Skip to content
This repository was archived by the owner on Jan 19, 2022. It is now read-only.

Commit a0a7182

Browse files
Document required IAM permissions for CloudFormation. (#751)
1 parent 585591a commit a0a7182

File tree

1 file changed

+44
-0
lines changed

1 file changed

+44
-0
lines changed

docs/src/main/asciidoc/cloudformation.adoc

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -188,3 +188,47 @@ with a special setup. The client itself can be configured using the `amazon-clou
188188
</bean>
189189
</beans>
190190
----
191+
192+
=== IAM Permissions
193+
Following IAM permissions are required by Spring Cloud AWS:
194+
195+
[cols="2"]
196+
|===
197+
| Describe stacks
198+
| `cloudformation:DescribeStacks`
199+
200+
| List stack resources
201+
| `cloudformation:ListStackResources`
202+
203+
| Describe stack resources
204+
| `cloudformation:DescribeStackResources`
205+
206+
| Describe EC2 tags
207+
| `ec2:DescribeTags`
208+
209+
|===
210+
211+
Sample IAM policy granting access to CloudFormation:
212+
213+
[source,json,indent=0]
214+
----
215+
{
216+
"Version": "2012-10-17",
217+
"Statement": [
218+
{
219+
"Effect": "Allow",
220+
"Action": [
221+
"cloudformation:ListStackResources",
222+
"cloudformation:DescribeStackResources",
223+
"cloudformation:DescribeStacks"
224+
],
225+
"Resource": "stack-arn"
226+
},
227+
{
228+
"Effect": "Allow",
229+
"Action": "ec2:DescribeTags",
230+
"Resource": "*"
231+
}
232+
]
233+
}
234+
----

0 commit comments

Comments
 (0)