Policy: ROSANodePoolManagementPolicy ARN: arn:aws:iam::aws:policy/service-role/ROSANodePoolManagementPolicy Allowed Actions Actions Services ec2:AuthorizeSecurityGroupIngress ec2 ec2:CreateTags ec2 ec2:CreateTags ec2 ec2:CreateTags ec2 ec2:DescribeDhcpOptions ec2 ec2:DescribeImages ec2 ec2:DescribeInstances ec2 ec2:DescribeInternetGateways ec2 ec2:DescribeNetworkInterfaceAttribute ec2 ec2:DescribeNetworkInterfaces ec2 ec2:DescribeRouteTables ec2 ec2:DescribeSecurityGroups ec2 ec2:DescribeSubnets ec2 ec2:DescribeVpcs ec2 ec2:ModifyNetworkInterfaceAttribute ec2 ec2:ModifyNetworkInterfaceAttribute ec2 ec2:RunInstances ec2 ec2:RunInstances ec2 ec2:RunInstances ec2 ec2:TerminateInstances ec2 iam:CreateServiceLinkedRole iam iam:PassRole iam kms:CreateGrant kms kms:DescribeKey kms kms:GenerateDataKeyWithoutPlaintext kms