Policy: AmazonEKSServicePolicy ARN: arn:aws:iam::aws:policy/AmazonEKSServicePolicy Allowed Actions Actions Services ec2:CreateNetworkInterface ec2 ec2:CreateNetworkInterfacePermission ec2 ec2:CreateTags ec2 ec2:CreateTags ec2 ec2:DeleteNetworkInterface ec2 ec2:DeleteTags ec2 ec2:DescribeInstances ec2 ec2:DescribeNetworkInterfaces ec2 ec2:DescribeSecurityGroups ec2 ec2:DescribeSubnets ec2 ec2:DescribeVpcs ec2 ec2:DetachNetworkInterface ec2 ec2:GetSecurityGroupsForVpc ec2 ec2:ModifyNetworkInterfaceAttribute ec2 eks:UpdateClusterVersion eks iam:CreateServiceLinkedRole iam iam:ListAttachedRolePolicies iam logs:CreateLogGroup logs logs:CreateLogStream logs logs:DescribeLogStreams logs logs:PutLogEvents logs route53:AssociateVPCWithHostedZone route53