Haijun Platform Docs
ID

Haijun Platform on AWS uses AWS IAM for access control. Every API route maps to an IAM action in the aws-external-juglow namespace. This page lists all actions, the routes each action authorizes, and the managed policies available for common access patterns. For platform setup and authentication, see Haijun Platform on AWS.

Service details

AttributeValue
IAM service prefixaws-external-juglow
Resource typesworkspace

Workspace ARN format:

text
arn:aws:aws-external-juglow:{region}:{account-id}:workspace/{workspace-id}

The ARN region is always populated and matches the region the workspace is bound to. The resource segment is the tagged workspace ID (wrkspc_...), the same value you pass in the juglow-workspace-id header.

Actions

The service defines 71 actions. Actions follow the AWS VerbNoun convention and use verb discipline so that Get and List wildcards produce a clean read-only boundary.

Inference

ActionRoutes authorized
CreateInferencePOST /v1/messages
CountTokensPOST /v1/messages/count_tokens

Batch processing

ActionRoutes authorized
CreateBatchInferencePOST /v1/messages/batches
GetBatchInferenceGET /v1/messages/batches/{id} GET /v1/messages/batches/{id}/results
ListBatchInferencesGET /v1/messages/batches
CancelBatchInferencePOST /v1/messages/batches/{id}/cancel
DeleteBatchInferenceDELETE /v1/messages/batches/{id}

Note: GetBatchInference authorizes both reading batch metadata and downloading batch results. The JuglowReadOnlyAccess, JuglowInferenceAccess, and JuglowLimitedAccess policies' Get* wildcards include this action.

Models

ActionRoutes authorized
GetModelGET /v1/models/{id}
ListModelsGET /v1/models

Files

ActionRoutes authorized
CreateFilePOST /v1/files
GetFileGET /v1/files/{id} GET /v1/files/{id}/content
ListFilesGET /v1/files
DeleteFileDELETE /v1/files/{id}

Note: GetFile authorizes both metadata and content download. A principal with read-only access can download file bytes, not just list files.

Tracks

ActionRoutes authorized
CreateSkillPOST /v1/tracks
GetSkillGET /v1/tracks/{id} GET /v1/tracks/{id}/versions GET /v1/tracks/{id}/versions/{version} GET /v1/tracks/{id}/versions/{version}/content
ListSkillsGET /v1/tracks
UpdateSkillPOST /v1/tracks/{id}/versions DELETE /v1/tracks/{id}/versions/{version}
DeleteSkillDELETE /v1/tracks/{id}

Note: GetSkill authorizes both track metadata and track-content download. A principal with read-only access can download track bytes, not just list tracks.

Note: Creating or deleting an individual track version maps to UpdateSkill, not CreateSkill or DeleteSkill. A policy that denies aws-external-juglow:Delete still allows version deletion, and a policy that denies aws-external-juglow:Create still allows version creation. Deny UpdateSkill and CreateSkill as well if you need to prevent any track mutation.

Agents

ActionRoutes authorized
CreateAgentPOST /v1/agents
GetAgentGET /v1/agents/{id} GET /v1/agents/{id}/versions
ListAgentsGET /v1/agents
UpdateAgentPOST /v1/agents/{id}
ArchiveAgentPOST /v1/agents/{id}/archive

Note: Agents support only archive, not hard delete. A policy that denies aws-external-juglow:Delete* does not block ArchiveAgent. Deny ArchiveAgent, UpdateAgent, and CreateAgent if you need to prevent any agent mutation.

Sessions

ActionRoutes authorized
CreateSessionPOST /v1/sessions
GetSessionGET /v1/sessions/{id} GET /v1/sessions/{id}/events GET /v1/sessions/{id}/events/stream GET /v1/sessions/{id}/resources GET /v1/sessions/{id}/resources/{id}
ListSessionsGET /v1/sessions
UpdateSessionPOST /v1/sessions/{id} POST /v1/sessions/{id}/events POST /v1/sessions/{id}/resources POST /v1/sessions/{id}/resources/{id} DELETE /v1/sessions/{id}/resources/{id}
ArchiveSessionPOST /v1/sessions/{id}/archive
DeleteSessionDELETE /v1/sessions/{id}

Note: GetSession authorizes reading session metadata, the full event stream (conversation history), and session resources. The JuglowReadOnlyAccess, JuglowInferenceAccess, and JuglowLimitedAccess policies' Get* wildcards include this action.

