"AWS": "123456789012"
"AWS": "arn:aws:iam::123456789012:root"
↑ どちらも同義。上は下の書き方のエイリアス
"AWS": "arn:aws:iam::AWS-account-ID:role/role-name"
"AWS": "arn:aws:sts::AWS-account-ID:assumed-role/role-name/role-session-name"
"AWS": "arn:aws:iam::AWS-account-ID:user/user-name"
"Federated": "accounts.google.com"
"Federated": "arn:aws:iam::AWS-account-ID:saml-provider/provider-name"
"AWS": "arn:aws:sts::AWS-account-ID:federated-user/user-name"
サービスプリンシパルの識別子にはサービス名が含まれ、通常は次の形式になります。
service-name.amazonaws.com
"Service": "elasticloadbalancing.amazonaws.com"
"*"
"AWS" : "*"
↑ どちらも同義。上は下の書き方のエイリアス
---