IAM Reference
This page lists every permission SKE needs, organized by feature group. You only need to grant permissions for features you use — core permissions for deployment, plus optional permissions for databases, caches, networking, and custom domains.
AWS IAM Permissions
Section titled “AWS IAM Permissions”SKE validates permissions per feature group using iam:SimulatePrincipalPolicy. Each group is checked independently.
Core (required for deployment)
Section titled “Core (required for deployment)”ECR — Container Registry
Section titled “ECR — Container Registry”ecr:GetAuthorizationTokenecr:CreateRepositoryecr:DescribeRepositoriesecr:BatchCheckLayerAvailabilityecr:GetDownloadUrlForLayerecr:BatchGetImageecr:InitiateLayerUploadecr:UploadLayerPartecr:CompleteLayerUploadecr:PutImageecr:SetRepositoryPolicyecr:GetRepositoryPolicyecr:DeleteRepositoryecr:ListImagesecr:BatchDeleteImageLambda — Compute
Section titled “Lambda — Compute”lambda:CreateFunctionlambda:UpdateFunctionCodelambda:UpdateFunctionConfigurationlambda:GetFunctionlambda:DeleteFunctionlambda:InvokeFunctionlambda:GetFunctionConfigurationlambda:ListFunctionslambda:AddPermissionlambda:RemovePermissionlambda:CreateAliaslambda:UpdateAliaslambda:GetAliaslambda:DeleteAliaslambda:PublishVersionlambda:ListVersionsByFunctionlambda:PutFunctionConcurrencylambda:DeleteFunctionConcurrencylambda:GetFunctionConcurrencylambda:TagResourcelambda:UntagResourcelambda:ListTagslambda:PutFunctionEventInvokeConfiglambda:GetFunctionEventInvokeConfiglambda:CreateEventSourceMappinglambda:GetEventSourceMappinglambda:UpdateEventSourceMappinglambda:DeleteEventSourceMappinglambda:ListEventSourceMappingsCloudFormation — Infrastructure Provisioning
Section titled “CloudFormation — Infrastructure Provisioning”cloudformation:CreateStackcloudformation:UpdateStackcloudformation:DeleteStackcloudformation:DescribeStackscloudformation:DescribeStackEventscloudformation:DescribeStackResourcescloudformation:GetTemplatecloudformation:ListStackscloudformation:ValidateTemplateSSM — Parameter Store
Section titled “SSM — Parameter Store”ssm:PutParameterssm:GetParameterssm:GetParametersssm:GetParametersByPathssm:DeleteParameterssm:DeleteParametersssm:DescribeParametersssm:AddTagsToResourcessm:RemoveTagsFromResourcessm:ListTagsForResourceDynamoDB — State Store
Section titled “DynamoDB — State Store”dynamodb:CreateTabledynamodb:DeleteTabledynamodb:DescribeTabledynamodb:PutItemdynamodb:GetItemdynamodb:UpdateItemdynamodb:DeleteItemdynamodb:Querydynamodb:Scandynamodb:TagResourcedynamodb:UntagResourcedynamodb:ListTagsOfResourceS3 — Asset Storage
Section titled “S3 — Asset Storage”s3:CreateBuckets3:DeleteBuckets3:PutObjects3:GetObjects3:DeleteObjects3:ListBuckets3:PutBucketPolicys3:GetBucketPolicys3:PutBucketCorss3:GetBucketCorss3:PutBucketWebsites3:GetBucketWebsiteAPI Gateway
Section titled “API Gateway”apigateway:POSTapigateway:GETapigateway:DELETEapigateway:PUTapigateway:PATCHCloudWatch Logs
Section titled “CloudWatch Logs”logs:CreateLogGrouplogs:DeleteLogGrouplogs:DescribeLogGroupslogs:CreateLogStreamlogs:DescribeLogStreamslogs:GetLogEventslogs:FilterLogEventslogs:PutRetentionPolicylogs:TagLogGrouplogs:UntagLogGrouplogs:ListTagsLogGroupIAM — Role Management
