Mods
AWS

IAM Role: AWS/CloudFront/Admin

PermissionGrant
cloudfront:CreateCloudFrontOriginAccessIdentityAdmin
cloudfront:CreateDistributionAdmin
cloudfront:CreateDistributionWithTagsAdmin
cloudfront:CreateFieldLevelEncryptionConfigAdmin
cloudfront:CreateFieldLevelEncryptionProfileAdmin
cloudfront:CreatePublicKeyAdmin
cloudfront:CreateStreamingDistributionAdmin
cloudfront:CreateStreamingDistributionWithTagsAdmin
cloudfront:DeleteCloudFrontOriginAccessIdentityAdmin
cloudfront:DeleteDistributionAdmin
cloudfront:DeleteFieldLevelEncryptionConfigAdmin
cloudfront:DeleteFieldLevelEncryptionProfileAdmin
cloudfront:DeletePublicKeyAdmin
cloudfront:DeleteStreamingDistributionAdmin
cloudfront:GetPublicKeyConfigAdmin
cloudfront:UpdateCloudFrontOriginAccessIdentityAdmin
cloudfront:UpdateDistributionAdmin
cloudfront:UpdateFieldLevelEncryptionConfigAdmin
cloudfront:UpdateFieldLevelEncryptionProfileAdmin
cloudfront:UpdatePublicKeyAdmin
cloudfront:UpdateStreamingDistributionAdmin
cloudfront-keyvaluestore:DeleteKeyAdmin
cloudfront-keyvaluestore:PutKeyAdmin
cloudfront-keyvaluestore:UpdateKeysAdmin
cloudfront:CreateInvalidationOperator
cloudfront:TagResourceOperator
cloudfront:UntagResourceOperator
acm:ListCertificatesMetadata
cloudfront:GetCloudFrontOriginAccessIdentityMetadata
cloudfront:GetCloudFrontOriginAccessIdentityConfigMetadata
cloudfront:GetDistributionMetadata
cloudfront:GetDistributionConfigMetadata
cloudfront:GetFieldLevelEncryptionMetadata
cloudfront:GetFieldLevelEncryptionConfigMetadata
cloudfront:GetFieldLevelEncryptionProfileMetadata
cloudfront:GetFieldLevelEncryptionProfileConfigMetadata
cloudfront:GetInvalidationMetadata
cloudfront:GetPublicKeyMetadata
cloudfront:GetStreamingDistributionMetadata
cloudfront:GetStreamingDistributionConfigMetadata
cloudfront:ListCloudFrontOriginAccessIdentitiesMetadata
cloudfront:ListDistributionsMetadata
cloudfront:ListDistributionsByWebACLIdMetadata
cloudfront:ListFieldLevelEncryptionConfigsMetadata
cloudfront:ListFieldLevelEncryptionProfilesMetadata
cloudfront:ListInvalidationsMetadata
cloudfront:ListPublicKeysMetadata
cloudfront:ListStreamingDistributionsMetadata
cloudfront:ListTagsForResourceMetadata
cloudfront-keyvaluestore:DescribeKeyValueStoreMetadata
cloudfront-keyvaluestore:GetKeyMetadata
cloudfront-keyvaluestore:ListKeysMetadata
elasticloadbalancing:DescribeLoadBalancersMetadata
iam:ListServerCertificatesMetadata
s3:ListAllMyBucketsMetadata