Skip to main content

owners

Creates, updates, deletes or gets an owner resource or lists owners in a region

Overview

Nameowners
TypeResource
DescriptionA owner can set up authorization permissions on their resources.
Idawscc.datazone.owners

Fields

NameDatatypeDescription
entity_typestringThe type of an entity.
ownerobjectThe owner that you want to add to the entity.
entity_identifierstringThe ID of the entity to which you want to add an owner.
domain_identifierstringThe ID of the domain in which you want to add the entity owner.
regionstringAWS region.

For more information, see AWS::DataZone::Owner.

Methods

NameAccessible byRequired Params
create_resourceINSERTDomainIdentifier, EntityIdentifier, EntityType, Owner, region
delete_resourceDELETEdata__Identifier, region
list_resourcesSELECTregion
get_resourceSELECTdata__Identifier, region

SELECT examples

Gets all properties from an individual owner.

SELECT
region,
entity_type,
owner,
entity_identifier,
domain_identifier
FROM awscc.datazone.owners
WHERE region = 'us-east-1' AND data__Identifier = '<DomainIdentifier>|<EntityType>|<EntityIdentifier>|<OwnerType>|<OwnerIdentifier>';

INSERT example

Use the following StackQL query and manifest file to create a new owner resource, using stack-deploy.

/*+ create */
INSERT INTO awscc.datazone.owners (
EntityType,
Owner,
EntityIdentifier,
DomainIdentifier,
region
)
SELECT
'{{ EntityType }}',
'{{ Owner }}',
'{{ EntityIdentifier }}',
'{{ DomainIdentifier }}',
'{{ region }}';

DELETE example

/*+ delete */
DELETE FROM awscc.datazone.owners
WHERE data__Identifier = '<DomainIdentifier|EntityType|EntityIdentifier|OwnerType|OwnerIdentifier>'
AND region = 'us-east-1';

Permissions

To operate on the owners resource, the following permissions are required:

Read

datazone:ListEntityOwners,
iam:GetRole

Create

datazone:AddEntityOwner,
datazone:ListEntityOwners,
datazone:GetGroupProfile,
datazone:GetUserProfile,
iam:GetRole

List

datazone:ListEntityOwners,
iam:GetRole

Delete

datazone:RemoveEntityOwner,
datazone:GetUserProfile,
iam:GetRole