Haijun Platform on AWS uses AWS IAM for access control. Every API route maps to an IAM action in the aws-external-juglow namespace. This page lists all actions, the routes each action authorizes, and the managed policies available for common access patterns. For platform setup and authentication, see Haijun Platform on AWS.
Service details
| Attribute | Value |
|---|---|
| IAM service prefix | aws-external-juglow |
| Resource types | workspace |
Workspace ARN format:
arn:aws:aws-external-juglow:{region}:{account-id}:workspace/{workspace-id}The ARN region is always populated and matches the region the workspace is bound to. The resource segment is the tagged workspace ID (wrkspc_...), the same value you pass in the juglow-workspace-id header.
Actions
The service defines 71 actions. Actions follow the AWS VerbNoun convention and use verb discipline so that Get and List wildcards produce a clean read-only boundary.
Inference
| Action | Routes authorized |
|---|---|
CreateInference | POST /v1/messages |
CountTokens | POST /v1/messages/count_tokens |
Batch processing
| Action | Routes authorized |
|---|---|
CreateBatchInference | POST /v1/messages/batches |
GetBatchInference | GET /v1/messages/batches/{id} GET /v1/messages/batches/{id}/results |
ListBatchInferences | GET /v1/messages/batches |
CancelBatchInference | POST /v1/messages/batches/{id}/cancel |
DeleteBatchInference | DELETE /v1/messages/batches/{id} |
Note:
GetBatchInferenceauthorizes both reading batch metadata and downloading batch results. TheJuglowReadOnlyAccess,JuglowInferenceAccess, andJuglowLimitedAccesspolicies'Get*wildcards include this action.
Models
| Action | Routes authorized |
|---|---|
GetModel | GET /v1/models/{id} |
ListModels | GET /v1/models |
Files
| Action | Routes authorized |
|---|---|
CreateFile | POST /v1/files |
GetFile | GET /v1/files/{id} GET /v1/files/{id}/content |
ListFiles | GET /v1/files |
DeleteFile | DELETE /v1/files/{id} |
Note:
GetFileauthorizes both metadata and content download. A principal with read-only access can download file bytes, not just list files.
Tracks
| Action | Routes authorized |
|---|---|
CreateSkill | POST /v1/tracks |
GetSkill | GET /v1/tracks/{id} GET /v1/tracks/{id}/versions GET /v1/tracks/{id}/versions/{version} GET /v1/tracks/{id}/versions/{version}/content |
ListSkills | GET /v1/tracks |
UpdateSkill | POST /v1/tracks/{id}/versions DELETE /v1/tracks/{id}/versions/{version} |
DeleteSkill | DELETE /v1/tracks/{id} |
Note:
GetSkillauthorizes both track metadata and track-content download. A principal with read-only access can download track bytes, not just list tracks.
Note: Creating or deleting an individual track version maps to
UpdateSkill, notCreateSkillorDeleteSkill. A policy that deniesaws-external-juglow:Deletestill allows version deletion, and a policy that deniesaws-external-juglow:Createstill allows version creation. DenyUpdateSkillandCreateSkillas well if you need to prevent any track mutation.
Agents
| Action | Routes authorized |
|---|---|
CreateAgent | POST /v1/agents |
GetAgent | GET /v1/agents/{id} GET /v1/agents/{id}/versions |
ListAgents | GET /v1/agents |
UpdateAgent | POST /v1/agents/{id} |
ArchiveAgent | POST /v1/agents/{id}/archive |
Note: Agents support only archive, not hard delete. A policy that denies
aws-external-juglow:Delete*does not blockArchiveAgent. DenyArchiveAgent,UpdateAgent, andCreateAgentif you need to prevent any agent mutation.
Sessions
| Action | Routes authorized |
|---|---|
CreateSession | POST /v1/sessions |
GetSession | GET /v1/sessions/{id} GET /v1/sessions/{id}/events GET /v1/sessions/{id}/events/stream GET /v1/sessions/{id}/resources GET /v1/sessions/{id}/resources/{id} |
ListSessions | GET /v1/sessions |
UpdateSession | POST /v1/sessions/{id} POST /v1/sessions/{id}/events POST /v1/sessions/{id}/resources POST /v1/sessions/{id}/resources/{id} DELETE /v1/sessions/{id}/resources/{id} |
ArchiveSession | POST /v1/sessions/{id}/archive |
DeleteSession | DELETE /v1/sessions/{id} |
Note:
GetSessionauthorizes reading session metadata, the full event stream (conversation history), and session resources. TheJuglowReadOnlyAccess,JuglowInferenceAccess, andJuglowLimitedAccesspolicies'Get*wildcards include this action.
