Administrator
- Administrator
- All Products
Action
| Description
|
---|---|
iam:AddRoleToInstanceProfile
| Optional if you do not specify master and worker instance profiles.
|
iam:CreateInstanceProfile
| Optional when you provide master and worker roles.
|
iam:DeleteInstanceProfile
| Optional when you provide master and worker roles.
|
iam:GetContextKeysForPrincipalPolicy
iam:SimulatePrincipalPolicy
| Required. Allows permission validation, including
advanced configuration validation and upgrade validation.
|
iam:GetInstanceProfile
| Required. Retrieves information about the specified instance profile, including the instance profile path, GUID, ARN, and role.
|
iam:ListInstanceProfiles
| Required. Lists the instance profiles that have the specified path prefix.
|
Action
| Description
|
---|---|
iam:CreateRole
| Optional when you provide master and worker roles.
|
iam:CreateServiceLinkedRole
| Required. Creates an IAM role that is linked to a specific AWS service.
|
iam:DeleteRole
| Optional when you provide master and worker roles.
|
iam:GetRole
| Required. Retrieves information about the specified role, including the role path.
|
iam:ListRolePolicies
| Required. Retrieves information about the specified role, including the role path.
|
iam:ListRoles
| Required. Retrieves information about the specified role, including the role path.
|
iam:TagRole
| Optional when you provide master and worker roles. Used to tag IAM roles that the Secure Agent creates.
|
Action
| Description
|
---|---|
iam:AttachRolePolicy
iam:DeleteRolePolicy
iam:DetachRolePolicy
iam:PutRolePolicy
| Optional when you provide master and worker roles.
|
iam:GetRolePolicy
| Required. Retrieves the specified inline policy document that AWS embeds with the specified IAM role.
|
iam:ListAttachedRolePolicies
| Required. Lists all managed policies that are attached to the specified IAM role.
|
iam:ListInstanceProfilesForRole
| Required. Lists the instance profiles that have the associated IAM role.
|
iam:RemoveRoleFromInstanceProfile
| Required. Removes the specified IAM role from the specified EC2 instance profile.
|