Permissions for @turbot/aws-ec2

Taking a look at permissions and associated grant levels for each permission for EC2:

PermissionGrant LevelHelp
acm:ListCertificatesMetadataRequired for ELB launches.
application-autoscaling:DeleteScalingPolicyAdminAdmins can change the autoscaling process.
application-autoscaling:DeleteScheduledActionAdmin
application-autoscaling:DeregisterScalableTargetOperator
application-autoscaling:DescribeScalableTargetsMetadata
application-autoscaling:DescribeScalingActivitiesMetadata
application-autoscaling:DescribeScalingPoliciesMetadata
application-autoscaling:DescribeScheduledActionsMetadata
application-autoscaling:PutScalingPolicyAdminAdmins can change the autoscaling process.
application-autoscaling:PutScheduledActionAdmin
application-autoscaling:RegisterScalableTargetOperator
autoscaling-plans:CreateScalingPlanAdmin
autoscaling-plans:DeleteScalingPlanAdmin
autoscaling-plans:DescribeScalingPlanResourcesMetadata
autoscaling-plans:DescribeScalingPlansMetadata
autoscaling-plans:GetScalingPlanResourceForecastDataMetadata
autoscaling-plans:UpdateScalingPlanOperator
autoscaling:AttachInstancesOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:AttachLoadBalancerTargetGroupsOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:AttachLoadBalancersOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:BatchDeleteScheduledActionWhitelistAdmins can change the autoscaling process.
autoscaling:BatchPutScheduledUpdateGroupActionWhitelistAdmins can change the autoscaling process.
autoscaling:CancelInstanceRefreshWhitelist
autoscaling:CompleteLifecycleActionOperatorAllows custom steps in the autoscaling lifecycle process
autoscaling:CreateAutoScalingGroupWhitelist
autoscaling:CreateLaunchConfigurationWhitelist
autoscaling:CreateOrUpdateScalingTriggerWhitelist
autoscaling:CreateOrUpdateTagsOperator
autoscaling:CreateScalingPlanWhitelistAdmins can create autoscaling plan.
autoscaling:DeleteAutoScalingGroupWhitelist
autoscaling:DeleteLaunchConfigurationWhitelist
autoscaling:DeleteLifecycleHookWhitelistAdmins can change the autoscaling process.
autoscaling:DeleteNotificationConfigurationOperatorOperators can control monitoring & notification of the autoscaling group.
autoscaling:DeletePolicyWhitelistAdmins can change the autoscaling process.
autoscaling:DeleteScalingPlanWhitelistAdmins can delete autoscaling plan.
autoscaling:DeleteScheduledActionWhitelistAdmins can change the autoscaling process.
autoscaling:DeleteTagsOperator
autoscaling:DeleteTriggerWhitelist
autoscaling:DeleteWarmPoolAdmin
autoscaling:DescribeAccountLimitsMetadata
autoscaling:DescribeAdjustmentTypesMetadata
autoscaling:DescribeAutoScalingGroupsMetadata
autoscaling:DescribeAutoScalingInstancesMetadata
autoscaling:DescribeAutoScalingNotificationTypesMetadata
autoscaling:DescribeInstanceRefreshesMetadata
autoscaling:DescribeLaunchConfigurationsMetadata
autoscaling:DescribeLifecycleHookTypesMetadata
autoscaling:DescribeLifecycleHooksMetadata
autoscaling:DescribeLoadBalancerTargetGroupsMetadata
autoscaling:DescribeLoadBalancersMetadata
autoscaling:DescribeMetricCollectionTypesMetadata
autoscaling:DescribeNotificationConfigurationsMetadata
autoscaling:DescribePoliciesMetadata
autoscaling:DescribeScalingActivitiesMetadata
autoscaling:DescribeScalingPlanResourcesMetadataDescribes the scalable resources in the specified scaling plan.
autoscaling:DescribeScalingPlansMetadataDescribes the specified scaling plans or all of your scaling plans.
