I need to determine exactly the bare minimum AWS IAM permissions needed to create, update and delete several Terraform AWS resources used by some of our terraform templates. This is so we can provide an exact list of permissions needed by our customers to run our terraform templates.
My normal AWS user is a full admin, so the access advisor isn't too helpful for tracking down this task. Instead of creating a new user with no permissions and gradually adding more in until I can run terraform, I wanted to know if there was a better way of finding the needed requirements?
Is there an online AWS resource detailing the bare minimum permissions needed to run CRUD operations on specific resource types? Is there a document in terraform that shows this? Is there a way to have the access advisor show the specific permissions used in operations when I have general * admin rules applied on a user?
For reference here is the list of terraform resources I need to find permission info about:
aws_vpc
aws_iam_instance_profile
aws_iam_policy
aws_iam_role
aws_iam_role_policy_attachment
aws_eip
aws_instance
aws_lb_target_group_attachment
aws_network_interface
aws_security_group
aws_internet_gateway
aws_lb
aws_lb_listener
aws_lb_target_group
aws_route
aws_route
aws_route_table_association
aws_subnet
aws_autoscaling_group
aws_launch_configuration