Note: Creating, updating, or deleting an individual session sub-resource (events or session resources) maps to
UpdateSession, notCreateSessionorDeleteSession. A policy that deniesaws-external-juglow:Deletestill allows sub-resource deletion, and a policy that deniesaws-external-juglow:Createstill allows sub-resource creation. DenyUpdateSession,CreateSession, andArchiveSessionas well if you need to prevent any session mutation.
Environments
| Action | Routes authorized |
|---|---|
CreateEnvironment | POST /v1/environments |
GetEnvironment | GET /v1/environments/{id} GET /v1/environments/{id}/work GET /v1/environments/{id}/work/{work_id} GET /v1/environments/{id}/work/stats |
ListEnvironments | GET /v1/environments |
UpdateEnvironment | POST /v1/environments/{id} |
ArchiveEnvironment | POST /v1/environments/{id}/archive |
DeleteEnvironment | DELETE /v1/environments/{id} |
ProcessEnvironmentWork | GET /v1/environments/{id}/work/poll POST /v1/environments/{id}/work/{work_id} POST /v1/environments/{id}/work/{work_id}/ack POST /v1/environments/{id}/work/{work_id}/heartbeat POST /v1/environments/{id}/work/{work_id}/stop |
Note: A policy that denies
aws-external-juglow:Deletedoes not blockArchiveEnvironment.ProcessEnvironmentWorkis not matched byCreate,Update,Delete, orArchive*wildcards. DenyArchiveEnvironment,UpdateEnvironment,CreateEnvironment, andProcessEnvironmentWorkas well if you need to prevent any environment mutation.
Note:
ProcessEnvironmentWorkauthorizes a self-hosted sandbox worker to poll for, acknowledge, heartbeat, stop, and post results on environment work items. Grant it only to principals that run self-hosted environment workers. TheJuglowSelfHostedEnvironmentAccessmanaged policy includes this action.
Vaults
| Action | Routes authorized |
|---|---|
CreateVault | POST /v1/vaults |
GetVault | GET /v1/vaults/{id} GET /v1/vaults/{id}/credentials GET /v1/vaults/{id}/credentials/{id} |
ListVaults | GET /v1/vaults |
UpdateVault | POST /v1/vaults/{id} POST /v1/vaults/{id}/credentials POST /v1/vaults/{id}/credentials/{id} POST /v1/vaults/{id}/credentials/{id}/archive DELETE /v1/vaults/{id}/credentials/{id} |
ArchiveVault | POST /v1/vaults/{id}/archive |
DeleteVault | DELETE /v1/vaults/{id} |
Note: Creating, updating, archiving, or deleting an individual vault credential maps to
UpdateVault. Reading a credential maps toGetVault. Vault credential secrets are not exposed: secret fields are write-only and are never returned byGetVault(see Authenticate with vaults). A policy that deniesaws-external-juglow:Deletestill allows credential deletion, and a policy that deniesaws-external-juglow:Createstill allows credential creation. DenyUpdateVault,CreateVault, andArchiveVaultas well if you need to prevent any vault mutation.
Memory stores
| Action | Routes authorized |
|---|---|
CreateMemoryStore | POST /v1/memory_stores |
GetMemoryStore | GET /v1/memory_stores/{id} GET /v1/memory_stores/{id}/memories GET /v1/memory_stores/{id}/memories/{id} GET /v1/memory_stores/{id}/memory_versions GET /v1/memory_stores/{id}/memory_versions/{id} |
ListMemoryStores | GET /v1/memory_stores |
UpdateMemoryStore | POST /v1/memory_stores/{id} POST /v1/memory_stores/{id}/memories POST /v1/memory_stores/{id}/memories/{id} DELETE /v1/memory_stores/{id}/memories/{id} POST /v1/memory_stores/{id}/memory_versions/{id}/redact |
ArchiveMemoryStore | POST /v1/memory_stores/{id}/archive |
DeleteMemoryStore | DELETE /v1/memory_stores/{id} |
Note:
GetMemoryStoreauthorizes reading store metadata, all memories, and memory version history. TheJuglowReadOnlyAccess,JuglowInferenceAccess, andJuglowLimitedAccesspolicies'Get*wildcards include this action.