autoscaling:DescribeScalingProcessTypesMetadata
autoscaling:DescribeScheduledActionsMetadata
autoscaling:DescribeTagsMetadata
autoscaling:DescribeTerminationPolicyTypesMetadata
autoscaling:DescribeTriggersMetadata
autoscaling:DescribeWarmPoolMetadata
autoscaling:DetachInstancesOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:DetachLoadBalancerTargetGroupsOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:DetachLoadBalancersOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:DisableMetricsCollectionOperatorOperators can control monitoring & notification of the autoscaling group.
autoscaling:EnableMetricsCollectionOperatorOperators can control monitoring & notification of the autoscaling group.
autoscaling:EnterStandbyOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:ExecutePolicyOperatorOperators can execute a policy that was defined by an Admin.
autoscaling:ExitStandbyOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:PutLifecycleHookWhitelistAdmins can change the autoscaling process.
autoscaling:PutNotificationConfigurationOperatorOperators can control monitoring & notification of the autoscaling group.
autoscaling:PutScalingPolicyWhitelistAdmins can change the autoscaling process.
autoscaling:PutScheduledUpdateGroupActionWhitelistAdmins can change the autoscaling process.
autoscaling:PutWarmPoolAdmin
autoscaling:RecordLifecycleActionHeartbeatOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:ResumeProcessesOperator
autoscaling:SetDesiredCapacityWhitelist
autoscaling:SetInstanceHealthOperator
autoscaling:SetInstanceProtectionOperatorOperators can manage instances in an autoscaling group but not change its config.
autoscaling:StartInstanceRefreshWhitelist
autoscaling:SuspendProcessesOperator
autoscaling:TerminateInstanceInAutoScalingGroupOperator
autoscaling:UpdateAutoScalingGroupWhitelist
aws-marketplace:BatchMeterUsageAdminAdministrators may report software usage.
aws-marketplace:GetEntitlementsMetadataViewing entitlement of a customer to a given product. http://docs.aws.amazon.com/marketplaceentitlement/latest/APIReference/Welcome.html.
aws-marketplace:MeterUsageAdminAdministrators may report software usage.
aws-marketplace:ResolveCustomerAdminUsed by SaaS application and returns customer identifier and product code based on registration token.
aws-marketplace:SubscribeWhitelistAdministrators may subscribe to marketplace software
aws-marketplace:UnsubscribeWhitelistAdministrators may subscribe to marketplace software
aws-marketplace:ViewSubscriptionsMetadataViewing marketplace subscriptions is required for server management if the marketplace is used.
cloudwatch:DescribeAlarmHistoryMetadataFor console access per EC2 ReadOnly policy
cloudwatch:DescribeAlarmsMetadataFor console access per EC2 ReadOnly policy
cloudwatch:DescribeAlarmsForMetricMetadataFor console access per EC2 ReadOnly policy
cloudwatch:GetMetricDataMetadataThis allows GetMetricData API to retrieve as many as metrics data and to perform mathematical expressions on this data.
cloudwatch:GetMetricStatisticsMetadataFor console access per EC2 ReadOnly policy
cloudwatch:ListMetricsMetadataFor console access per EC2 ReadOnly policy
ec2-reports:ViewInstanceUsageReportMetadataObscure permission http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/usage-reports.html#iam-access-ec2-reports
ec2-reports:ViewReservedInstanceUtilizationReportMetadataObscure permission http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/usage-reports.html#iam-access-ec2-reports
ec2:AcceptReservedInstancesExchangeQuoteAdminAccounts can manage their own reserved instances (but cannot resell them).
ec2:AllocateAddressAdminAdmins can allocate new elastic IP addresses; this is considered safe as the proper routing still needs to be configured for public access.
ec2:AllocateHostsAdmin
ec2:AssignIpv6AddressesAdminPrivate IP addresses are within the allocated space to the account so can be safely managed by the account.
ec2:AssignPrivateIpAddressesAdminPrivate IP addresses are within the allocated space to the account so can be safely managed by the account.
ec2:AssociateAddressAdminAdmins can associate elastic IP addresses; this is considered safe as the proper routing still needs to be configured for public access.
ec2:AssociateEnclaveCertificateIamRoleAdmin
ec2:AssociateIamInstanceProfileAdminAdmins manage IAM instance profile associations for existing instances.
