Mods
AWS

IAM Role: AWS/VPC/Admin

PermissionGrant
ec2:AcceptTransitGatewayMulticastDomainAssociationsAdmin
ec2:AcceptTransitGatewayPeeringAttachmentAdmin
ec2:AcceptTransitGatewayVpcAttachmentAdmin
ec2:AdvertiseByoipCidrAdmin
ec2:AllocateAddressAdmin
ec2:AllocateIpamPoolCidrAdmin
ec2:ApplySecurityGroupsToClientVpnTargetNetworkAdmin
ec2:AssociateAddressAdmin
ec2:AssociateClientVpnTargetNetworkAdmin
ec2:AssociateTransitGatewayMulticastDomainAdmin
ec2:AssociateTransitGatewayRouteTableAdmin
ec2:AttachClassicLinkVpcAdmin
ec2:AuthorizeClientVpnIngressAdmin
ec2:CreateCarrierGatewayAdmin
ec2:CreateClientVpnEndpointAdmin
ec2:CreateClientVpnRouteAdmin
ec2:CreateIpamAdmin
ec2:CreateIpamPoolAdmin
ec2:CreateIpamScopeAdmin
ec2:CreateLocalGatewayRouteAdmin
ec2:CreateLocalGatewayRouteTableVpcAssociationAdmin
ec2:CreateNetworkInsightsPathAdmin
ec2:CreateNetworkInsightsAccessScopeAdmin
ec2:CreatePublicIpv4PoolAdmin
ec2:CreateSubnetCidrReservationAdmin
ec2:CreateTrafficMirrorFilterAdmin
ec2:CreateTrafficMirrorFilterRuleAdmin
ec2:CreateTrafficMirrorSessionAdmin
ec2:CreateTrafficMirrorTargetAdmin
ec2:CreateTransitGatewayAdmin
ec2:CreateTransitGatewayConnectAdmin
ec2:CreateTransitGatewayConnectPeerAdmin
ec2:CreateTransitGatewayMulticastDomainAdmin
ec2:CreateTransitGatewayPeeringAttachmentAdmin
ec2:CreateTransitGatewayPrefixListReferenceAdmin
ec2:CreateTransitGatewayRouteAdmin
ec2:CreateTransitGatewayRouteTableAdmin
ec2:CreateTransitGatewayVpcAttachmentAdmin
ec2:CreateTransitGatewayVpcAttachmentAdmin
ec2:DeleteCarrierGatewayAdmin
ec2:DeleteClientVpnEndpointAdmin
ec2:DeleteClientVpnRouteAdmin
ec2:DeleteIpamAdmin
ec2:DeleteIpamPoolAdmin
ec2:DeleteIpamScopeAdmin
ec2:DeleteLocalGatewayRouteAdmin
ec2:DeleteLocalGatewayRouteTableVpcAssociationAdmin
ec2:DeleteNetworkInsightsAnalysisAdmin
ec2:DeleteNetworkInsightsAccessScopeAdmin
ec2:DeleteNetworkInsightsAccessScopeAnalysisAdmin
ec2:DeleteNetworkInsightsPathAdmin
ec2:DeletePublicIpv4PoolAdmin
ec2:DeleteSubnetCidrReservationAdmin
ec2:DeleteTrafficMirrorFilterAdmin
ec2:DeleteTrafficMirrorFilterRuleAdmin
ec2:DeleteTrafficMirrorSessionAdmin
ec2:DeleteTrafficMirrorTargetAdmin
ec2:DeleteTransitGatewayAdmin
ec2:DeleteTransitGatewayConnectAdmin
ec2:DeleteTransitGatewayConnectPeerAdmin
ec2:DeleteTransitGatewayMulticastDomainAdmin
ec2:DeleteTransitGatewayPeeringAttachmentAdmin
ec2:DeleteTransitGatewayPrefixListReferenceAdmin
ec2:DeleteTransitGatewayRouteAdmin
ec2:DeleteTransitGatewayRouteTableAdmin
ec2:DeleteTransitGatewayVpcAttachmentAdmin
ec2:DeleteTransitGatewayVpcAttachmentAdmin
ec2:DeprovisionByoipCidrAdmin
ec2:DeprovisionIpamPoolCidrAdmin
ec2:DeprovisionPublicIpv4PoolCidrAdmin
ec2:DeregisterTransitGatewayMulticastGroupMembersAdmin
ec2:DeregisterTransitGatewayMulticastGroupSourcesAdmin
ec2:DisableIpamOrganizationAdminAccountAdmin
ec2:DisableTransitGatewayRouteTablePropagationAdmin
ec2:DisassociateAddressAdmin
ec2:DisassociateClientVpnTargetNetworkAdmin
