Policy: DatabaseAdministrator ARN: arn:aws:iam::aws:policy/job-function/DatabaseAdministrator Allowed Actions Actions Services cloudwatch:DeleteAlarms cloudwatch cloudwatch:Describe* cloudwatch cloudwatch:DisableAlarmActions cloudwatch cloudwatch:EnableAlarmActions cloudwatch cloudwatch:Get* cloudwatch cloudwatch:List* cloudwatch cloudwatch:PutMetricAlarm cloudwatch datapipeline:ActivatePipeline datapipeline datapipeline:CreatePipeline datapipeline datapipeline:DeletePipeline datapipeline datapipeline:DescribeObjects datapipeline datapipeline:DescribePipelines datapipeline datapipeline:GetPipelineDefinition datapipeline datapipeline:ListPipelines datapipeline datapipeline:PutPipelineDefinition datapipeline datapipeline:QueryObjects datapipeline dynamodb:* dynamodb ec2:DescribeAccountAttributes ec2 ec2:DescribeAddresses ec2 ec2:DescribeAvailabilityZones ec2 ec2:DescribeInternetGateways ec2 ec2:DescribeSecurityGroups ec2 ec2:DescribeSubnets ec2 ec2:DescribeVpcs ec2 elasticache:* elasticache iam:GetRole iam iam:ListRoles iam iam:PassRole iam kms:ListKeys kms lambda:CreateEventSourceMapping lambda lambda:CreateFunction lambda lambda:DeleteEventSourceMapping lambda lambda:DeleteFunction lambda lambda:GetFunctionConfiguration lambda lambda:ListEventSourceMappings lambda lambda:ListFunctions lambda logs:Create* logs logs:DescribeLogGroups logs logs:DescribeLogStreams logs logs:FilterLogEvents logs logs:GetLogEvents logs logs:PutLogEvents logs logs:PutMetricFilter logs rds:* rds redshift:* redshift s3:AbortMultipartUpload s3 s3:CreateBucket s3 s3:DeleteObject* s3 s3:Get* s3 s3:List* s3 s3:PutAccelerateConfiguration s3 s3:PutBucketTagging s3 s3:PutBucketVersioning s3 s3:PutBucketWebsite s3 s3:PutLifecycleConfiguration s3 s3:PutObject* s3 s3:PutReplicationConfiguration s3 s3:Replicate* s3 s3:RestoreObject s3 sns:CreateTopic sns sns:DeleteTopic sns sns:Get* sns sns:List* sns sns:SetTopicAttributes sns sns:Subscribe sns sns:Unsubscribe sns