ec2:AssociateInstanceEventWindowAdmin
ec2:AssociateTrunkInterfaceAdmin
ec2:AttachNetworkInterfaceAdminNetwork interfaces can be safely used by the account inside the VPC context.
ec2:AttachVolumeAdmin
ec2:BidEvictedEventAdminAdmins can update or terminate spot instances.
ec2:BundleInstanceWhitelistOptional VM export
ec2:CancelBundleTaskWhitelistOptional VM export
ec2:CancelCapacityReservationAdmin
ec2:CancelCapacityReservationFleetsAdmin
ec2:CancelConversionTaskWhitelistOptional VM export
ec2:CancelExportTaskWhitelistOptional VM export
ec2:CancelImportTaskWhitelistOptional VM import
ec2:CancelReservedInstancesListingAdminReserved instance reselling is at the cluster level.
ec2:CancelSpotFleetRequestsAdmin
ec2:CancelSpotInstanceRequestsAdminAccounts can safely use spot instances within their VPC.
ec2:ConfirmProductInstanceAdminOnly relevant to AMI marketplace sellers.
ec2:CopyFpgaImageAdminCopies the specified Amazon FPGA Image (AFI) to the current region.
ec2:CopyImageWhitelistOptional image management. Copies image between regions not across accounts
ec2:CopySnapshotOperatorLow risk operation to copy data within the same account.
ec2:CreateCapacityReservationAdmin
ec2:CreateCapacityReservationFleetAdmin
ec2:CreateFleetAdmin
ec2:CreateFpgaImageWhitelistOptional FPGA image management. https://aws.amazon.com/ec2/instance-types/f1/
ec2:CreateImageWhitelistOptional image management. Creates a new AMI from an instance in the account.
ec2:CreateInstanceExportTaskWhitelistOptional VM export.
ec2:CreateInstanceEventWindowAdmin
ec2:CreateKeyPairAdminAdministrators use key pairs when starting new instances. This should be moved to an option in the future when Guardrails supports non-key pair based login.
ec2:CreateLaunchTemplateAdmin
ec2:CreateLaunchTemplateVersionAdmin
ec2:CreateManagedPrefixListAdmin
ec2:CreateNetworkInterfacePermissionAdmin
ec2:CreateNetworkInterfaceAdminNetwork interfaces can be safely used by the account inside the VPC context.
ec2:CreatePlacementGroupAdminServers can be safely placed within cluster managed networks.
ec2:CreateReplaceRootVolumeTaskAdmin
ec2:CreateReservedInstancesListingAdminReserved instance reselling is at the cluster level.
ec2:CreateRestoreImageTaskAdmin
ec2:CreateSnapshotOperatorLow risk operation to backup data within the same account.
ec2:CreateSnapshotsOperatorLow risk operation to backup data within the same account.
ec2:CreateSpotDatafeedSubscriptionAdminAccounts can safely use spot instances within their VPC.
ec2:CreateStoreImageTaskAdmin
ec2:CreateTagsOperatorTags are low risk for management in Guardrails since accounts are the isolation boundary; not tags.
ec2:CreateVolumeAdminStorage management is safe within the account.
ec2:DeleteFleetsAdmin
ec2:DeleteFpgaImageAdminDeletes the specified Amazon FPGA Image.
ec2:DeleteInstanceEventWindowAdmin
ec2:DeleteKeyPairAdmin
ec2:DeleteLaunchTemplateAdmin
ec2:DeleteLaunchTemplateVersionsAdmin
ec2:DeleteManagedPrefixListAdmin
ec2:DeleteNetworkInterfaceAdminNetwork interfaces can be safely used by the account inside the VPC context.
ec2:DeleteNetworkInterfacePermissionAdmin
ec2:DeletePlacementGroupAdmin
ec2:DeleteSnapshotAdminDeletion of snapshots is limited to Admin though creation is open to Operator.
ec2:DeleteSpotDatafeedSubscriptionAdmin
ec2:DeleteTagsOperatorTags are low risk for management in Guardrails since accounts are the isolation boundary; not tags. Most deletions are denied to operator but tags are a low risk management activity even for deletion.
