A service role needs what the resource handlers call (CRUDL Handlers), and each type's schema lists that. The DynamoDB 24 table schema downloaded in Registry and Providers names 50 permissions across six services:
jq -r '[.handlers[].permissions[]] | unique | group_by(split(":")[0])
| map("\(.[0] | split(":")[0])=\(length)") | join(" ")' \
~/v5-ch7/schemas/aws-dynamodb-table.jsondynamodb=32 iam=1 kinesis=2 kms=6 logs=6 s3=3
Most serve features BookNest does not use: Kinesis streams, KMS keys, imports from S3 24 , replicas. Grant what your templates use, scoped to BookNest's names, and add actions when a deploy's AccessDenied names one. The role booknest-cfn-deployer trusts cloudformation.amazonaws.com; its inline policy starts with the tables:
Policies:
- PolicyName: booknest-data-stacks
PolicyDocument:
Version: "2012-10-17"
Statement:
- Sid: Tables
Effect: Allow
Action: [dynamodb:CreateTable, dynamodb:UpdateTable, dynamodb:DeleteTable,
dynamodb:Describe*, dynamodb:ListTagsOfResource, dynamodb:TagResource,
dynamodb:UntagResource, dynamodb:UpdateTimeToLive,
dynamodb:UpdateContinuousBackups, dynamodb:GetResourcePolicy]
Resource: !Sub arn:aws:dynamodb:*:${AWS::AccountId}:table/booknest-*A Parameters statement grants the SSM calls on parameter/booknest/* the same way. On AWS 24 , IAM Access Analyzer can validate a policy and generate one from CloudTrail 24 activity (not run here).