We want our developers to be able to create Code Pipelines that can deploy their services. This means they would need to be able to create IAM Roles for the Code Pipeline Steps.
This means we'd need to give our developers IAM capabilities. Is there a way to restrict this in a way that the IAM Roles they can create are limited to creating certain services? Let's say ECS, EC2, RDS related actions. Or maybe specifically blacklist certain services like IAM related actions.