ec2:DeleteQueuedReservedInstancesAdmin
ec2:DeleteVolumeAdmin
ec2:DeregisterImageWhitelistOptional image management. Deregisters an image preventing further launches
ec2:DeregisterInstanceEventNotificationAttributesAdmin
ec2:DescribeAccountAttributesMetadata
ec2:DescribeAddressesMetadata
ec2:DescribeAddressesAttributeMetadata
ec2:DescribeAvailabilityZonesMetadata
ec2:DescribeBundleTasksMetadata
ec2:DescribeCapacityReservationsMetadata
ec2:DescribeCapacityReservationFleetsMetadata
ec2:DescribeCarrierGatewaysMetadata
ec2:DescribeClassicLinkInstancesMetadata
ec2:DescribeConversionTasksMetadata
ec2:DescribeElasticGpusMetadata
ec2:DescribeExportImageTasksMetadata
ec2:DescribeExportTasksMetadata
ec2:DescribeFastSnapshotRestoresMetadata
ec2:DescribeFleetHistoryMetadata
ec2:DescribeFleetInstancesMetadata
ec2:DescribeFleetsMetadata
ec2:DescribeFpgaImageAttributeMetadataDescribes the specified attribute of the specified Amazon FPGA Image.
ec2:DescribeFpgaImagesMetadata
ec2:DescribeHostReservationOfferingsMetadata
ec2:DescribeHostReservationsMetadata
ec2:DescribeHostsMetadata
ec2:DescribeIamInstanceProfileAssociationsMetadata
ec2:DescribeIdFormatMetadata
ec2:DescribeIdentityIdFormatMetadata
ec2:DescribeImageAttributeMetadata
ec2:DescribeImagesMetadata
ec2:DescribeImportImageTasksMetadata
ec2:DescribeImportSnapshotTasksMetadata
ec2:DescribeInstanceAttributeMetadata
ec2:DescribeInstanceCreditSpecificationsMetadata
ec2:DescribeInstanceEventNotificationAttributesMetadata
ec2:DescribeInstanceEventWindowsMetadata
ec2:DescribeInstanceStatusMetadata
ec2:DescribeInstancesMetadata
ec2:DescribeInstanceTypeOfferingsMetadata
ec2:DescribeInstanceTypesMetadata
ec2:DescribeKeyPairsMetadata
ec2:DescribeLaunchTemplateVersionsMetadata
ec2:DescribeLaunchTemplatesMetadata
ec2:DescribeLicensesMetadataNote: Not currently in use by AWS - http://aws.amazon.com/blogs/aws/bring\_your\_own\_ea\_windows\_server\_license\_to\_ec2/
ec2:DescribeMovingAddressesMetadata
ec2:DescribeNetworkInterfaceAttributeMetadata
ec2:DescribeNetworkInterfacePermissionsMetadataDescribes the permissions of network interfaces.
ec2:DescribeNetworkInterfacesMetadata
ec2:DescribePlacementGroupsMetadata
ec2:DescribePublicIpv4PoolsMetadata
ec2:DescribeIpv6PoolsMetadata
ec2:DescribeReplaceRootVolumeTasksMetadata
ec2:DescribeRegionsMetadata
ec2:DescribeReservedInstancesMetadata
ec2:DescribeReservedInstancesListingsMetadata
ec2:DescribeReservedInstancesModificationsMetadata
ec2:DescribeReservedInstancesOfferingsMetadata
ec2:DescribeReplaceRootVolumeTasksMetadata
ec2:DescribeScheduledInstanceAvailabilityMetadata
ec2:DescribeScheduledInstancesMetadata
ec2:DescribeSecurityGroupReferencesMetadata
ec2:DescribeSecurityGroupsMetadata
ec2:DescribeSnapshotAttributeMetadata
ec2:DescribeSnapshotTierStatusMetadata
ec2:DescribeSnapshotsMetadata
ec2:DescribeSpotDatafeedSubscriptionMetadata
ec2:DescribeSpotFleetInstancesMetadata
ec2:DescribeSpotFleetRequestHistoryMetadata
ec2:DescribeSpotFleetRequestsMetadata
ec2:DescribeSpotInstanceRequestsMetadata
ec2:DescribeSpotPriceHistoryMetadata
ec2:DescribeStaleSecurityGroupsMetadata
ec2:DescribeStoreImageTasksMetadata
ec2:DescribeTagsMetadata
ec2:DescribeVolumeAttributeMetadata
ec2:DescribeVolumeStatusMetadata
ec2:DescribeVolumesMetadata
ec2:DescribeVolumesModificationsMetadata
ec2:DetachClassicLinkVpcAdmin
ec2:DetachNetworkInterfaceAdminNetwork interfaces can be safely used by the account inside the VPC context.
