Policy: AmazonMWAAServiceRolePolicy ARN: arn:aws:iam::aws:policy/aws-service-role/AmazonMWAAServiceRolePolicy Allowed Actions Actions Services cloudwatch:PutMetricData cloudwatch ec2:AttachNetworkInterface ec2 ec2:CreateNetworkInterface ec2 ec2:CreateNetworkInterfacePermission ec2 ec2:CreateTags ec2 ec2:CreateVpcEndpoint ec2 ec2:CreateVpcEndpoint ec2 ec2:DeleteNetworkInterface ec2 ec2:DeleteNetworkInterfacePermission ec2 ec2:DeleteVpcEndpoints ec2 ec2:DescribeDhcpOptions ec2 ec2:DescribeNetworkInterfaces ec2 ec2:DescribeSecurityGroups ec2 ec2:DescribeSubnets ec2 ec2:DescribeVpcEndpoints ec2 ec2:DescribeVpcs ec2 ec2:DetachNetworkInterface ec2 ec2:ModifyVpcEndpoint ec2 ec2:ModifyVpcEndpoint ec2 logs:CreateLogGroup logs logs:CreateLogStream logs logs:DescribeLogGroups logs