"Action": "iam:CreateServiceLinkedRole",
"autoscaling.amazonaws.com",
"ec2scheduled.amazonaws.com",
"elasticloadbalancing.amazonaws.com",
"spotfleet.amazonaws.com",
"transitgateway.amazonaws.com"
"Action": "iam:CreateServiceLinkedRole",
"eks-nodegroup.amazonaws.com",
"eks-fargate.amazonaws.com"
"arn:*:ssm:*:$CORTEX_ACCOUNT_ID:parameter/aws/*",
"arn:*:ssm:*::parameter/aws/*",
"arn:*:logs:$CORTEX_REGION:$CORTEX_ACCOUNT_ID:log-group:$CORTEX_CLUSTER_NAME",
"arn:*:iam::$CORTEX_ACCOUNT_ID:role/*"
"iam:CreateInstanceProfile",
"logs:DescribeLogStreams",
"iam:RemoveRoleFromInstanceProfile",
"iam:AddRoleToInstanceProfile",
"iam:ListInstanceProfilesForRole",
"iam:ListAttachedRolePolicies",
"iam:DeleteOpenIDConnectProvider",
"iam:DeleteInstanceProfile",
"iam:GetInstanceProfile",
"iam:ListInstanceProfiles",
"iam:CreateOpenIDConnectProvider",
"iam:GetOpenIDConnectProvider",
"arn:*:iam::$CORTEX_ACCOUNT_ID:instance-profile/eksctl-*",
"arn:*:iam::$CORTEX_ACCOUNT_ID:role/eksctl-*",
"arn:*:iam::$CORTEX_ACCOUNT_ID:role/aws-service-role/eks-nodegroup.amazonaws.com/AWSServiceRoleForAmazonEKSNodegroup",
"arn:*:iam::$CORTEX_ACCOUNT_ID:role/eksctl-managed-*",
"arn:*:iam::$CORTEX_ACCOUNT_ID:oidc-provider/*",
"arn:*:logs:$CORTEX_REGION:$CORTEX_ACCOUNT_ID:log-group:$CORTEX_CLUSTER_NAME:*"
"iam:ListPolicyVersions",
"iam:CreatePolicyVersion",
"iam:DeletePolicyVersion"
"Resource": "arn:*:iam::$CORTEX_ACCOUNT_ID:policy/cortex-*"
"ecr:GetAuthorizationToken",
"elasticloadbalancing:*",
"acm:DescribeCertificate",
"servicequotas:ListServiceQuotas"
"Resource": "arn:*:sqs:$CORTEX_REGION:$CORTEX_ACCOUNT_ID:cx-*"
"Resource": "arn:*:s3:::$CORTEX_CLUSTER_NAME*"
"Resource": "arn:*:s3:::$CORTEX_CLUSTER_NAME*/*"