-
Notifications
You must be signed in to change notification settings - Fork 0
/
cfn-amplifyRole.yaml
35 lines (34 loc) · 1.12 KB
/
cfn-amplifyRole.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
AWSTemplateFormatVersion: "2010-09-09"
Resources:
AmplifyRole:
Type: 'AWS::IAM::Role'
Properties:
RoleName: amplifyconsole-geotrack-backend-role
Description: IAM Role to deploy amplify geotrack app
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Service:
- amplify.amazonaws.com
Action:
- 'sts:AssumeRole'
Path: /
ManagedPolicyArns:
- arn:aws:iam::aws:policy/AdministratorAccess-Amplify
Policies:
- PolicyName: geotrack-extended-policy
PolicyDocument: # JSON policy document
Version: '2012-10-17'
Statement: # allow read only access to all S3 buckets
- Effect: Allow
Action:
- ssm:RemoveTagsFromResource
- ssm:AddTagsToResource
- iam:ListPolicies
- iam:CreatePolicies
- iam:ReadPolicies
- iam:ListRoles
- iam:AttachRolePolicy
Resource: '*'