Mods
AWS

IAM Role: AWS/CloudFront/Operator

PermissionGrant
cloudfront:CreateInvalidationOperator
cloudfront:TagResourceOperator
cloudfront:UntagResourceOperator
acm:ListCertificatesMetadata
cloudfront:GetCloudFrontOriginAccessIdentityMetadata
cloudfront:GetCloudFrontOriginAccessIdentityConfigMetadata
cloudfront:GetDistributionMetadata
cloudfront:GetDistributionConfigMetadata
cloudfront:GetFieldLevelEncryptionMetadata
cloudfront:GetFieldLevelEncryptionConfigMetadata
cloudfront:GetFieldLevelEncryptionProfileMetadata
cloudfront:GetFieldLevelEncryptionProfileConfigMetadata
cloudfront:GetInvalidationMetadata
cloudfront:GetPublicKeyMetadata
cloudfront:GetStreamingDistributionMetadata
cloudfront:GetStreamingDistributionConfigMetadata
cloudfront:ListCloudFrontOriginAccessIdentitiesMetadata
cloudfront:ListDistributionsMetadata
cloudfront:ListDistributionsByWebACLIdMetadata
cloudfront:ListFieldLevelEncryptionConfigsMetadata
cloudfront:ListFieldLevelEncryptionProfilesMetadata
cloudfront:ListInvalidationsMetadata
cloudfront:ListPublicKeysMetadata
cloudfront:ListStreamingDistributionsMetadata
cloudfront:ListTagsForResourceMetadata
cloudfront-keyvaluestore:DescribeKeyValueStoreMetadata
cloudfront-keyvaluestore:GetKeyMetadata
cloudfront-keyvaluestore:ListKeysMetadata
elasticloadbalancing:DescribeLoadBalancersMetadata
iam:ListServerCertificatesMetadata
s3:ListAllMyBucketsMetadata