ec2:DetachVolumeAdmin
ec2:DisableEbsEncryptionByDefaultAdminAdmins can disable EBS Encryption by Default.
ec2:DisableFastSnapshotRestoresAdmin
ec2:DisableImageDeprecationAdmin
ec2:DisableSerialConsoleAccessAdmin
ec2:DisassociateAddressAdminAdmins can disassociate elastic IP addresses.
ec2:DisassociateEnclaveCertificateIamRoleAdmin
ec2:DisassociateIamInstanceProfileAdminAdmins manage IAM instance profile associations for existing instances.
ec2:DisassociateInstanceEventWindowAdmin
ec2:DisassociateTrunkInterfaceAdmin
ec2:EnableFastSnapshotRestoresAdmin
ec2:DisableImageBlockPublicAccessAdmin
ec2:EnableImageBlockPublicAccessAdmin
ec2:EnableImageDeprecationAdmin
ec2:EnableSerialConsoleAccessAdmin
ec2:EnableEbsEncryptionByDefaultAdminAdmins can enable EBS Encryption by Default.
ec2:EnableVolumeIOAdmin
ec2:ExportImageOperator
ec2:GetAssociatedEnclaveCertificateIamRolesMetadata
ec2:GetCapacityReservationUsageMetadata
ec2:GetConsoleOutputMetadataAllows viewing of console data from machines; helpful for monitoring & investigating system during bootup. Considered to be metadata not ReadOnly since systems should not be logging sensitive information and it's a key part of troubleshooting before needing access to the actual machine (which would obviously be at least ReadOnly).
ec2:GetConsoleScreenshotMetadataAllows viewing of on-demand screenshot of instance console for machines which is helpful for monitoring & investigating systems when they become unreachable via RDS and SSH. Considered to be metadata and not ReadOnly since it's a key part of troubleshooting when the instance is unreachable.
ec2:GetDefaultCreditSpecificationMetadata
ec2:GetEbsDefaultKmsKeyIdMetadata
ec2:GetEbsEncryptionByDefaultMetadata
ec2:GetGroupsForCapacityReservationMetadata
ec2:GetHostReservationPurchasePreviewMetadataAllows preview of host reservation purchase but does not result in offering being purchased.
ec2:GetInstanceTypesFromInstanceRequirementsMetadata
ec2:GetLaunchTemplateDataMetadataLaunch template data contains metadata about the EC2 instance.
ec2:GetPasswordDataAdminRequired for launch of Windows machines and used with key pairs.
ec2:GetReservedInstancesExchangeQuoteMetadata
ec2:GetSerialConsoleAccessStatusMetadata
ec2:GetSpotPlacementScoresMetadata
ec2:ImportImageWhitelistOptional VM import
ec2:ImportInstanceWhitelistOptional VM import
ec2:ImportKeyPairAdminAdministrators use key pairs when starting new instances. This should be moved to an option in the future when Guardrails supports non-key pair based login.
ec2:ImportSnapshotWhitelistOptional VM import
ec2:ImportVolumeWhitelistOptional VM import
ec2:ListSnapshotsInRecycleBinMetadata
ec2:ModifyAvailabilityZoneGroupAdmin
ec2:ModifyCapacityReservationAdmin
ec2:ModifyCapacityReservationFleetAdmin
ec2:ModifyDefaultCreditSpecificationAdmin
ec2:ModifyEbsDefaultKmsKeyIdAdminAdmins can update default KMS key for EBS Encryption by Default.
