|
5 | 5 | "Sid": "Statement1", |
6 | 6 | "Effect": "Allow", |
7 | 7 | "Action": [ |
8 | | - "acm:AddTagsToCertificate", |
9 | 8 | "acm:DeleteCertificate", |
10 | | - "acm:DescribeCertificate", |
11 | | - "acm:ListTagsForCertificate", |
12 | 9 | "acm:RequestCertificate", |
13 | | - "cloudformation:DescribeStacks", |
14 | | - "cloudformation:GetTemplateSummary", |
15 | | - "cloudformation:ListStackInstances", |
16 | 10 | "codedeploy:CreateApplication", |
17 | 11 | "codedeploy:CreateDeployment", |
18 | 12 | "codedeploy:CreateDeploymentGroup", |
19 | 13 | "codedeploy:DeleteApplication", |
20 | 14 | "codedeploy:DeleteDeploymentGroup", |
21 | | - "codedeploy:GetApplication", |
22 | | - "codedeploy:GetApplicationRevision", |
23 | | - "codedeploy:GetDeployment", |
24 | | - "codedeploy:GetDeploymentConfig", |
25 | | - "codedeploy:GetDeploymentGroup", |
26 | | - "codedeploy:ListDeployments", |
27 | | - "codedeploy:ListTagsForResource", |
28 | 15 | "codedeploy:RegisterApplicationRevision", |
29 | 16 | "codedeploy:UpdateDeploymentGroup", |
30 | | - "codedeploy:TagResource", |
31 | | - "codedeploy:UntagResource", |
32 | 17 | "codedeploy:UpdateApplication", |
33 | | - "dynamodb:GetItem", |
34 | 18 | "dynamodb:PutItem", |
35 | 19 | "dynamodb:DeleteItem", |
36 | 20 | "ec2:AllocateAddress", |
|
45 | 29 | "ec2:CreateRouteTable", |
46 | 30 | "ec2:CreateSecurityGroup", |
47 | 31 | "ec2:CreateSubnet", |
48 | | - "ec2:CreateTags", |
49 | 32 | "ec2:CreateVpc", |
50 | 33 | "ec2:DeleteFlowLogs", |
51 | 34 | "ec2:DeleteInternetGateway", |
|
55 | 38 | "ec2:DeleteSecurityGroup", |
56 | 39 | "ec2:DeleteSubnet", |
57 | 40 | "ec2:DeleteVpc", |
58 | | - "ec2:DescribeAccountAttributes", |
59 | | - "ec2:DescribeAddresses", |
60 | | - "ec2:DescribeAddressesAttribute", |
61 | | - "ec2:DescribeAvailabilityZones", |
62 | | - "ec2:DescribeFlowLogs", |
63 | | - "ec2:DescribeInternetGateways", |
64 | | - "ec2:DescribeNatGateways", |
65 | | - "ec2:DescribeNetworkAcls", |
66 | | - "ec2:DescribeNetworkInterfaces", |
67 | | - "ec2:DescribeRouteTables", |
68 | | - "ec2:DescribeSecurityGroupRules", |
69 | | - "ec2:DescribeSecurityGroups", |
70 | | - "ec2:DescribeSubnets", |
71 | | - "ec2:DescribeVpcAttribute", |
72 | | - "ec2:DescribeVpcs", |
73 | 41 | "ec2:DetachInternetGateway", |
74 | 42 | "ec2:DetachNetworkInterface", |
75 | 43 | "ec2:DisassociateAddress", |
76 | 44 | "ec2:DisassociateRouteTable", |
77 | | - "ec2:GetSecurityGroupsForVpc", |
78 | 45 | "ec2:ModifyVpcAttribute", |
79 | 46 | "ec2:ReleaseAddress", |
80 | 47 | "ec2:RevokeSecurityGroupEgress", |
81 | 48 | "ec2:RevokeSecurityGroupIngress", |
82 | | - "ecr:BatchCheckLayerAvailability", |
83 | | - "ecr:BatchGetImage", |
84 | 49 | "ecr:CompleteLayerUpload", |
85 | | - "ecr:DescribeImages", |
86 | | - "ecr:GetAuthorizationToken", |
