Permissions for @turbot/aws-fsx

Taking a look at permissions and associated grant levels for each permission for FSx:

PermissionGrant LevelHelp
ds:DescribeDirectoriesMetadata
ec2:DescribeNetworkInterfaceAttributeMetadata
ec2:DescribeNetworkInterfacesMetadata
ec2:DescribeSecurityGroupsMetadata
ec2:DescribeSubnetsMetadata
ec2:DescribeVpcsMetadata
fsx:CreateBackupAdmin
fsx:CreateFileSystemAdmin
fsx:CreateFileSystemFromBackupAdmin
fsx:DeleteBackupAdmin
fsx:DeleteFileSystemAdmin
fsx:DescribeBackupsMetadata
fsx:DescribeFileSystemsMetadata
fsx:ListTagsForResourceMetadata
fsx:TagResourceAdmin
fsx:UntagResourceAdmin
fsx:UpdateFileSystemAdmin
iam:GetRoleMetadata
iam:ListRolesMetadataRequired to list the existing roles in IAM.
iam:PassRoleAdminAWS services allow Admin to pass an existing role to the service.
kms:DescribeKeyMetadata
kms:ListAliasesMetadata
s3:HeadBucketMetadataHelps to determine if a bucket exists and user have permission to access it.