ec2:ModifyFleetAdmin
ec2:ModifyFpgaImageAttributeAdminModifies the specified attributes(description
ec2:ModifyHostsAdmin
ec2:ModifyIdFormatAdmin
ec2:ModifyIdentityIdFormatAdmin
ec2:ModifyInstanceEventWindowAdmin
ec2:ModifyImageAttributeWhitelistOptional image attribute management
ec2:ModifyInstanceAttributeAdminAccounts can manage their own instances.
ec2:ModifyInstanceCapacityReservationAttributesAdmin
ec2:ModifyInstanceCreditSpecificationAdmin
ec2:ModifyInstanceEventStartTimeAdmin
ec2:ModifyInstanceMetadataOptionsAdmin
ec2:ModifyInstancePlacementAdmin
ec2:ModifyLaunchTemplateAdmin
ec2:ModifyNetworkInterfaceAttributeAdminNetwork interfaces can be safely used by the account inside the VPC context.
ec2:ModifyReservedInstancesAdminAccounts can manage their own reserved instances (but cannot resell them).
ec2:ModifySnapshotTierAdmin
ec2:ModifySnapshotAttributeAdminAllows for cross-account access.
ec2:ModifySpotFleetRequestAdmin
ec2:ModifyVolumeAdminWithin account storage performance changes.
ec2:ModifyVolumeAttributeAdminWithin account storage performance changes.
ec2:MonitorInstancesAdminMonitoring frequency is managed by accounts.
ec2:MoveAddressToVpcAdmin
ec2:PurchaseHostReservationAdminAccounts can manage their own dedicated hosts.
ec2:PurchaseReservedInstancesOfferingAdminAccounts can manage their own reserved instances (but cannot resell them).
ec2:PurchaseScheduledInstancesOwnerLong term subscriptions are managed by owners.
ec2:RebootInstancesOperatorOperators can start stop and reboot existing instances.
ec2:RegisterImageWhitelistOptional image management. Registers an AMI for launching; typically done automatically as part of CreateImage
ec2:RegisterInstanceEventNotificationAttributesAdmin
ec2:ReleaseAddressAdminAdmins can release elastic IP addresses.
ec2:ReleaseHostsAdmin
ec2:ReplaceIamInstanceProfileAssociationAdminAdmins manage IAM instance profile associations for existing instances.
ec2:ReportInstanceStatusOperatorOperators can report bad instances to AWS support.
ec2:RequestSpotFleetAdmin
ec2:RequestSpotInstancesAdminAccounts can safely use spot instances within their VPC.
ec2:ResetEbsDefaultKmsKeyIdAdminAdmins can reset default KMS key for EBS Encryption by Default to the AWS managed CMK for EBS.
ec2:ResetFpgaImageAttributeAdminResets the the load permission attribute.
ec2:ResetImageAttributeWhitelistOptional image attribute management
ec2:ResetInstanceAttributeAdminInstances are managed by accounts.
ec2:ResetNetworkInterfaceAttributeAdminNetwork interfaces can be safely used by the account inside the VPC context.
ec2:ResetSnapshotAttributeAdmin
ec2:RestoreAddressToClassicAdminEC2 classic should not be used
ec2:RestoreSnapshotTierAdmin
ec2:RestoreSnapshotFromRecycleBinAdmin
ec2:RunInstancesAdminOnly Admin can create new instances.
ec2:RunScheduledInstancesAdmin
ec2:SendDiagnosticInterruptAdmin
ec2:SendSpotInstanceInterruptionsAdmin
ec2:StartInstancesOperatorOperators can start stop and reboot existing instances.
ec2:StopInstancesOperatorOperators can start stop and reboot existing instances.
ec2:TerminateInstancesAdminOnly Admin can terminate instances.
ec2:UnassignIpv6AddressesAdminPrivate IP addresses are within the allocated space to the account so can be safely managed by the account.
ec2:UnassignPrivateIpAddressesAdminPrivate IP addresses are within the allocated space to the account so can be safely managed by the account.
