Policy: AWSGlueDataBrewServiceRole ARN: arn:aws:iam::aws:policy/service-role/AWSGlueDataBrewServiceRole Allowed Actions Actions Services ec2:CreateNetworkInterface ec2 ec2:CreateTags ec2 ec2:DeleteNetworkInterface ec2 ec2:DeleteTags ec2 ec2:DescribeNetworkInterfaces ec2 ec2:DescribeRouteTables ec2 ec2:DescribeSecurityGroups ec2 ec2:DescribeSubnets ec2 ec2:DescribeVpcAttribute ec2 ec2:DescribeVpcEndpoints ec2 glue:BatchGetCustomEntityTypes glue glue:GetConnection glue glue:GetCustomEntityType glue glue:GetDatabases glue glue:GetPartitions glue glue:GetTable glue glue:GetTables glue lakeformation:GetDataAccess lakeformation logs:CreateLogGroup logs logs:CreateLogStream logs logs:PutLogEvents logs s3:GetObject s3 s3:ListBucket s3 secretsmanager:GetSecretValue secretsmanager