87 | | - "ecr:GetDownloadUrlForLayer", |
88 | 50 | "ecr:InitiateLayerUpload", |
89 | 51 | "ecr:PutImage", |
90 | 52 | "ecr:UploadLayerPart", |
|
93 | 55 | "ecs:DeleteCluster", |
94 | 56 | "ecs:DeleteService", |
95 | 57 | "ecs:DeregisterTaskDefinition", |
96 | | - "ecs:DescribeClusters", |
97 | | - "ecs:DescribeServices", |
98 | | - "ecs:DescribeTaskDefinition", |
99 | 58 | "ecs:RegisterTaskDefinition", |
100 | 59 | "ecs:UpdateService", |
101 | | - "ecs:TagResource", |
102 | | - "ecs:UntagResource", |
103 | | - "elasticloadbalancing:AddTags", |
104 | 60 | "elasticloadbalancing:CreateListener", |
105 | 61 | "elasticloadbalancing:CreateLoadBalancer", |
106 | 62 | "elasticloadbalancing:CreateRule", |
|
109 | 65 | "elasticloadbalancing:DeleteLoadBalancer", |
110 | 66 | "elasticloadbalancing:DeleteRule", |
111 | 67 | "elasticloadbalancing:DeleteTargetGroup", |
112 | | - "elasticloadbalancing:DescribeListenerAttributes", |
113 | | - "elasticloadbalancing:DescribeListeners", |
114 | | - "elasticloadbalancing:DescribeListenerCertificates", |
115 | | - "elasticloadbalancing:DescribeLoadBalancerAttributes", |
116 | | - "elasticloadbalancing:DescribeLoadBalancers", |
117 | | - "elasticloadbalancing:DescribeRules", |
118 | | - "elasticloadbalancing:DescribeTags", |
119 | | - "elasticloadbalancing:DescribeTargetGroupAttributes", |
120 | | - "elasticloadbalancing:DescribeTargetGroups", |
121 | 68 | "elasticloadbalancing:ModifyListener", |
122 | 69 | "elasticloadbalancing:ModifyListenerAttributes", |
123 | 70 | "elasticloadbalancing:ModifyLoadBalancerAttributes", |
124 | 71 | "elasticloadbalancing:ModifyRule", |
125 | 72 | "elasticloadbalancing:ModifyTargetGroupAttributes", |
126 | 73 | "iam:AttachRolePolicy", |
127 | 74 | "iam:CreatePolicyVersion", |
128 | | - "iam:GetRole", |
129 | 75 | "iam:PassRole", |
130 | | - "iam:ListRolePolicies", |
131 | | - "iam:ListAttachedRolePolicies", |
132 | | - "iam:ListInstanceProfilesForRole", |
133 | | - "iam:ListPolicyVersions", |
134 | | - "iam:GetPolicy", |
135 | 76 | "iam:CreateRole", |
136 | 77 | "iam:CreatePolicy", |
137 | 78 | "iam:DeleteRole", |
138 | 79 | "iam:DeletePolicy", |
139 | | - "iam:GetPolicyVersion", |
140 | 80 | "iam:DetachRolePolicy", |
141 | | - "iam:TagPolicy", |
142 | | - "iam:TagRole", |
143 | 81 | "kms:CreateGrant", |
144 | 82 | "kms:Decrypt", |
145 | | - "kms:DescribeKey", |
146 | 83 | "logs:CreateLogGroup", |
147 | 84 | "logs:DeleteLogGroup", |
148 | | - "logs:DescribeLogGroups", |
149 | | - "logs:ListTagsForResource", |
150 | 85 | "logs:PutRetentionPolicy", |
151 | 86 | "rds:CreateDBCluster", |
152 | 87 | "rds:CreateDBInstance", |
153 | 88 | "rds:CreateDBSubnetGroup", |
154 | 89 | "rds:DeleteDBCluster", |
155 | 90 | "rds:DeleteDBInstance", |
156 | 91 | "rds:DeleteDBSubnetGroup", |
157 | | - "rds:DescribeDBClusters", |
