core-network-policy-versions/{policyVersionId}/restore:
POST:
summary: Amazon Web Services Restorecorenetworkpolicyversion
description: Restores a previous policy version as a new, immutable version of a core network policy. A subsequent change set is created showing the differences between the LIVE policy and restored policy.
operationId: amazonWebServicesRestoreCoreNetworkPolicyVersion
tags:
- Core Networks