Permissions for @turbot/aws-route53

Taking a look at permissions and associated grant levels for each permission for Route 53:

PermissionGrant LevelHelp
cloudfront:ListDistributionsMetadataRequired for AWS console access to Route 53 per http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/UsingWithIAM.html
ec2:DescribeRegionsMetadataRequired for AWS console access to Route 53 per http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/UsingWithIAM.html
ec2:DescribeVpcsMetadataRequired for AWS console access to Route 53 per http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/UsingWithIAM.html
elasticloadbalancing:DescribeLoadBalancersMetadataRequired for AWS console access to Route 53 per http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/UsingWithIAM.html
route53:AssociateVPCWithHostedZoneAdminAllowed since network admins control the DNS servers (through VPC settings) so this will only work if they have chosen to use AmazonProvidedDNS.
route53:ChangeResourceRecordSetsAdmin
route53:ChangeResourceRecordSetsAdmin
route53:ChangeTagsForResourceAdminTypically Operator but no sense creating Operator group just for tagging permissions.
route53:CreateHealthCheckAdminPublic zones only.
route53:CreateHostedZoneAdmin
route53:CreateQueryLoggingConfigAdminAdmin can create a configuration for DNS query logging to publish log data to an Amazon CloudWatch Logs log group.
route53:CreateReusableDelegationSetAdmin
route53:CreateTrafficPolicyAdminAdmins manage traffic policies.
route53:CreateTrafficPolicyInstanceAdminAdmins manage traffic policies.
route53:CreateTrafficPolicyVersionAdminAdmins manage traffic policies.
route53:CreateVPCAssociationAuthorizationAdmin
route53:DeleteHealthCheckAdminPublic zones only.
route53:DeleteHostedZoneAdmin
route53:DeleteQueryLoggingConfigAdminAdmin can delete a configuration for DNS query logging to stop publishing log data to an Amazon CloudWatch Logs log group.
route53:DeleteReusableDelegationSetAdmin
route53:DeleteTrafficPolicyAdminAdmins manage traffic policies.
route53:DeleteTrafficPolicyInstanceAdminAdmins manage traffic policies.
route53:DeleteVPCAssociationAuthorizationAdmin
route53:DisassociateVPCFromHostedZoneAdminAllowed since network admins control the DNS servers (through VPC settings) so this will only work if they have chosen to use AmazonProvidedDNS.
route53:GetAccountLimitMetadata
route53:GetChangeMetadata
route53:GetChangeDetailsMetadata
route53:GetCheckerIpRangesMetadata
route53:GetGeoLocationMetadata
route53:GetHealthCheckMetadata
route53:GetHealthCheckCountMetadata
route53:GetHealthCheckLastFailureReasonMetadata
route53:GetHealthCheckStatusMetadata
route53:GetHostedZoneMetadata
route53:GetHostedZoneCountMetadata
route53:GetHostedZoneLimitMetadata
route53:GetQueryLoggingConfigMetadataGets information about a specified configuration for DNS query logging.
route53:GetReusableDelegationSetMetadata
route53:GetReusableDelegationSetLimitMetadata
route53:GetTrafficPolicyMetadata
route53:GetTrafficPolicyInstanceMetadata
route53:GetTrafficPolicyInstanceCountMetadata
route53:ListChangeBatchesByHostedZoneMetadata
route53:ListChangeBatchesByRRSetMetadata
route53:ListGeoLocationsMetadata
route53:ListHealthChecksMetadata
route53:ListHostedZonesMetadata
route53:ListHostedZonesByNameMetadata
route53:ListQueryLoggingConfigsMetadataLists the configurations for DNS query logging that are associated with the current AWS account
route53:ListResourceRecordSetsMetadata
route53:ListReusableDelegationSetsMetadata
route53:ListTagsForResourceMetadata
route53:ListTagsForResourcesMetadata
route53:ListTrafficPoliciesMetadata
route53:ListTrafficPolicyInstancesMetadata
route53:ListTrafficPolicyInstancesByHostedZoneMetadata
route53:ListTrafficPolicyInstancesByPolicyMetadata
route53:ListTrafficPolicyVersionsMetadata
route53:ListVPCAssociationAuthorizationsMetadata
route53:TestDNSAnswerMetadataNot listed in policy simulator.
route53:UpdateHealthCheckAdminPublic zones only.
route53:UpdateHostedZoneCommentAdmin
route53:UpdateTrafficPolicyCommentAdminAdmins manage traffic policies.
route53:UpdateTrafficPolicyInstanceAdminAdmins manage traffic policies.
route53domains:CheckDomainAvailabilityMetadata
route53domains:CheckDomainTransferabilityMetadata
s3:ListBucketMetadataRequired for AWS console access to Route 53 per http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/UsingWithIAM.html