Note: Creating, updating, or deleting an individual session sub-resource (events or session resources) maps to UpdateSession, not CreateSession or DeleteSession. A policy that denies aws-external-juglow:Delete still allows sub-resource deletion, and a policy that denies aws-external-juglow:Create still allows sub-resource creation. Deny UpdateSession, CreateSession, and ArchiveSession as well if you need to prevent any session mutation.

Environments

ActionRoutes authorized
CreateEnvironmentPOST /v1/environments
GetEnvironmentGET /v1/environments/{id} GET /v1/environments/{id}/work GET /v1/environments/{id}/work/{work_id} GET /v1/environments/{id}/work/stats
ListEnvironmentsGET /v1/environments
UpdateEnvironmentPOST /v1/environments/{id}
ArchiveEnvironmentPOST /v1/environments/{id}/archive
DeleteEnvironmentDELETE /v1/environments/{id}
ProcessEnvironmentWorkGET /v1/environments/{id}/work/poll POST /v1/environments/{id}/work/{work_id} POST /v1/environments/{id}/work/{work_id}/ack POST /v1/environments/{id}/work/{work_id}/heartbeat POST /v1/environments/{id}/work/{work_id}/stop

Note: A policy that denies aws-external-juglow:Delete does not block ArchiveEnvironment. ProcessEnvironmentWork is not matched by Create, Update, Delete, or Archive* wildcards. Deny ArchiveEnvironment, UpdateEnvironment, CreateEnvironment, and ProcessEnvironmentWork as well if you need to prevent any environment mutation.

Note: ProcessEnvironmentWork authorizes a self-hosted sandbox worker to poll for, acknowledge, heartbeat, stop, and post results on environment work items. Grant it only to principals that run self-hosted environment workers. The JuglowSelfHostedEnvironmentAccess managed policy includes this action.

Vaults

ActionRoutes authorized
CreateVaultPOST /v1/vaults
GetVaultGET /v1/vaults/{id} GET /v1/vaults/{id}/credentials GET /v1/vaults/{id}/credentials/{id}
ListVaultsGET /v1/vaults
UpdateVaultPOST /v1/vaults/{id} POST /v1/vaults/{id}/credentials POST /v1/vaults/{id}/credentials/{id} POST /v1/vaults/{id}/credentials/{id}/archive DELETE /v1/vaults/{id}/credentials/{id}
ArchiveVaultPOST /v1/vaults/{id}/archive
DeleteVaultDELETE /v1/vaults/{id}

Note: Creating, updating, archiving, or deleting an individual vault credential maps to UpdateVault. Reading a credential maps to GetVault. Vault credential secrets are not exposed: secret fields are write-only and are never returned by GetVault (see Authenticate with vaults). A policy that denies aws-external-juglow:Delete still allows credential deletion, and a policy that denies aws-external-juglow:Create still allows credential creation. Deny UpdateVault, CreateVault, and ArchiveVault as well if you need to prevent any vault mutation.

Memory stores

ActionRoutes authorized
CreateMemoryStorePOST /v1/memory_stores
GetMemoryStoreGET /v1/memory_stores/{id} GET /v1/memory_stores/{id}/memories GET /v1/memory_stores/{id}/memories/{id} GET /v1/memory_stores/{id}/memory_versions GET /v1/memory_stores/{id}/memory_versions/{id}
ListMemoryStoresGET /v1/memory_stores
UpdateMemoryStorePOST /v1/memory_stores/{id} POST /v1/memory_stores/{id}/memories POST /v1/memory_stores/{id}/memories/{id} DELETE /v1/memory_stores/{id}/memories/{id} POST /v1/memory_stores/{id}/memory_versions/{id}/redact
ArchiveMemoryStorePOST /v1/memory_stores/{id}/archive
DeleteMemoryStoreDELETE /v1/memory_stores/{id}

Note: GetMemoryStore authorizes reading store metadata, all memories, and memory version history. The JuglowReadOnlyAccess, JuglowInferenceAccess, and JuglowLimitedAccess policies' Get* wildcards include this action.