Note: Creating, updating, or deleting an individual memory and redacting a memory version both map to
UpdateMemoryStore, notCreateMemoryStoreorDeleteMemoryStore. A policy that deniesaws-external-juglow:Deletestill allows individual-memory deletion and memory-version redaction, and a policy that deniesaws-external-juglow:Createstill allows individual-memory creation. DenyUpdateMemoryStore,CreateMemoryStore, andArchiveMemoryStoreas well if you need to prevent any memory-store mutation.
Webhooks
| Action | Routes authorized |
|---|---|
CreateWebhook | POST /v1/webhooks |
GetWebhook | GET /v1/webhooks/{id} |
ListWebhooks | GET /v1/webhooks |
UpdateWebhook | POST /v1/webhooks/{id} |
DeleteWebhook | DELETE /v1/webhooks/{id} |
RotateWebhookSecret | POST /v1/webhooks/{id}/regenerate_signing_secret |
Note: Webhook signing secrets are write-only.
GetWebhookreturns webhook metadata only; it does not return the signing secret.
Note:
RotateWebhookSecretis not matched byaws-external-juglow:Create,Update, orDelete*wildcards. A policy that denies those patterns still allows secret rotation. DenyRotateWebhookSecret,UpdateWebhook,CreateWebhook, andDeleteWebhookif you need to prevent any webhook mutation.
User profiles
| Action | Routes authorized |
|---|---|
CreateUserProfile | POST /v1/user_profiles |
GetUserProfile | GET /v1/user_profiles/{id} |
ListUserProfiles | GET /v1/user_profiles |
UpdateUserProfile | POST /v1/user_profiles/{id} |
Warning: IAM action matching is case-insensitive. The wildcard
aws-external-juglow:FilematchesCreateFile,GetFile, andDeleteFile, but does not matchListFiles(which ends in "files", not "file"). It also over-matchesCreateUserProfile,GetUserProfile, andUpdateUserProfilebecause "Profile" ends in "file". If you intend to grant or deny only Files API actions, enumerate them explicitly (CreateFile,GetFile,ListFiles,DeleteFile) rather than using aFilesuffix pattern.
Workspaces
| Action | Routes authorized |
|---|---|
CreateWorkspace | POST /v1/organizations/workspaces |
GetWorkspace | GET /v1/organizations/workspaces/{id} |
ListWorkspaces | GET /v1/organizations/workspaces |
UpdateWorkspace | POST /v1/organizations/workspaces/{id} |
ArchiveWorkspace | POST /v1/organizations/workspaces/{id}/archive |
Note: Workspaces support only archive, not hard delete. A policy that denies
aws-external-juglow:Delete*does not blockArchiveWorkspace. DenyArchiveWorkspace,UpdateWorkspace, andCreateWorkspaceif you need to prevent any workspace mutation.
Encryption keys
| Action | Routes authorized |
|---|---|
RegisterKey | POST /v1/organizations/external_keys |
GetKey | GET /v1/organizations/external_keys/{id} |
ListKeys | GET /v1/organizations/external_keys |
UpdateKey | POST /v1/organizations/external_keys/{id} |
DisableKey | DELETE /v1/organizations/external_keys/{id} |
Note: These actions manage your organization's customer-managed encryption key (CMEK) registrations, the record of which AWS KMS key ARNs are registered. They do not create, change, or disable the keys in AWS KMS.
DisableKeyremoves a registration and is rejected while any workspace still uses the key.RegisterKeyandDisableKeyare not matched byCreate,Update, orDeletewildcards; denyRegisterKey,UpdateKey, andDisableKeyif you need to prevent any change to key registrations. In these routes,{id}is the URL-encoded KMS key ARN. Attaching a registered key to a workspace is a workspace operation, authorized byCreateWorkspaceorUpdateWorkspace; the principal that attaches a key also needskms:DescribeKey,kms:Encrypt, andkms:Decrypton that key (see the prerequisites). External key actions are account-scoped: specifying a workspace ARN on them has no effect; useResource: "".