ec2:DisassociateTransitGatewayRouteTableAdmin
ec2:DisassociateTransitGatewayMulticastDomainAdmin
ec2:EnableIpamOrganizationAdminAccountAdmin
ec2:EnableTransitGatewayRouteTablePropagationAdmin
ec2:ExportClientVpnClientCertificateRevocationListAdmin
ec2:ExportClientVpnClientConfigurationAdmin
ec2:ExportTransitGatewayRoutesAdmin
ec2:ImportClientVpnClientCertificateRevocationListAdmin
ec2:ModifyAddressAttributeAdmin
ec2:ModifyCapacityReservationAdmin
ec2:ModifyClientVpnEndpointAdmin
ec2:ModifyIpamAdmin
ec2:ModifyIpamPoolAdmin
ec2:ModifyIpamResourceCidrAdmin
ec2:ModifyIpamScopeAdmin
ec2:ModifyManagedPrefixListAdmin
ec2:ModifyTrafficMirrorFilterNetworkServicesAdmin
ec2:ModifyTrafficMirrorFilterRuleAdmin
ec2:ModifyTrafficMirrorSessionAdmin
ec2:ModifyTransitGatewayAdmin
ec2:ModifyTransitGatewayPrefixListReferenceAdmin
ec2:ModifyTransitGatewayVpcAttachmentAdmin
ec2:ModifyVpnConnectionAdmin
ec2:ModifyVpnConnectionAdmin
ec2:ModifyVpnConnectionOptionsAdmin
ec2:ModifyVpnTunnelCertificateAdmin
ec2:ModifyVpnTunnelOptionsAdmin
ec2:MoveByoipCidrToIpamAdmin
ec2:ProvisionByoipCidrAdmin
ec2:ProvisionIpamPoolCidrAdmin
ec2:ProvisionPublicIpv4PoolCidrAdmin
ec2:RegisterTransitGatewayMulticastGroupMembersAdmin
ec2:RegisterTransitGatewayMulticastGroupSourcesAdmin
ec2:RejectTransitGatewayMulticastDomainAssociationsAdmin
ec2:RejectTransitGatewayPeeringAttachmentAdmin
ec2:RejectTransitGatewayVpcAttachmentAdmin
ec2:ReleaseAddressAdmin
ec2:ReleaseIpamPoolAllocationAdmin
ec2:ReplaceTransitGatewayRouteAdmin
ec2:ResetAddressAttributeAdmin
ec2:RestoreManagedPrefixListVersionAdmin
ec2:RevokeClientVpnIngressAdmin
ec2:StartNetworkInsightsAnalysisAdmin
ec2:StartNetworkInsightsAccessScopeAnalysisAdmin
ec2:StartVpcEndpointServicePrivateDnsVerificationAdmin
ec2:TerminateClientVpnConnectionsAdmin
ec2:WithdrawByoipCidrAdmin
tiros:CreateQueryAdmin
ec2:CreateTagsOperator
ec2:DeleteTagsOperator
acm:ListCertificatesMetadata
ec2:DescribeAddressesMetadata
ec2:DescribeAggregateIdFormatMetadata
ec2:DescribeByoipCidrsMetadata
ec2:DescribeClientVpnAuthorizationRulesMetadata
ec2:DescribeClientVpnConnectionsMetadata
ec2:DescribeClientVpnEndpointsMetadata
ec2:DescribeClientVpnRoutesMetadata
ec2:DescribeClientVpnTargetNetworksMetadata
ec2:DescribeCoipPoolsMetadata
ec2:DescribeCustomerGatewaysMetadata
ec2:DescribeDhcpOptionsMetadata
ec2:DescribeEgressOnlyInternetGatewaysMetadata
ec2:DescribeFlowLogsMetadata
ec2:DescribeInternetGatewaysMetadata
ec2:DescribeIpamPoolsMetadata
ec2:DescribeIpamScopesMetadata
ec2:DescribeIpamsMetadata
ec2:DescribeIpv6PoolsMetadata
ec2:DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociationsMetadata
ec2:DescribeLocalGatewayRouteTableVpcAssociationsMetadata
ec2:DescribeLocalGatewayRouteTablesMetadata
ec2:DescribeLocalGatewayVirtualInterfaceGroupsMetadata
ec2:DescribeLocalGatewayVirtualInterfacesMetadata
ec2:DescribeLocalGatewaysMetadata
ec2:DescribeManagedPrefixListsMetadata
ec2:DescribeMovingAddressesMetadata