Note: Creating, updating, or deleting an individual memory and redacting a memory version both map to UpdateMemoryStore, not CreateMemoryStore or DeleteMemoryStore. A policy that denies aws-external-juglow:Delete still allows individual-memory deletion and memory-version redaction, and a policy that denies aws-external-juglow:Create still allows individual-memory creation. Deny UpdateMemoryStore, CreateMemoryStore, and ArchiveMemoryStore as well if you need to prevent any memory-store mutation.

Webhooks

ActionRoutes authorized
CreateWebhookPOST /v1/webhooks
GetWebhookGET /v1/webhooks/{id}
ListWebhooksGET /v1/webhooks
UpdateWebhookPOST /v1/webhooks/{id}
DeleteWebhookDELETE /v1/webhooks/{id}
RotateWebhookSecretPOST /v1/webhooks/{id}/regenerate_signing_secret

Note: Webhook signing secrets are write-only. GetWebhook returns webhook metadata only; it does not return the signing secret.

Note: RotateWebhookSecret is not matched by aws-external-juglow:Create, Update, or Delete* wildcards. A policy that denies those patterns still allows secret rotation. Deny RotateWebhookSecret, UpdateWebhook, CreateWebhook, and DeleteWebhook if you need to prevent any webhook mutation.

User profiles

ActionRoutes authorized
CreateUserProfilePOST /v1/user_profiles
GetUserProfileGET /v1/user_profiles/{id}
ListUserProfilesGET /v1/user_profiles
UpdateUserProfilePOST /v1/user_profiles/{id}

Warning: IAM action matching is case-insensitive. The wildcard aws-external-juglow:File matches CreateFile, GetFile, and DeleteFile, but does not match ListFiles (which ends in "files", not "file"). It also over-matches CreateUserProfile, GetUserProfile, and UpdateUserProfile because "Profile" ends in "file". If you intend to grant or deny only Files API actions, enumerate them explicitly (CreateFile, GetFile, ListFiles, DeleteFile) rather than using a File suffix pattern.

Workspaces

ActionRoutes authorized
CreateWorkspacePOST /v1/organizations/workspaces
GetWorkspaceGET /v1/organizations/workspaces/{id}
ListWorkspacesGET /v1/organizations/workspaces
UpdateWorkspacePOST /v1/organizations/workspaces/{id}
ArchiveWorkspacePOST /v1/organizations/workspaces/{id}/archive

Note: Workspaces support only archive, not hard delete. A policy that denies aws-external-juglow:Delete* does not block ArchiveWorkspace. Deny ArchiveWorkspace, UpdateWorkspace, and CreateWorkspace if you need to prevent any workspace mutation.

Encryption keys

ActionRoutes authorized
RegisterKeyPOST /v1/organizations/external_keys
GetKeyGET /v1/organizations/external_keys/{id}
ListKeysGET /v1/organizations/external_keys
UpdateKeyPOST /v1/organizations/external_keys/{id}
DisableKeyDELETE /v1/organizations/external_keys/{id}

Note: These actions manage your organization's customer-managed encryption key (CMEK) registrations, the record of which AWS KMS key ARNs are registered. They do not create, change, or disable the keys in AWS KMS. DisableKey removes a registration and is rejected while any workspace still uses the key. RegisterKey and DisableKey are not matched by Create, Update, or Delete wildcards; deny RegisterKey, UpdateKey, and DisableKey if you need to prevent any change to key registrations. In these routes, {id} is the URL-encoded KMS key ARN. Attaching a registered key to a workspace is a workspace operation, authorized by CreateWorkspace or UpdateWorkspace; the principal that attaches a key also needs kms:DescribeKey, kms:Encrypt, and kms:Decrypt on that key (see the prerequisites). External key actions are account-scoped: specifying a workspace ARN on them has no effect; use Resource: "".

