Policy: AmazonRDSServiceRolePolicy ARN: arn:aws:iam::aws:policy/aws-service-role/AmazonRDSServiceRolePolicy Allowed Actions Actions Services cloudwatch:PutMetricData cloudwatch ec2:AllocateAddress ec2 ec2:AssignPrivateIpAddresses ec2 ec2:AssociateAddress ec2 ec2:AuthorizeSecurityGroupIngress ec2 ec2:CreateCoipPoolPermission ec2 ec2:CreateLocalGatewayRouteTablePermission ec2 ec2:CreateNetworkInterface ec2 ec2:CreateSecurityGroup ec2 ec2:CreateVpcEndpoint ec2 ec2:DeleteCoipPoolPermission ec2 ec2:DeleteLocalGatewayRouteTablePermission ec2 ec2:DeleteNetworkInterface ec2 ec2:DeleteSecurityGroup ec2 ec2:DeleteVpcEndpoints ec2 ec2:DescribeAddresses ec2 ec2:DescribeAvailabilityZones ec2 ec2:DescribeCoipPools ec2 ec2:DescribeInternetGateways ec2 ec2:DescribeLocalGatewayRouteTablePermissions ec2 ec2:DescribeLocalGatewayRouteTableVpcAssociations ec2 ec2:DescribeLocalGatewayRouteTables ec2 ec2:DescribeLocalGateways ec2 ec2:DescribeSecurityGroups ec2 ec2:DescribeSubnets ec2 ec2:DescribeVpcAttribute ec2 ec2:DescribeVpcEndpoints ec2 ec2:DescribeVpcs ec2 ec2:DisassociateAddress ec2 ec2:ModifyNetworkInterfaceAttribute ec2 ec2:ModifyVpcEndpoint ec2 ec2:ReleaseAddress ec2 ec2:RevokeSecurityGroupIngress ec2 ec2:UnassignPrivateIpAddresses ec2 kinesis:CreateStream kinesis kinesis:DeleteStream kinesis kinesis:DescribeStream kinesis kinesis:MergeShards kinesis kinesis:PutRecord kinesis kinesis:PutRecords kinesis kinesis:SplitShard kinesis kinesis:UpdateShardCount kinesis logs:CreateLogGroup logs logs:CreateLogStream logs logs:DescribeLogStreams logs logs:PutLogEvents logs rds:CrossRegionCommunication rds secretsmanager:DeleteSecret secretsmanager secretsmanager:DescribeSecret secretsmanager secretsmanager:GetRandomPassword secretsmanager secretsmanager:ListSecretVersionIds secretsmanager secretsmanager:PutSecretValue secretsmanager secretsmanager:RotateSecret secretsmanager secretsmanager:TagResource secretsmanager secretsmanager:UpdateSecret secretsmanager secretsmanager:UpdateSecretVersionStage secretsmanager