Policy: AmazonKendraFullAccess ARN: arn:aws:iam::aws:policy/AmazonKendraFullAccess Allowed Actions Actions Services cloudwatch:GetMetricData cloudwatch ec2:DescribeSecurityGroups ec2 ec2:DescribeSubnets ec2 ec2:DescribeVpcs ec2 iam:ListRoles iam iam:PassRole iam kendra:* kendra kms:DescribeKey kms kms:ListAliases kms kms:ListKeys kms s3:GetBucketLocation s3 s3:ListAllMyBuckets s3 secretsmanager:CreateSecret secretsmanager secretsmanager:DescribeSecret secretsmanager secretsmanager:ListSecrets secretsmanager