ec2:UnmonitorInstancesAdminMonitoring frequency is managed by accounts.
elastic-inference:ConnectAdmin
elasticloadbalancing:AddListenerCertificatesAdminAdmin can add specified certificate to the specified secure listener.
elasticloadbalancing:AddTagsOperatorOperators can manage tags metadata about ELB.
elasticloadbalancing:ApplySecurityGroupsToLoadBalancerAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:AttachLoadBalancerToSubnetsAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:ConfigureHealthCheckAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:CreateAppCookieStickinessPolicyAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:CreateLBCookieStickinessPolicyAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:CreateListenerAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:CreateLoadBalancerAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:CreateLoadBalancerListenersAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:CreateLoadBalancerListenersAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:CreateLoadBalancerPolicyAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:CreateRuleAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:CreateTargetGroupAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:DeleteListenerAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:DeleteLoadBalancerAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:DeleteLoadBalancerListenersAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:DeleteLoadBalancerPolicyAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:DeleteRuleAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:DeleteTargetGroupAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:DeregisterInstancesFromLoadBalancerOperatorOperators can manage individual instances on the ELB as part of being able to stop start and reboot servers.
elasticloadbalancing:DeregisterTargetsOperatorOperators can manage individual instances on the ALB as part of being able to stop start and reboot servers.
elasticloadbalancing:DescribeAccountLimitsMetadata
elasticloadbalancing:DescribeInstanceHealthMetadata
elasticloadbalancing:DescribeListenerCertificatesMetadata
elasticloadbalancing:DescribeListenersMetadata
elasticloadbalancing:DescribeLoadBalancerAttributesMetadata
elasticloadbalancing:DescribeLoadBalancerPoliciesMetadata
elasticloadbalancing:DescribeLoadBalancerPolicyTypesMetadata
elasticloadbalancing:DescribeLoadBalancersMetadata
elasticloadbalancing:DescribeRulesMetadata
elasticloadbalancing:DescribeSSLPoliciesMetadata
elasticloadbalancing:DescribeTagsMetadata
elasticloadbalancing:DescribeTargetGroupAttributesMetadata
elasticloadbalancing:DescribeTargetGroupsMetadata
elasticloadbalancing:DescribeTargetHealthMetadata
elasticloadbalancing:DetachLoadBalancerFromSubnetsAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:DisableAvailabilityZonesForLoadBalancerAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:EnableAvailabilityZonesForLoadBalancerAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:ModifyListenerAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:ModifyLoadBalancerAttributesAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:ModifyRuleAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:ModifyTargetGroupAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:ModifyTargetGroupAttributesAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:RegisterInstancesWithLoadBalancerOperatorOperators can manage individual instances on the ELB as part of being able to stop start and reboot servers.
elasticloadbalancing:RegisterTargetsOperatorOperators can manage individual instances on the ELB as part of being able to stop start and reboot servers.
elasticloadbalancing:RemoveListenerCertificatesAdminAdmin can remove the specified certificate from the specified secure listener.
elasticloadbalancing:RemoveTagsOperatorOperators can manage tags metadata about ELB.
elasticloadbalancing:SetIpAddressTypeAdmin
elasticloadbalancing:SetLoadBalancerListenerSSLCertificateAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:SetLoadBalancerListenerSSLCertificateAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:SetLoadBalancerPoliciesForBackendServerAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:SetLoadBalancerPoliciesOfListenerAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:SetLoadBalancerPoliciesOfListenerAdminAccounts can manage ELB configuration within cluster defined network boundaries.
elasticloadbalancing:SetRulePrioritiesAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:SetSecurityGroupsAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:SetSubnetsAdminAccounts can manage ALB configuration within cluster defined network boundaries.
elasticloadbalancing:SetWebAclAdmin
health:DescribeEventAggregatesMetadata
iam:PassRoleAdmin
kms:ListAliasesMetadata
marketplacecommerceanalytics:GenerateDataSetAdminAdministrators may access product and customer data on the AWS Marketplace.
marketplacecommerceanalytics:StartSupportDataExportAdminAdministrators may access product and customer data on the AWS Marketplace.