diff --git a/examples/recommended-inline-policy.json b/examples/recommended-inline-policy.json index 4709db32..e6e781b3 100644 --- a/examples/recommended-inline-policy.json +++ b/examples/recommended-inline-policy.json @@ -5,12 +5,31 @@ "Effect": "Allow", "Action": [ "vpc-lattice:*", - "iam:CreateServiceLinkedRole", "ec2:DescribeVpcs", "ec2:DescribeSubnets", "ec2:DescribeTags" ], "Resource": "*" + }, + { + "Effect" : "Allow", + "Action" : "iam:CreateServiceLinkedRole", + "Resource" : "arn:aws:iam::*:role/aws-service-role/vpc-lattice.amazonaws.com/AWSServiceRoleForVpcLattice", + "Condition" : { + "StringLike" : { + "iam:AWSServiceName" : "vpc-lattice.amazonaws.com" + } + } + }, + { + "Effect" : "Allow", + "Action" : "iam:CreateServiceLinkedRole", + "Resource" : "arn:aws:iam::*:role/aws-service-role/delivery.logs.amazonaws.com/AWSServiceRoleForLogDelivery", + "Condition" : { + "StringLike" : { + "iam:AWSServiceName" : "delivery.logs.amazonaws.com" + } + } } ] }