Skip to content

Permissions of IAM Role created by opswitch (v.11.0)

The following IAM Role permissions were created by opswitch when linking AWS accounts. v.11.0 removes rds:DeleteDBInstance and rds:RestoreDBInstanceFromDBSnapshot permissions.

  • Permissions prefixed with Describe
  • CreateSnapshot
  • DeleteSnapshot
  • CreateImage
  • DeregisterImage
  • CreateTags
  • StartInstances
  • StopInstances
  • ModifyInstanceAttribute
  • CopySnapshot
  • CopyImage
  • DescribeAutoScalingGroups
  • UpdateAutoScalingGroup
  • DescribeServices
  • ListClusters
  • ListServices
  • UpdateService
  • Permissions prefixed with Describe
  • CreateDBSnapshot
  • DeleteDBSnapshot
  • ListTagsForResource
  • AddTagsToResource
  • StartDBInstance
  • StopDBInstance
  • CreateDBClusterSnapshot
  • DeleteDBClusterSnapshot
  • StartDBCluster
  • StopDBCluster
  • CopyDBSnapshot
  • CopyDBClusterSnapshot
  • StartWorkspaces
  • DescribeWorkspaces
  • DescribeTags
  • DescribeClusters
  • CreateTags
  • SendCommand
    • Allow all EC2 instances to execute the AWSEC2-CreateVssSnapshot document.
  • GetCommandInvocation
  • CreateGrant
  • ListAliases
  • ListKeyPolicies
  • ListKeys
  • GetKeyPolicy
  • Permissions prefixed with Describe
  • Permissions prefixed with Get
  • ListStacks
  • CreateChangeSet