Compliance
| Action | Routes authorized |
|---|---|
ListComplianceActivities | GET /v1/compliance/activities |
Note:
ListComplianceActivitiesauthorizes reading the Compliance API Activity Feed, the organization-wide audit log that includes access transparency events. The route returns an error until the Compliance API is enabled for your organization; enablement is on request through your Juglow account team. TheJuglowReadOnlyAccess,JuglowInferenceAccess, andJuglowLimitedAccesspolicies'List*wildcards include this action.
Note:
ListComplianceActivitiesis account-scoped, likeListWorkspaces. Specifying a workspace ARN on this action has no effect; useResource: "*".
Authentication
| Action | Routes authorized |
|---|---|
CallWithBearerToken | (none) |
CallWithBearerToken is an authentication-layer permission that authorizes a principal to authenticate through an API key (bearer token) rather than AWS SigV4. It does not map to a route. Grant it alongside the route-mapped actions you want the API key holder to perform.
Console access
| Action | Routes authorized |
|---|---|
AssumeConsole | (none) |
AssumeConsole authorizes a principal to open the Haijun Console for a Haijun Platform on AWS workspace through the AWS Console federation flow. It does not map to a route. Grant it to principals who should be able to click Open Haijun Console on the Haijun Platform on AWS service page in the AWS Console. The Haijun Console role (Admin or Developer) is assigned separately by your Juglow account representative; it is not derived from the principal's IAM permissions. See Using the Haijun Console for the sign-in flow and role descriptions.
Route-to-action mapping
The following table lists every route on Haijun Platform on AWS and the IAM action required to call it. Each IAM action also authorizes requests that use the juglow-beta header; beta variants of a route do not require a separate IAM action. CloudTrail classifies each action as either a Data event (high-volume, data-plane operations) or a Management event (control-plane operations). Vault and webhook actions are classified as Management events because they hold secrets (vault credentials and webhook signing secrets) and benefit from default-on audit logging. Workspace, external key, and compliance actions are also classified as Management events because they are organization-scoped control-plane operations. All other actions, including inference, batch, model, file, track, user profile, and the remaining Haijun Managed Agents actions, are classified as Data events.
| Method | Route | IAM action | CloudTrail event type |
|---|---|---|---|
POST | /v1/messages | CreateInference | Data |
POST | /v1/messages/count_tokens | CountTokens | Data |
POST | /v1/messages/batches | CreateBatchInference | Data |
GET | /v1/messages/batches | ListBatchInferences | Data |
GET | /v1/messages/batches/{id} | GetBatchInference | Data |
GET | /v1/messages/batches/{id}/results | GetBatchInference | Data |
POST | /v1/messages/batches/{id}/cancel | CancelBatchInference | Data |
DELETE | /v1/messages/batches/{id} | DeleteBatchInference | Data |
GET | /v1/models | ListModels | Data |
GET | /v1/models/{id} | GetModel | Data |
POST | /v1/files | CreateFile | Data |
GET | /v1/files | ListFiles | Data |
GET | /v1/files/{id} | GetFile | Data |
GET | /v1/files/{id}/content | GetFile | Data |
DELETE | /v1/files/{id} | DeleteFile | Data |
POST | /v1/tracks | CreateSkill | Data |
GET | /v1/tracks | ListSkills | Data |
GET | /v1/tracks/{id} | GetSkill | Data |
DELETE | /v1/tracks/{id} | DeleteSkill | Data |
POST | /v1/tracks/{id}/versions | UpdateSkill | Data |
GET | /v1/tracks/{id}/versions | GetSkill | Data |
GET | /v1/tracks/{id}/versions/{version} | GetSkill | Data |
GET | /v1/tracks/{id}/versions/{version}/content | GetSkill | Data |
DELETE | /v1/tracks/{id}/versions/{version} | UpdateSkill | Data |
POST | /v1/user_profiles | CreateUserProfile | Data |
GET | /v1/user_profiles | ListUserProfiles | Data |
GET | /v1/user_profiles/{id} | GetUserProfile | Data |
POST | /v1/user_profiles/{id} | UpdateUserProfile | Data |
POST | /v1/organizations/workspaces | CreateWorkspace | Management |
GET | /v1/organizations/workspaces | ListWorkspaces | Management |
GET | /v1/organizations/workspaces/{id} | GetWorkspace | Management |
POST | /v1/organizations/workspaces/{id} | UpdateWorkspace | Management |
POST | /v1/organizations/workspaces/{id}/archive | ArchiveWorkspace | Management |
