Mods
AWS

IAM Role: AWS/CloudHSM/Metadata

PermissionGrant
cloudhsm:DescribeBackupsMetadata
cloudhsm:DescribeClustersMetadata
cloudhsm:DescribeHapgMetadata
cloudhsm:DescribeHsmMetadata
cloudhsm:DescribeLunaClientMetadata
cloudhsm:ListAvailableZonesMetadata
cloudhsm:ListHapgsMetadata
cloudhsm:ListHsmsMetadata
cloudhsm:ListLunaClientsMetadata
cloudhsm:ListTagsMetadata
cloudhsm:ListTagsForResourceMetadata