Least-Privilege Roles

Writing a Least-Privilege Service Role

A service role needs what the resource handlers call (CRUDL Handlers), and each type's schema lists that. The DynamoDB 24 table schema downloaded in Registry and Providers names 50 permissions across six services:

Counting the permissions the DynamoDB table handlers declareYAML
jq -r '[.handlers[].permissions[]] | unique | group_by(split(":")[0])
  | map("\(.[0] | split(":")[0])=\(length)") | join(" ")' \
  ~/v5-ch7/schemas/aws-dynamodb-table.json
Output
dynamodb=32 iam=1 kinesis=2 kms=6 logs=6 s3=3

Most serve features BookNest does not use: Kinesis streams, KMS keys, imports from S3 24 , replicas. Grant what your templates use, scoped to BookNest's names, and add actions when a deploy's AccessDenied names one. The role booknest-cfn-deployer trusts cloudformation.amazonaws.com; its inline policy starts with the tables:

infra/deployer-role.yaml (excerpt): what the service role may do to tablesYAML
      Policies:
        - PolicyName: booknest-data-stacks
          PolicyDocument:
            Version: "2012-10-17"
            Statement:
              - Sid: Tables
                Effect: Allow
                Action: [dynamodb:CreateTable, dynamodb:UpdateTable, dynamodb:DeleteTable,
                         dynamodb:Describe*, dynamodb:ListTagsOfResource, dynamodb:TagResource,
                         dynamodb:UntagResource, dynamodb:UpdateTimeToLive,
                         dynamodb:UpdateContinuousBackups, dynamodb:GetResourcePolicy]
                Resource: !Sub arn:aws:dynamodb:*:${AWS::AccountId}:table/booknest-*

A Parameters statement grants the SSM calls on parameter/booknest/* the same way. On AWS 24 , IAM Access Analyzer can validate a policy and generate one from CloudTrail 24 activity (not run here).