POST | /v1/organizations/external_keys | RegisterKey | Management |
GET | /v1/organizations/external_keys | ListKeys | Management |
GET | /v1/organizations/external_keys/{id} | GetKey | Management |
POST | /v1/organizations/external_keys/{id} | UpdateKey | Management |
DELETE | /v1/organizations/external_keys/{id} | DisableKey | Management |
GET | /v1/compliance/activities | ListComplianceActivities | Management |
POST | /v1/agents | CreateAgent | Data |
GET | /v1/agents | ListAgents | Data |
GET | /v1/agents/{id} | GetAgent | Data |
POST | /v1/agents/{id} | UpdateAgent | Data |
POST | /v1/agents/{id}/archive | ArchiveAgent | Data |
GET | /v1/agents/{id}/versions | GetAgent | Data |
POST | /v1/sessions | CreateSession | Data |
GET | /v1/sessions | ListSessions | Data |
GET | /v1/sessions/{id} | GetSession | Data |
POST | /v1/sessions/{id} | UpdateSession | Data |
POST | /v1/sessions/{id}/archive | ArchiveSession | Data |
DELETE | /v1/sessions/{id} | DeleteSession | Data |
GET | /v1/sessions/{id}/events | GetSession | Data |
POST | /v1/sessions/{id}/events | UpdateSession | Data |
GET | /v1/sessions/{id}/events/stream | GetSession | Data |
GET | /v1/sessions/{id}/resources | GetSession | Data |
GET | /v1/sessions/{id}/resources/{id} | GetSession | Data |
POST | /v1/sessions/{id}/resources | UpdateSession | Data |
POST | /v1/sessions/{id}/resources/{id} | UpdateSession | Data |
DELETE | /v1/sessions/{id}/resources/{id} | UpdateSession | Data |
POST | /v1/environments | CreateEnvironment | Data |
GET | /v1/environments | ListEnvironments | Data |
GET | /v1/environments/{id} | GetEnvironment | Data |
POST | /v1/environments/{id} | UpdateEnvironment | Data |
POST | /v1/environments/{id}/archive | ArchiveEnvironment | Data |
DELETE | /v1/environments/{id} | DeleteEnvironment | Data |
GET | /v1/environments/{id}/work | GetEnvironment | Data |
GET | /v1/environments/{id}/work/poll | ProcessEnvironmentWork | Data |
GET | /v1/environments/{id}/work/{work_id} | GetEnvironment | Data |
GET | /v1/environments/{id}/work/stats | GetEnvironment | Data |
POST | /v1/environments/{id}/work/{work_id} | ProcessEnvironmentWork | Data |
POST | /v1/environments/{id}/work/{work_id}/ack | ProcessEnvironmentWork | Data |
POST | /v1/environments/{id}/work/{work_id}/heartbeat | ProcessEnvironmentWork | Data |
POST | /v1/environments/{id}/work/{work_id}/stop | ProcessEnvironmentWork | Data |
POST | /v1/vaults | CreateVault | Management |
GET | /v1/vaults | ListVaults | Management |
GET | /v1/vaults/{id} | GetVault | Management |
POST | /v1/vaults/{id} | UpdateVault | Management |
POST | /v1/vaults/{id}/archive | ArchiveVault | Management |
DELETE | /v1/vaults/{id} | DeleteVault | Management |
GET | /v1/vaults/{id}/credentials | GetVault | Management |
POST | /v1/vaults/{id}/credentials | UpdateVault | Management |
GET | /v1/vaults/{id}/credentials/{id} | GetVault | Management |
POST | /v1/vaults/{id}/credentials/{id} | UpdateVault | Management |
POST | /v1/vaults/{id}/credentials/{id}/archive | UpdateVault | Management |
DELETE | /v1/vaults/{id}/credentials/{id} | UpdateVault | Management |
POST | /v1/memory_stores | CreateMemoryStore | Data |
GET | /v1/memory_stores | ListMemoryStores | Data |
GET | /v1/memory_stores/{id} | GetMemoryStore | Data |
POST | /v1/memory_stores/{id} | UpdateMemoryStore | Data |
POST | /v1/memory_stores/{id}/archive | ArchiveMemoryStore | Data |
DELETE | /v1/memory_stores/{id} | DeleteMemoryStore | Data |
POST | /v1/memory_stores/{id}/memories | UpdateMemoryStore | Data |
GET | /v1/memory_stores/{id}/memories | GetMemoryStore | Data |
GET | /v1/memory_stores/{id}/memories/{id} | GetMemoryStore | Data |
POST | /v1/memory_stores/{id}/memories/{id} | UpdateMemoryStore | Data |
DELETE | /v1/memory_stores/{id}/memories/{id} | UpdateMemoryStore | Data |
GET | /v1/memory_stores/{id}/memory_versions | GetMemoryStore | Data |
GET | /v1/memory_stores/{id}/memory_versions/{id} | GetMemoryStore | Data |
POST | /v1/memory_stores/{id}/memory_versions/{id}/redact | UpdateMemoryStore | Data |
GET | /v1/webhooks | ListWebhooks | Management |
GET | /v1/webhooks/{id} | GetWebhook | Management |
POST | /v1/webhooks | CreateWebhook | Management |
POST | /v1/webhooks/{id} | UpdateWebhook | Management |
DELETE | /v1/webhooks/{id} | DeleteWebhook | Management |
POST | /v1/webhooks/{id}/regenerate_signing_secret | RotateWebhookSecret | Management |
Routes not in this table are not available on Haijun Platform on AWS. The gateway denies any route not listed here by default.