158 | | - "rds:DescribeDBInstances", |
159 | | - "rds:DescribeDBSubnetGroups", |
160 | | - "rds:DescribeGlobalClusters", |
161 | | - "rds:ListTagsForResource", |
162 | | - "rds:AddTagsToResource", |
163 | 92 | "rds:ModifyDBCluster", |
164 | 93 | "rds:ModifyCurrentDBClusterCapacity", |
165 | 94 | "rds:ModifyDBInstance", |
166 | | - "rds:RemoveTagsFromResource", |
167 | 95 | "resource-groups:CreateGroup", |
168 | 96 | "resource-groups:DeleteGroup", |
169 | | - "resource-groups:GetGroup", |
170 | | - "resource-groups:GetGroupConfiguration", |
171 | | - "resource-groups:GetGroupQuery", |
172 | | - "resource-groups:GetTags", |
173 | | - "resource-groups:Tag", |
174 | 97 | "route53:ChangeResourceRecordSets", |
175 | 98 | "route53:CreateHostedZone", |
176 | | - "route53:GetChange", |
177 | | - "route53:GetHostedZone", |
178 | | - "route53:ListHostedZones", |
179 | | - "route53:ListResourceRecordSets", |
180 | | - "route53:ListTagsForResource", |
181 | 99 | "s3:CreateBucket", |
182 | 100 | "s3:DeleteBucket", |
183 | 101 | "s3:DeleteBucketPolicy", |
184 | 102 | "s3:DeleteObject", |
185 | 103 | "s3:DeleteObjectVersion", |
186 | | - "s3:GetAccelerateConfiguration", |
187 | | - "s3:GetBucketAcl", |
188 | | - "s3:GetBucketCors", |
189 | | - "s3:GetBucketCORS", |
190 | | - "s3:GetBucketLogging", |
191 | | - "s3:GetBucketObjectLockConfiguration", |
192 | | - "s3:GetBucketPolicy", |
193 | | - "s3:GetBucketPublicAccessBlock", |
194 | | - "s3:GetBucketRequestPayment", |
195 | | - "s3:GetBucketTagging", |
196 | | - "s3:GetBucketVersioning", |
197 | | - "s3:GetBucketWebsite", |
198 | | - "s3:GetEncryptionConfiguration", |
199 | | - "s3:GetObject", |
200 | | - "s3:GetObjectTagging", |
201 | | - "s3:GetLifecycleConfiguration", |
202 | | - "s3:ListBucket", |
203 | | - "s3:ListBucketVersions", |
204 | 104 | "s3:PutBucketLogging", |
205 | 105 | "s3:PutBucketPolicy", |
206 | 106 | "s3:PutBucketPublicAccessBlock", |
207 | | - "s3:PutBucketTagging", |
208 | 107 | "s3:PutBucketVersioning", |
209 | 108 | "s3:PutObject", |
210 | | - "s3:PutObjectTagging", |
211 | | - "s3:GetReplicationConfiguration", |
212 | | - "s3:TagResource", |
213 | | - "s3:UntagResource", |
214 | 109 | "secretsmanager:CreateSecret", |
215 | 110 | "secretsmanager:PutSecretValue", |
216 | 111 | "secretsmanager:UpdateSecret", |
217 | | - "secretsmanager:TagResource", |
218 | | - "secretsmanager:UntagResource", |
219 | | - "ssm:AddTagsToResource", |
220 | 112 | "ssm:DeleteParameter", |
221 | 113 | "ssm:DeleteParameters", |
222 | | - "ssm:DescribeParameters", |
223 | | - "ssm:GetParameter", |
224 | | - "ssm:GetParameters", |
225 | | - "ssm:ListTagsForResource", |
226 | | - "ssm:PutParameter", |
227 | | - "sts:GetCallerIdentity" |
| 114 | + "ssm:PutParameter" |
228 | 115 | ], |
229 | 116 | "Resource": ["*"] |
230 | 117 | } |
|
0 commit comments