@@ -12,6 +12,8 @@ you grant that user all of the required permissions. To deploy all components of
1212cluster, the IAM user requires the following permissions:
1313
1414.Required EC2 permissions for installation
15+ [%collapsible]
16+ ====
1517* `ec2:AllocateAddress`
1618* `ec2:AssociateAddress`
1719* `ec2:AuthorizeSecurityGroupEgress`
@@ -58,8 +60,11 @@ cluster, the IAM user requires the following permissions:
5860* `ec2:RevokeSecurityGroupIngress`
5961* `ec2:RunInstances`
6062* `ec2:TerminateInstances`
63+ ====
6164
6265.Required permissions for creating network resources during installation
66+ [%collapsible]
67+ ====
6368* `ec2:AssociateDhcpOptions`
6469* `ec2:AssociateRouteTable`
6570* `ec2:AttachInternetGateway`
@@ -75,11 +80,14 @@ cluster, the IAM user requires the following permissions:
7580* `ec2:ModifyVpcAttribute`
7681
7782[NOTE]
78- ====
83+ =====
7984If you use an existing VPC, your account does not require these permissions for creating network resources.
85+ =====
8086====
8187
8288.Required Elasticloadbalancing permissions for installation
89+ [%collapsible]
90+ ====
8391* `elasticloadbalancing:AddTags`
8492* `elasticloadbalancing:ApplySecurityGroupsToLoadBalancer`
8593* `elasticloadbalancing:AttachLoadBalancerToSubnets`
@@ -104,8 +112,11 @@ If you use an existing VPC, your account does not require these permissions for
104112* `elasticloadbalancing:RegisterInstancesWithLoadBalancer`
105113* `elasticloadbalancing:RegisterTargets`
106114* `elasticloadbalancing:SetLoadBalancerPoliciesOfListener`
115+ ====
107116
108117.Required IAM permissions for installation
118+ [%collapsible]
119+ ====
109120* `iam:AddRoleToInstanceProfile`
110121* `iam:CreateInstanceProfile`
111122* `iam:CreateRole`
@@ -124,8 +135,11 @@ If you use an existing VPC, your account does not require these permissions for
124135* `iam:RemoveRoleFromInstanceProfile`
125136* `iam:SimulatePrincipalPolicy`
126137* `iam:TagRole`
138+ ====
127139
128140.Required Route53 permissions for installation
141+ [%collapsible]
142+ ====
129143* `route53:ChangeResourceRecordSets`
130144* `route53:ChangeTagsForResource`
131145* `route53:CreateHostedZone`
@@ -137,8 +151,11 @@ If you use an existing VPC, your account does not require these permissions for
137151* `route53:ListResourceRecordSets`
138152* `route53:ListTagsForResource`
139153* `route53:UpdateHostedZoneComment`
154+ ====
140155
141156.Required S3 permissions for installation
157+ [%collapsible]
158+ ====
142159* `s3:CreateBucket`
143160* `s3:DeleteBucket`
144161* `s3:GetAccelerateConfiguration`
@@ -159,8 +176,11 @@ If you use an existing VPC, your account does not require these permissions for
159176* `s3:PutBucketAcl`
160177* `s3:PutBucketTagging`
161178* `s3:PutEncryptionConfiguration`
179+ ====
162180
163181.S3 permissions that cluster Operators require
182+ [%collapsible]
183+ ====
164184* `s3:DeleteObject`
165185* `s3:GetObject`
166186* `s3:GetObjectAcl`
@@ -169,8 +189,11 @@ If you use an existing VPC, your account does not require these permissions for
169189* `s3:PutObject`
170190* `s3:PutObjectAcl`
171191* `s3:PutObjectTagging`
192+ ====
172193
173194.Required permissions to delete base cluster resources
195+ [%collapsible]
196+ ====
174197* `autoscaling:DescribeAutoScalingGroups`
175198* `ec2:DeleteNetworkInterface`
176199* `ec2:DeleteVolume`
@@ -184,8 +207,11 @@ If you use an existing VPC, your account does not require these permissions for
184207* `s3:DeleteObject`
185208* `s3:ListBucketVersions`
186209* `tag:GetResources`
210+ ====
187211
188212.Required permissions to delete network resources
213+ [%collapsible]
214+ ====
189215* `ec2:DeleteDhcpOptions`
190216* `ec2:DeleteInternetGateway`
191217* `ec2:DeleteNatGateway`
@@ -199,11 +225,14 @@ If you use an existing VPC, your account does not require these permissions for
199225* `ec2:ReplaceRouteTableAssociation`
200226
201227[NOTE]
202- ====
228+ =====
203229If you use an existing VPC, your account does not require these permissions to delete network resources.
230+ =====
204231====
205232
206233.Additional IAM and S3 permissions that are required to create manifests
234+ [%collapsible]
235+ ====
207236* `iam:CreateAccessKey`
208237* `iam:CreateUser`
209238* `iam:DeleteAccessKey`
@@ -221,3 +250,4 @@ If you use an existing VPC, your account does not require these permissions to d
221250* `s3:HeadBucket`
222251* `s3:ListBucketMultipartUploads`
223252* `s3:AbortMultipartUpload`
253+ ====
0 commit comments