IAM Policy to restrict deployment to particular API stage

Using this policy a user access can be restricted to deploy API only to particular stage(s)

The IAM policy allows deployment action only on the dev stage and not on other stages like prod.

Limit stage deployment to authorized user

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": "apigateway:POST",
            "Resource": [
                "arn:aws:apigateway:us-east-1::/restapis/<api-id>/deployments"
            ],
            "Condition": {
                "ForAnyValue:StringEquals": {
                    "apigateway:Request/StageName": "dev"
                }
            }
        }
    ]
}

                                


Created by:

Abhishek Agawane

Abhishek Agawane

Abhishek is a Security Consultant at Amazon Web Services with more than 9 years of industry experience. He helps organizations architect resilient, secure, and efficient cloud environments, guiding them through complex challenges and large-scale infrastructure transformations. He has helped numerous organizations enhance their cloud operations through targeted optimizations, robust architectures, and best-practice implementations.