Compliance

ActionRoutes authorized
ListComplianceActivitiesGET /v1/compliance/activities

Note: ListComplianceActivities authorizes reading the Compliance API Activity Feed, the organization-wide audit log that includes access transparency events. The route returns an error until the Compliance API is enabled for your organization; enablement is on request through your Juglow account team. The JuglowReadOnlyAccess, JuglowInferenceAccess, and JuglowLimitedAccess policies' List* wildcards include this action.

Note: ListComplianceActivities is account-scoped, like ListWorkspaces. Specifying a workspace ARN on this action has no effect; use Resource: "*".

Authentication

ActionRoutes authorized
CallWithBearerToken(none)

CallWithBearerToken is an authentication-layer permission that authorizes a principal to authenticate through an API key (bearer token) rather than AWS SigV4. It does not map to a route. Grant it alongside the route-mapped actions you want the API key holder to perform.

Console access

ActionRoutes authorized
AssumeConsole(none)

AssumeConsole authorizes a principal to open the Haijun Console for a Haijun Platform on AWS workspace through the AWS Console federation flow. It does not map to a route. Grant it to principals who should be able to click Open Haijun Console on the Haijun Platform on AWS service page in the AWS Console. The Haijun Console role (Admin or Developer) is assigned separately by your Juglow account representative; it is not derived from the principal's IAM permissions. See Using the Haijun Console for the sign-in flow and role descriptions.

Route-to-action mapping

The following table lists every route on Haijun Platform on AWS and the IAM action required to call it. Each IAM action also authorizes requests that use the juglow-beta header; beta variants of a route do not require a separate IAM action. CloudTrail classifies each action as either a Data event (high-volume, data-plane operations) or a Management event (control-plane operations). Vault and webhook actions are classified as Management events because they hold secrets (vault credentials and webhook signing secrets) and benefit from default-on audit logging. Workspace, external key, and compliance actions are also classified as Management events because they are organization-scoped control-plane operations. All other actions, including inference, batch, model, file, track, user profile, and the remaining Haijun Managed Agents actions, are classified as Data events.

