I found this policy...not sure if everything in there is needed, but as a start it works: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "apigateway:GET", "autoscaling:DescribeAutoScalingGroups", "cloudformation:ListResources", "cloudformation:GetResource", "cloudfront:GetDistributionConfig", "cloudfront:ListDistributions", "cloudfront:ListTagsForResource", "cloudwatch:DescribeAlarms", "cloudwatch:GetMetricData", "cloudwatch:ListMetrics", "directconnect:DescribeConnections", "dynamodb:DescribeTable", "dynamodb:ListTables", "dynamodb:ListTagsOfResource", "ec2:DescribeInstances", "ec2:DescribeInstanceStatus", "ec2:DescribeNatGateways", "ec2:DescribeRegions", "ec2:DescribeReservedInstances", "ec2:DescribeReservedInstancesModifications", "ec2:DescribeTags", "ec2:DescribeVolumes", "ecs:DescribeClusters", "ecs:DescribeServices", "ecs:DescribeTasks", "ecs:ListClusters", "ecs:ListServices", "ecs:ListTagsForResource", "ecs:ListTaskDefinitions", "ecs:ListTasks", "eks:DescribeCluster", "eks:ListClusters", "elasticache:DescribeCacheClusters", "elasticloadbalancing:DescribeLoadBalancerAttributes", "elasticloadbalancing:DescribeLoadBalancers", "elasticloadbalancing:DescribeTags", "elasticloadbalancing:DescribeTargetGroups", "elasticmapreduce:DescribeCluster", "elasticmapreduce:ListClusters", "es:DescribeElasticsearchDomain", "es:ListDomainNames", "kinesis:DescribeStream", "kinesis:ListShards", "kinesis:ListStreams", "kinesis:ListTagsForStream", "kinesisanalytics:ListApplications", "kinesisanalytics:DescribeApplication", "lambda:GetAlias", "lambda:ListFunctions", "lambda:ListTags", "logs:DeleteSubscriptionFilter", "logs:DescribeLogGroups", "logs:DescribeSubscriptionFilters", "logs:PutSubscriptionFilter", "organizations:DescribeOrganization", "rds:DescribeDBInstances", "rds:DescribeDBClusters", "rds:ListTagsForResource", "redshift:DescribeClusters", "redshift:DescribeLoggingStatus", "s3:GetBucketLocation", "s3:GetBucketLogging", "s3:GetBucketNotification", "s3:GetBucketTagging", "s3:ListAllMyBuckets", "s3:ListBucket", "s3:PutBucketNotification", "sqs:GetQueueAttributes", "sqs:ListQueues", "sqs:ListQueueTags", "states:ListActivities", "states:ListStateMachines", "tag:GetResources", "workspaces:DescribeWorkspaces" ], "Resource": "*" } ] }
... View more