service: the ECS service.resource_pattern: the resource name or pattern.actions: the operations allowed for that resource.
Services
Actions
Endpoint mapping
Resource patterns
Collection endpoints use* as their permission resource. Named endpoints use the route’s resource identifier.
Example:
* for account-wide access to the selected service and actions.