Skip to content

Commit 1fa991b

Browse files
authored
Merge pull request #37556 from codyhoag/aws-optional-permissions
BZ#2012324 Explain when specific "Create" IAM permissions are needed
2 parents 4d5db18 + 20b63e4 commit 1fa991b

File tree

1 file changed

+5
-2
lines changed

1 file changed

+5
-2
lines changed

modules/installation-aws-permissions.adoc

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -247,8 +247,6 @@ If you use an existing VPC, your account does not require these permissions to d
247247
.Additional IAM and S3 permissions that are required to create manifests
248248
[%collapsible]
249249
====
250-
* `iam:CreateAccessKey`
251-
* `iam:CreateUser`
252250
* `iam:DeleteAccessKey`
253251
* `iam:DeleteUser`
254252
* `iam:DeleteUserPolicy`
@@ -264,6 +262,11 @@ If you use an existing VPC, your account does not require these permissions to d
264262
* `s3:HeadBucket`
265263
* `s3:ListBucketMultipartUploads`
266264
* `s3:AbortMultipartUpload`
265+
266+
[NOTE]
267+
=====
268+
If you are managing your cloud provider credentials with mint mode, the IAM user also requires the `iam:CreateAccessKey` and `iam:CreateUser` permissions.
269+
=====
267270
====
268271

269272
.Optional permissions for instance and quota checks for installation

0 commit comments

Comments
 (0)