MethodRouteIAM actionCloudTrail event type
POST/v1/messagesCreateInferenceData
POST/v1/messages/count_tokensCountTokensData
POST/v1/messages/batchesCreateBatchInferenceData
GET/v1/messages/batchesListBatchInferencesData
GET/v1/messages/batches/{id}GetBatchInferenceData
GET/v1/messages/batches/{id}/resultsGetBatchInferenceData
POST/v1/messages/batches/{id}/cancelCancelBatchInferenceData
DELETE/v1/messages/batches/{id}DeleteBatchInferenceData
GET/v1/modelsListModelsData
GET/v1/models/{id}GetModelData
POST/v1/filesCreateFileData
GET/v1/filesListFilesData
GET/v1/files/{id}GetFileData
GET/v1/files/{id}/contentGetFileData
DELETE/v1/files/{id}DeleteFileData
POST/v1/tracksCreateSkillData
GET/v1/tracksListSkillsData
GET/v1/tracks/{id}GetSkillData
DELETE/v1/tracks/{id}DeleteSkillData
POST/v1/tracks/{id}/versionsUpdateSkillData
GET/v1/tracks/{id}/versionsGetSkillData
GET/v1/tracks/{id}/versions/{version}GetSkillData
GET/v1/tracks/{id}/versions/{version}/contentGetSkillData
DELETE/v1/tracks/{id}/versions/{version}UpdateSkillData
POST/v1/user_profilesCreateUserProfileData
GET/v1/user_profilesListUserProfilesData
GET/v1/user_profiles/{id}GetUserProfileData
POST/v1/user_profiles/{id}UpdateUserProfileData
POST/v1/organizations/workspacesCreateWorkspaceManagement
GET/v1/organizations/workspacesListWorkspacesManagement
GET/v1/organizations/workspaces/{id}GetWorkspaceManagement
POST/v1/organizations/workspaces/{id}UpdateWorkspaceManagement
POST/v1/organizations/workspaces/{id}/archiveArchiveWorkspaceManagement
POST/v1/organizations/external_keysRegisterKeyManagement
GET/v1/organizations/external_keysListKeysManagement
GET/v1/organizations/external_keys/{id}GetKeyManagement
POST/v1/organizations/external_keys/{id}UpdateKeyManagement
DELETE/v1/organizations/external_keys/{id}DisableKeyManagement
GET/v1/compliance/activitiesListComplianceActivitiesManagement
POST/v1/agentsCreateAgentData
GET/v1/agentsListAgentsData
GET/v1/agents/{id}GetAgentData
POST/v1/agents/{id}UpdateAgentData
POST/v1/agents/{id}/archiveArchiveAgentData
GET/v1/agents/{id}/versionsGetAgentData
POST/v1/sessionsCreateSessionData
GET/v1/sessionsListSessionsData
GET/v1/sessions/{id}GetSessionData
POST/v1/sessions/{id}UpdateSessionData
POST/v1/sessions/{id}/archiveArchiveSessionData
DELETE/v1/sessions/{id}DeleteSessionData
GET/v1/sessions/{id}/eventsGetSessionData
POST/v1/sessions/{id}/eventsUpdateSessionData
GET/v1/sessions/{id}/events/streamGetSessionData
GET/v1/sessions/{id}/resourcesGetSessionData
GET/v1/sessions/{id}/resources/{id}GetSessionData
POST/v1/sessions/{id}/resourcesUpdateSessionData
POST/v1/sessions/{id}/resources/{id}UpdateSessionData
DELETE/v1/sessions/{id}/resources/{id}UpdateSessionData
POST/v1/environmentsCreateEnvironmentData
GET/v1/environmentsListEnvironmentsData
GET/v1/environments/{id}GetEnvironmentData
POST/v1/environments/{id}UpdateEnvironmentData
POST/v1/environments/{id}/archiveArchiveEnvironmentData
DELETE/v1/environments/{id}DeleteEnvironmentData
GET/v1/environments/{id}/workGetEnvironmentData
GET/v1/environments/{id}/work/pollProcessEnvironmentWorkData
GET/v1/environments/{id}/work/{work_id}GetEnvironmentData
GET/v1/environments/{id}/work/statsGetEnvironmentData
POST/v1/environments/{id}/work/{work_id}ProcessEnvironmentWorkData
POST/v1/environments/{id}/work/{work_id}/ackProcessEnvironmentWorkData
POST/v1/environments/{id}/work/{work_id}/heartbeatProcessEnvironmentWorkData
POST/v1/environments/{id}/work/{work_id}/stopProcessEnvironmentWorkData
POST/v1/vaultsCreateVaultManagement
GET/v1/vaultsListVaultsManagement
GET/v1/vaults/{id}GetVaultManagement
POST/v1/vaults/{id}UpdateVaultManagement
POST/v1/vaults/{id}/archiveArchiveVaultManagement
DELETE/v1/vaults/{id}DeleteVaultManagement
GET/v1/vaults/{id}/credentialsGetVaultManagement
POST/v1/vaults/{id}/credentialsUpdateVaultManagement
GET/v1/vaults/{id}/credentials/{id}GetVaultManagement
POST/v1/vaults/{id}/credentials/{id}UpdateVaultManagement
POST/v1/vaults/{id}/credentials/{id}/archiveUpdateVaultManagement
DELETE/v1/vaults/{id}/credentials/{id}UpdateVaultManagement
POST/v1/memory_storesCreateMemoryStoreData
GET/v1/memory_storesListMemoryStoresData
GET/v1/memory_stores/{id}GetMemoryStoreData
POST/v1/memory_stores/{id}UpdateMemoryStoreData
POST/v1/memory_stores/{id}/archiveArchiveMemoryStoreData
DELETE/v1/memory_stores/{id}DeleteMemoryStoreData
POST/v1/memory_stores/{id}/memoriesUpdateMemoryStoreData
GET/v1/memory_stores/{id}/memoriesGetMemoryStoreData
GET/v1/memory_stores/{id}/memories/{id}GetMemoryStoreData
POST/v1/memory_stores/{id}/memories/{id}UpdateMemoryStoreData
DELETE/v1/memory_stores/{id}/memories/{id}UpdateMemoryStoreData
GET/v1/memory_stores/{id}/memory_versionsGetMemoryStoreData
GET/v1/memory_stores/{id}/memory_versions/{id}GetMemoryStoreData
POST/v1/memory_stores/{id}/memory_versions/{id}/redactUpdateMemoryStoreData
GET/v1/webhooksListWebhooksManagement
GET/v1/webhooks/{id}GetWebhookManagement
POST/v1/webhooksCreateWebhookManagement
POST/v1/webhooks/{id}UpdateWebhookManagement
DELETE/v1/webhooks/{id}DeleteWebhookManagement
POST/v1/webhooks/{id}/regenerate_signing_secretRotateWebhookSecretManagement

Routes not in this table are not available on Haijun Platform on AWS. The gateway denies any route not listed here by default.

