{ "AWSTemplateFormatVersion": "2010-09-09", "Description": "Setups a role for diagram builder for all resources within an account", "Resources": { "cloudiscoveryRole": { "Type": "AWS::IAM::Role", "Properties": { "AssumeRolePolicyDocument" : { "Statement" : [ { "Effect" : "Allow", "Principal" : { "AWS": { "Fn::Join" : [ "", [ "arn:aws:iam::", { "Ref" : "AWS::AccountId" }, ":root" ]]} }, "Action" : [ "sts:AssumeRole" ] } ] }, "Policies": [{ "PolicyName": "additional-permissions", "PolicyDocument": { "Version": "2012-10-17", "Statement" : [ { "Effect" : "Allow", "Action" : [ "kafka:ListClusters", "synthetics:DescribeCanaries", "medialive:ListInputs", "cloudhsm:DescribeClusters", "ssm:GetParametersByPath", "servicequotas:Get*", "amplify:ListApps", "autoscaling-plans:DescribeScalingPlans", "medialive:ListChannels", "medialive:ListInputDevices", "mediapackage:ListChannels", "qldb:ListLedgers", "transcribe:ListVocabularies", "glue:GetDatabases", "glue:GetUserDefinedFunctions", "glue:GetSecurityConfigurations", "glue:GetTriggers", "glue:GetCrawlers", "glue:ListWorkflows", "glue:ListMLTransforms", "codeguru-reviewer:ListCodeReviews", "servicediscovery:ListNamespaces", "apigateway:GET", "forecast:ListPredictors", "frauddetector:GetDetectors", "forecast:ListDatasetImportJobs", "frauddetector:GetModels", "frauddetector:GetOutcomes", "networkmanager:DescribeGlobalNetworks", "codeartifact:ListDomains", "ses:GetSendQuota", "codeguru-profiler:ListProfilingGroups", "cloudtrail:ListTrails" ], "Resource": [ "*" ] } ] } }], "Path" : "/", "ManagedPolicyArns" : [ "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess", "arn:aws:iam::aws:policy/SecurityAudit" ] } } }, "Outputs" : { "cloudiscoveryRoleArn" : { "Value" : { "Fn::GetAtt": [ "cloudiscoveryRole", "Arn" ]} } } }