AWS DataSync (IAM)
JSON →AWS DataSync is a data transfer service that simplifies, automates, and accelerates moving data between on-premises storage and AWS.
Common permissions
datasync:ListTasksdatasync:DescribeTaskdatasync:CreateTaskdatasync:UpdateTaskdatasync:ListAgentsdatasync:DescribeAgentdatasync:CreateAgentdatasync:StartTaskExecution Least-privilege example
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"datasync:ListTasks",
"datasync:DescribeTask",
"datasync:CreateTask",
"datasync:UpdateTask",
"datasync:ListAgents",
"datasync:DescribeAgent",
"datasync:CreateAgent",
"datasync:StartTaskExecution"
],
"Resource": "*"
}
]
} Warnings
- Avoid datasync:* — grants full control including delete and modify operations.
- Avoid datasync:DeleteTask — can permanently delete data transfer tasks.
Resources
API
full doc /v1/iam/datasync