Kafka Admin Role creation on AWS using Cloud Formation

Viewed 47

I am trying to create an admin role for my MSK cluster on AWS using cloud formation. I am using below role policies but not sure why I am not able to list cluster, describe cluster or create MSK connector for my cluster.

can someone please help to identify what is wrong with my role policies.

RolePolicies:
Type: AWS::IAM::ManagedPolicy
Properties:
  ManagedPolicyName: msk-role-policy
  Roles:
  - !Ref AdminRole
  PolicyDocument:
    Version: '2012-10-17'
    Statement:
    -
      Sid: PassRole
      Action:
      - iam:PassRole
      Resource:
      - !Join [ ":", ["arn:aws:iam:", !Ref "AWS::AccountId", "role/app/*"] ]
      Effect: Allow
    -
      Sid: MSKstackCreationPermissionsKafka
      Action:
      - kafka:*
      Resource: 
      - !Join [ ":", ["arn:aws:kafka:us-east-1", !Ref "AWS::AccountId", "cluster/demo*"] ]
      Effect: Allow
    
    -
      Sid: MSKstackCreationPermissionsEc2
      Action:
      - ec2:Describe*
      - ec2:*Address
      - ec2:*SecurityGroup
      - ec2:RunInstances
      - ec2:*Tags
      - ec2:AuthorizeSecurityGroupIngress
      - kms:DescribeKey
      - kms:CreateGrant
      - logs:CreateLogDelivery
      - logs:GetLogDelivery
      - logs:UpdateLogDelivery
      - logs:DeleteLogDelivery
      - logs:ListLogDeliveries
      - logs:PutResourcePolicy
      - logs:DescribeResourcePolicies
      - logs:DescribeLogGroups
      - S3:GetBucketPolicy
      - S3:List*
      - S3:CreateBucket
      Resource: '*'
      Effect: Allow
      
    -
      Sid: MSKstackCreationPermissionsS3
      Action:
      - S3:*
      Resource: 'arn:aws:s3:::cf-templates*/*'
      Effect: Allow
0 Answers
Related