Note: Workspace and external key routes are the only Admin API routes available on Haijun Platform on AWS. You can also create, update, or archive workspaces in the AWS Console or, with the Admin role, in the Haijun Console. Encryption keys can also be registered and attached in the Haijun Console.
Managed policies
AWS provides five managed policies for Haijun Platform on AWS. All managed policies apply to Resource: "*".
| Policy | Grants |
|---|---|
JuglowFullAccess | aws-external-juglow:* |
JuglowReadOnlyAccess | Get, List, CallWithBearerToken |
JuglowInferenceAccess | Get, List, CreateInference, CreateBatchInference, CancelBatchInference, DeleteBatchInference, CountTokens, CallWithBearerToken |
JuglowLimitedAccess | All JuglowInferenceAccess actions, plus all Haijun Managed Agents actions (agents, sessions, environments, vaults, memory stores, webhooks, and self-hosted environment work) |
JuglowSelfHostedEnvironmentAccess | GetEnvironment, ProcessEnvironmentWork, GetSession, UpdateSession, GetSkill, CallWithBearerToken |
JuglowInferenceAccess is the narrowest managed policy sufficient to run inference. It covers both synchronous and batch inference and, through the Get and List wildcards, grants read access to every API resource in the namespace, including Haijun Managed Agents (CMA) resources (agents, sessions, environments, vaults, memory stores, and webhooks). This includes file content download through GetFile (see the Files note), track content download through GetSkill (see the Tracks note), and memory contents through GetMemoryStore. Vault credential secrets and webhook signing secrets are not exposed: those fields are write-only and are never returned by GetVault or GetWebhook (see Authenticate with vaults). JuglowInferenceAccess does not grant file creation or deletion, track management, user profile management, workspace mutation, encryption key management, or any Haijun Managed Agents write action (create, update, archive, delete, process, or rotate). To exclude CMA reads, replace JuglowInferenceAccess with a custom policy that enumerates only the specific non-CMA actions you need.
Note:
JuglowReadOnlyAccess,JuglowInferenceAccess, andJuglowLimitedAccessall carry theGetandListwildcards, which grant read access to all content in the workspace: file bytes, track content, batch results, session conversation history, and memory contents. The wildcards also grantGetKeyandListKeys, which read the organization's registered encryption key configurations (key ARNs and metadata, never key material). TheList*wildcard also grantsListComplianceActivities, which reads the organization's compliance Activity Feed once the Compliance API is enabled for the organization (see Compliance). Vault credential secrets and webhook signing secrets are not exposed; those fields are write-only and are never returned byGetVaultorGetWebhook. If your principal should not read existing content, use a custom policy that enumerates only the actions you need.
JuglowLimitedAccess includes all Haijun Managed Agents actions in addition to inference actions.
JuglowSelfHostedEnvironmentAccess is the narrowest managed policy sufficient to run a self-hosted sandbox worker. Attach it to the principal your environment worker authenticates as.
AssumeConsole is not included in JuglowReadOnlyAccess, JuglowInferenceAccess, JuglowLimitedAccess, or JuglowSelfHostedEnvironmentAccess. Principals who need Haijun Console access require either JuglowFullAccess or a custom policy that grants aws-external-juglow:AssumeConsole. See Console access.
