I am trying to create an admin role for my MSK cluster on AWS using cloud formation. I am using below role policies but not sure why I am not able to list cluster, describe cluster or create MSK connector for my cluster.
can someone please help to identify what is wrong with my role policies.
RolePolicies:
Type: AWS::IAM::ManagedPolicy
Properties:
ManagedPolicyName: msk-role-policy
Roles:
- !Ref AdminRole
PolicyDocument:
Version: '2012-10-17'
Statement:
-
Sid: PassRole
Action:
- iam:PassRole
Resource:
- !Join [ ":", ["arn:aws:iam:", !Ref "AWS::AccountId", "role/app/*"] ]
Effect: Allow
-
Sid: MSKstackCreationPermissionsKafka
Action:
- kafka:*
Resource:
- !Join [ ":", ["arn:aws:kafka:us-east-1", !Ref "AWS::AccountId", "cluster/demo*"] ]
Effect: Allow
-
Sid: MSKstackCreationPermissionsEc2
Action:
- ec2:Describe*
- ec2:*Address
- ec2:*SecurityGroup
- ec2:RunInstances
- ec2:*Tags
- ec2:AuthorizeSecurityGroupIngress
- kms:DescribeKey
- kms:CreateGrant
- logs:CreateLogDelivery
- logs:GetLogDelivery
- logs:UpdateLogDelivery
- logs:DeleteLogDelivery
- logs:ListLogDeliveries
- logs:PutResourcePolicy
- logs:DescribeResourcePolicies
- logs:DescribeLogGroups
- S3:GetBucketPolicy
- S3:List*
- S3:CreateBucket
Resource: '*'
Effect: Allow
-
Sid: MSKstackCreationPermissionsS3
Action:
- S3:*
Resource: 'arn:aws:s3:::cf-templates*/*'
Effect: Allow