ec2:DescribeNatGatewaysMetadata
ec2:DescribeNetworkAclsMetadata
ec2:DescribeNetworkInsightsAccessScopeAnalysesMetadata
ec2:DescribeNetworkInsightsAccessScopesMetadata
ec2:DescribeNetworkInsightsAnalysesMetadata
ec2:DescribeNetworkInsightsPathsMetadata
ec2:DescribeNetworkInterfacesMetadata
ec2:DescribePrefixListsMetadata
ec2:DescribePrincipalIdFormatMetadata
ec2:DescribePublicIpv4PoolsMetadata
ec2:DescribeRouteTablesMetadata
ec2:DescribeSecurityGroupReferencesMetadata
ec2:DescribeSecurityGroupRulesMetadata
ec2:DescribeSecurityGroupsMetadata
ec2:DescribeStaleSecurityGroupsMetadata
ec2:DescribeSubnetsMetadata
ec2:DescribeTagsMetadata
ec2:DescribeTrafficMirrorFiltersMetadata
ec2:DescribeTrafficMirrorSessionsMetadata
ec2:DescribeTrafficMirrorTargetsMetadata
ec2:DescribeTransitGatewayAttachmentsMetadata
ec2:DescribeTransitGatewayConnectPeersMetadata
ec2:DescribeTransitGatewayConnectsMetadata
ec2:DescribeTransitGatewayMulticastDomainsMetadata
ec2:DescribeTransitGatewayPeeringAttachmentsMetadata
ec2:DescribeTransitGatewayRouteTablesMetadata
ec2:DescribeTransitGatewayVpcAttachmentsMetadata
ec2:DescribeTransitGatewaysMetadata
ec2:DescribeTrunkInterfaceAssociationsMetadata
ec2:DescribeVpcAttributeMetadata
ec2:DescribeVpcClassicLinkMetadata
ec2:DescribeVpcClassicLinkDnsSupportMetadata
ec2:DescribeVpcEndpointConnectionNotificationsMetadata
ec2:DescribeVpcEndpointConnectionsMetadata
ec2:DescribeVpcEndpointServiceConfigurationsMetadata
ec2:DescribeVpcEndpointServicePermissionsMetadata
ec2:DescribeVpcEndpointServicesMetadata
ec2:DescribeVpcEndpointsMetadata
ec2:DescribeVpcPeeringConnectionMetadata
ec2:DescribeVpcPeeringConnectionsMetadata
ec2:DescribeVpcsMetadata
ec2:DescribeVpnConnectionsMetadata
ec2:DescribeVpnGatewaysMetadata
ec2:GetAssociatedIpv6PoolCidrsMetadata
ec2:GetCapacityReservationUsageMetadata
ec2:GetCoipPoolUsageMetadata
ec2:GetFlowLogsIntegrationTemplateMetadata
ec2:GetIpamAddressHistoryMetadata
ec2:GetIpamPoolAllocationsMetadata
ec2:GetIpamPoolCidrsMetadata
ec2:GetIpamResourceCidrsMetadata
ec2:GetManagedPrefixListAssociationsMetadata
ec2:GetManagedPrefixListEntriesMetadata
ec2:GetNetworkInsightsAccessScopeAnalysisFindingsMetadata
ec2:GetNetworkInsightsAccessScopeContentMetadata
ec2:GetSubnetCidrReservationsMetadata
ec2:GetTransitGatewayAttachmentPropagationsMetadata
ec2:GetTransitGatewayMulticastDomainAssociationsMetadata
ec2:GetTransitGatewayPrefixListReferencesMetadata
ec2:GetTransitGatewayRouteTableAssociationsMetadata
ec2:GetTransitGatewayRouteTablePropagationsMetadata
ec2:GetVpnConnectionDeviceSampleConfigurationMetadata
ec2:GetVpnConnectionDeviceTypesMetadata
ec2:SearchLocalGatewayRoutesMetadata
ec2:SearchTransitGatewayMulticastGroupsMetadata
ec2:SearchTransitGatewayRoutesMetadata
elasticloadbalancing:DescribeLoadBalancersMetadata
logs:DescribeLogGroupsMetadata
logs:DescribeLogStreamsMetadata
ram:GetResourceShareAssociationsMetadata
tiros:GetQueryAnswerMetadata
tiros:GetQueryExplanationMetadata