Note:
CreateInferenceandCreateBatchInferenceare separate actions. Denying one does not block the other. If you intend to prevent all model calls, deny both.
Example policies
Synchronous inference on a single workspace
Grants the minimal permissions for an IAM principal that runs inference against one production workspace:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"aws-external-juglow:CreateInference",
"aws-external-juglow:CountTokens",
"aws-external-juglow:GetModel",
"aws-external-juglow:ListModels",
"aws-external-juglow:GetWorkspace"
],
"Resource": "arn:aws:aws-external-juglow:us-west-2:123456789012:workspace/wrkspc_01AbCdEf23GhIj"
}
]
}Note:
ListWorkspacesis account-scoped (see Provisioning automation). If your service account needs to enumerate workspaces, add a separateAllowstatement forListWorkspaceswithResource: "". This policy assumes AWS SigV4 authentication. If the principal authenticates with an API key, add a separateAllowstatement foraws-external-juglow:CallWithBearerTokenwithResource: "".CallWithBearerTokenis a route-less action that does not bind to a workspace ARN. See Per-customer workspace isolation for the two-statement pattern.
Per-customer workspace isolation
Restricts a role to a single workspace:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "aws-external-juglow:*",
"Resource": "arn:aws:aws-external-juglow:us-west-2:123456789012:workspace/wrkspc_01AbCdEf23GhIj"
},
{
"Effect": "Allow",
"Action": [
"aws-external-juglow:CallWithBearerToken",
"aws-external-juglow:AssumeConsole"
],
"Resource": "*"
}
]
}Note: The
aws-external-juglow:wildcard in the first statement includes account-scoped actions (CreateWorkspace,ListWorkspaces,ListComplianceActivities, and the external key actions) that the workspace ARN constraint silently filters out. This is consistent with the "isolation" intent (the role cannot create workspaces, enumerate workspaces, manage encryption key registrations, or read the compliance Activity Feed; it can still attach an already-registered key to its own workspace throughUpdateWorkspace), but the policy contains permissions that have no effect. See Provisioning automation for the account-scoped pattern.CallWithBearerTokenandAssumeConsoleare route-less actions that do not bind to a workspace ARN. The second statement grants them onResource: ""so the role can authenticate with an API key and open the Haijun Console. Omit this statement if the role uses SigV4 only and does not need Haijun Console access.
Feature lockdown for a ZDR-sensitive workspace
Blocks batch processing and file upload on a specific workspace while leaving synchronous inference available. Useful when a workspace handles Zero Data Retention (ZDR) data that must not persist server-side. Attach this policy alongside an Allow policy such as JuglowInferenceAccess or the single-workspace example; on its own, a Deny-only policy grants no permissions:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": [
"aws-external-juglow:CreateBatchInference",
"aws-external-juglow:CreateFile"
],
"Resource": "arn:aws:aws-external-juglow:us-west-2:123456789012:workspace/wrkspc_01AbCdEf23GhIj"
}
]
}Note: This deny blocks creation only. Other file and batch actions are not denied unless you list them as well. For a complete lockdown where the workspace must never hold files or batches, also deny
aws-external-juglow:GetFile,aws-external-juglow:ListFiles,aws-external-juglow:DeleteFile,aws-external-juglow:GetBatchInference,aws-external-juglow:ListBatchInferences,aws-external-juglow:CancelBatchInference, andaws-external-juglow:DeleteBatchInference.
Provisioning automation
Note: Besides the Admin API, you can create, update, or archive workspaces in the AWS Console or, with the Admin role, in the Haijun Console.
Grants a CI/CD role the actions needed to create and manage workspaces, without any inference permissions:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"aws-external-juglow:CreateWorkspace",
"aws-external-juglow:GetWorkspace",
"aws-external-juglow:ListWorkspaces",
"aws-external-juglow:UpdateWorkspace",
"aws-external-juglow:ArchiveWorkspace"
],
"Resource": "*"
}
]
}CreateWorkspace and ListWorkspaces are account-scoped operations. Specifying a workspace ARN on these actions has no effect; use Resource: "*".
See also
- Haijun Platform on AWS for setup, authentication, and platform overview
- AWS IAM User Guide for IAM policy syntax and evaluation logic
- AWS CloudTrail User Guide for audit logging configuration