{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"iam:CreateRole",
"iam:Get*",
"iam:PutRolePolicy",
"iam:DeleteRolePolicy",
"iam:DeletePolicy",
"iam:DeleteRole",
"iam:AttachRolePolicy",
"iam:List*",
"iam:Pass*",
"iot:Connect",
"iot:Publish",
"iot:Subscribe",
"iot:Receive",
"iot:AcceptCertificateTransfer",
"iot:AddThingToThingGroup",
"iot:AssociateTargetsWithJob",
"iot:Attach*",
"iot:Cancel*",
"iot:ClearDefaultAuthorizer",
"iot:Create*",
"iot:Delete*",
"iot:DeprecateThingType",
"iot:Describe*",
"iot:Detach*",
"iot:DisableTopicRule",
"iot:EnableTopicRule",
"iot:Get*",
"iot:List*",
"iot:Register*",
"iot:RejectCertificateTransfer",
"iot:RemoveThingFromThingGroup",
"iot:ReplaceTopicRule",
"iot:SearchIndex",
"iot:Set*",
"iot:StartThingRegistrationTask",
"iot:StopThingRegistrationTask",
"iot:TransferCertificate",
"iot:Update*",
"autoscaling:Describe*",
"cloudwatch:*",
"logs:*",
"s3:PutObject",
"s3:ListBucket",
"s3:GetObject",
"s3:CreateBucket",
"cloudformation:*"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": "iam:CreateServiceLinkedRole",
"Resource": "arn:aws:iam::*:role/aws-service-role/events.amazonaws.com/AWSServiceRoleForCloudWatchEvents*",
"Condition": {
"StringLike": {
"iam:AWSServiceName": "events.amazonaws.com"
}
}
}
]
}