Mods
AWS

IAM Role: AWS/QLDB/Metadata

PermissionGrant
iam:ListRolesMetadata
kms:DescribeKeyMetadata
kms:ListAliasesMetadata
qldb:DescribeJournalS3ExportMetadata
qldb:DescribeLedgerMetadata
qldb:GetBlockMetadata
qldb:GetDigestMetadata
qldb:GetRevisionMetadata
qldb:ListJournalS3ExportsMetadata
qldb:ListJournalS3ExportsForLedgerMetadata
qldb:ListLedgersMetadata
qldb:ListTagsForResourceMetadata
s3:GetBucketLocationMetadata
s3:ListAllMyBucketsMetadata