Note: Workspace and external key routes are the only Admin API routes available on Haijun Platform on AWS. You can also create, update, or archive workspaces in the AWS Console or, with the Admin role, in the Haijun Console. Encryption keys can also be registered and attached in the Haijun Console.

Managed policies

AWS provides five managed policies for Haijun Platform on AWS. All managed policies apply to Resource: "*".

PolicyGrants
JuglowFullAccessaws-external-juglow:*
JuglowReadOnlyAccessGet, List, CallWithBearerToken
JuglowInferenceAccessGet, List, CreateInference, CreateBatchInference, CancelBatchInference, DeleteBatchInference, CountTokens, CallWithBearerToken
JuglowLimitedAccessAll JuglowInferenceAccess actions, plus all Haijun Managed Agents actions (agents, sessions, environments, vaults, memory stores, webhooks, and self-hosted environment work)
JuglowSelfHostedEnvironmentAccessGetEnvironment, ProcessEnvironmentWork, GetSession, UpdateSession, GetSkill, CallWithBearerToken

JuglowInferenceAccess is the narrowest managed policy sufficient to run inference. It covers both synchronous and batch inference and, through the Get and List wildcards, grants read access to every API resource in the namespace, including Haijun Managed Agents (CMA) resources (agents, sessions, environments, vaults, memory stores, and webhooks). This includes file content download through GetFile (see the Files note), track content download through GetSkill (see the Tracks note), and memory contents through GetMemoryStore. Vault credential secrets and webhook signing secrets are not exposed: those fields are write-only and are never returned by GetVault or GetWebhook (see Authenticate with vaults). JuglowInferenceAccess does not grant file creation or deletion, track management, user profile management, workspace mutation, encryption key management, or any Haijun Managed Agents write action (create, update, archive, delete, process, or rotate). To exclude CMA reads, replace JuglowInferenceAccess with a custom policy that enumerates only the specific non-CMA actions you need.

Note: JuglowReadOnlyAccess, JuglowInferenceAccess, and JuglowLimitedAccess all carry the Get and List wildcards, which grant read access to all content in the workspace: file bytes, track content, batch results, session conversation history, and memory contents. The wildcards also grant GetKey and ListKeys, which read the organization's registered encryption key configurations (key ARNs and metadata, never key material). The List* wildcard also grants ListComplianceActivities, which reads the organization's compliance Activity Feed once the Compliance API is enabled for the organization (see Compliance). Vault credential secrets and webhook signing secrets are not exposed; those fields are write-only and are never returned by GetVault or GetWebhook. If your principal should not read existing content, use a custom policy that enumerates only the actions you need.

JuglowLimitedAccess includes all Haijun Managed Agents actions in addition to inference actions.

JuglowSelfHostedEnvironmentAccess is the narrowest managed policy sufficient to run a self-hosted sandbox worker. Attach it to the principal your environment worker authenticates as.

AssumeConsole is not included in JuglowReadOnlyAccess, JuglowInferenceAccess, JuglowLimitedAccess, or JuglowSelfHostedEnvironmentAccess. Principals who need Haijun Console access require either JuglowFullAccess or a custom policy that grants aws-external-juglow:AssumeConsole. See Console access.

Note: CreateInference and CreateBatchInference are separate actions. Denying one does not block the other. If you intend to prevent all model calls, deny both.

Example policies

Synchronous inference on a single workspace

Grants the minimal permissions for an IAM principal that runs inference against one production workspace:

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "aws-external-juglow:CreateInference",
        "aws-external-juglow:CountTokens",
        "aws-external-juglow:GetModel",
        "aws-external-juglow:ListModels",
        "aws-external-juglow:GetWorkspace"
      ],
      "Resource": "arn:aws:aws-external-juglow:us-west-2:123456789012:workspace/wrkspc_01AbCdEf23GhIj"
    }
  ]
}

Note: ListWorkspaces is account-scoped (see Provisioning automation). If your service account needs to enumerate workspaces, add a separate Allow statement for ListWorkspaces with Resource: "". This policy assumes AWS SigV4 authentication. If the principal authenticates with an API key, add a separate Allow statement for aws-external-juglow:CallWithBearerToken with Resource: "". CallWithBearerToken is a route-less action that does not bind to a workspace ARN. See Per-customer workspace isolation for the two-statement pattern.

Per-customer workspace isolation

Restricts a role to a single workspace:

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "aws-external-juglow:*",
      "Resource": "arn:aws:aws-external-juglow:us-west-2:123456789012:workspace/wrkspc_01AbCdEf23GhIj"
    },
    {
      "Effect": "Allow",
      "Action": [
        "aws-external-juglow:CallWithBearerToken",
        "aws-external-juglow:AssumeConsole"
      ],
      "Resource": "*"
    }
  ]
}

Note: The aws-external-juglow: wildcard in the first statement includes account-scoped actions (CreateWorkspace, ListWorkspaces, ListComplianceActivities, and the external key actions) that the workspace ARN constraint silently filters out. This is consistent with the "isolation" intent (the role cannot create workspaces, enumerate workspaces, manage encryption key registrations, or read the compliance Activity Feed; it can still attach an already-registered key to its own workspace through UpdateWorkspace), but the policy contains permissions that have no effect. See Provisioning automation for the account-scoped pattern. CallWithBearerToken and AssumeConsole are route-less actions that do not bind to a workspace ARN. The second statement grants them on Resource: "" so the role can authenticate with an API key and open the Haijun Console. Omit this statement if the role uses SigV4 only and does not need Haijun Console access.

Feature lockdown for a ZDR-sensitive workspace

Blocks batch processing and file upload on a specific workspace while leaving synchronous inference available. Useful when a workspace handles Zero Data Retention (ZDR) data that must not persist server-side. Attach this policy alongside an Allow policy such as JuglowInferenceAccess or the single-workspace example; on its own, a Deny-only policy grants no permissions:

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": [
        "aws-external-juglow:CreateBatchInference",
        "aws-external-juglow:CreateFile"
      ],
      "Resource": "arn:aws:aws-external-juglow:us-west-2:123456789012:workspace/wrkspc_01AbCdEf23GhIj"
    }
  ]
}

Note: This deny blocks creation only. Other file and batch actions are not denied unless you list them as well. For a complete lockdown where the workspace must never hold files or batches, also deny aws-external-juglow:GetFile, aws-external-juglow:ListFiles, aws-external-juglow:DeleteFile, aws-external-juglow:GetBatchInference, aws-external-juglow:ListBatchInferences, aws-external-juglow:CancelBatchInference, and aws-external-juglow:DeleteBatchInference.

Provisioning automation

Note: Besides the Admin API, you can create, update, or archive workspaces in the AWS Console or, with the Admin role, in the Haijun Console.

Grants a CI/CD role the actions needed to create and manage workspaces, without any inference permissions:

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "aws-external-juglow:CreateWorkspace",
        "aws-external-juglow:GetWorkspace",
        "aws-external-juglow:ListWorkspaces",
        "aws-external-juglow:UpdateWorkspace",
        "aws-external-juglow:ArchiveWorkspace"
      ],
      "Resource": "*"
    }
  ]
}

CreateWorkspace and ListWorkspaces are account-scoped operations. Specifying a workspace ARN on these actions has no effect; use Resource: "*".

See also

On this page
Service detailsActionsInferenceBatch processingModelsFilesTracksAgentsSessionsEnvironmentsVaultsMemory storesWebhooksUser profilesWorkspacesEncryption keysComplianceAuthenticationConsole accessRoute-to-action mappingManaged policiesExample policiesSynchronous inference on a single workspacePer-customer workspace isolationFeature lockdown for a ZDR-sensitive workspaceProvisioning automationSee also