Section titled “IAM — Role Management”iam:CreateRoleiam:DeleteRoleiam:GetRoleiam:PassRoleiam:AttachRolePolicyiam:DetachRolePolicyiam:PutRolePolicyiam:DeleteRolePolicyiam:GetRolePolicyiam:ListRolePoliciesiam:ListAttachedRolePoliciesiam:TagRoleiam:UntagRoleiam:UpdateAssumeRolePolicySecrets Manager
Section titled “Secrets Manager”secretsmanager:CreateSecretsecretsmanager:DeleteSecretsecretsmanager:GetSecretValuesecretsmanager:PutSecretValuesecretsmanager:UpdateSecretsecretsmanager:DescribeSecretsecretsmanager:ListSecretssecretsmanager:TagResourcesecretsmanager:UntagResourcesecretsmanager:RestoreSecretOptional features
Section titled “Optional features”RDS — Databases
Section titled “RDS — Databases”rds:CreateDBInstancerds:DeleteDBInstancerds:DescribeDBInstancesrds:ModifyDBInstancerds:RebootDBInstancerds:CreateDBSubnetGrouprds:DeleteDBSubnetGrouprds:DescribeDBSubnetGroupsrds:ModifyDBSubnetGrouprds:CreateDBClusterrds:DeleteDBClusterrds:DescribeDBClustersrds:ModifyDBClusterrds:AddTagsToResourcerds:RemoveTagsFromResourcerds:ListTagsForResourcerds:CreateDBSnapshotrds:DeleteDBSnapshotrds:DescribeDBSnapshotsrds:RestoreDBInstanceFromDBSnapshotElastiCache — Caches
Section titled “ElastiCache — Caches”elasticache:CreateCacheClusterelasticache:DeleteCacheClusterelasticache:DescribeCacheClusterselasticache:ModifyCacheClusterelasticache:CreateReplicationGroupelasticache:DeleteReplicationGroupelasticache:DescribeReplicationGroupselasticache:ModifyReplicationGroupelasticache:CreateCacheSubnetGroupelasticache:DeleteCacheSubnetGroupelasticache:DescribeCacheSubnetGroupselasticache:ModifyCacheSubnetGroupelasticache:CreateServerlessCacheelasticache:DeleteServerlessCacheelasticache:DescribeServerlessCacheselasticache:ModifyServerlessCacheelasticache:AddTagsToResourceelasticache:RemoveTagsFromResourceelasticache:ListTagsForResourceVPC — Networking
Section titled “VPC — Networking”ec2:CreateVpcec2:DeleteVpcec2:DescribeVpcsec2:ModifyVpcAttributeec2:CreateSubnetec2:DeleteSubnetec2:DescribeSubnetsec2:CreateSecurityGroupec2:DeleteSecurityGroupec2:DescribeSecurityGroupsec2:AuthorizeSecurityGroupIngressec2:RevokeSecurityGroupIngressec2:AuthorizeSecurityGroupEgressec2:RevokeSecurityGroupEgressec2:CreateInternetGatewayec2:DeleteInternetGatewayec2:AttachInternetGatewayec2:DetachInternetGatewayec2:DescribeInternetGatewaysec2:CreateNatGatewayec2:DeleteNatGatewayec2:DescribeNatGatewaysec2:AllocateAddressec2:ReleaseAddressec2:DescribeAddressesec2:CreateRouteTableec2:DeleteRouteTableec2:DescribeRouteTablesec2:CreateRouteec2:DeleteRouteec2:AssociateRouteTableec2:DisassociateRouteTableec2:CreateTagsec2:DeleteTagsec2:DescribeTagsec2:DescribeAvailabilityZonesACM — SSL Certificates
Section titled “ACM — SSL Certificates”acm:RequestCertificateacm:DeleteCertificateacm:DescribeCertificateacm:ListCertificatesacm:AddTagsToCertificateacm:RemoveTagsFromCertificateacm:ListTagsForCertificateRoute 53 — DNS
Section titled “Route 53 — DNS”route53:CreateHostedZoneroute53:DeleteHostedZoneroute53:GetHostedZoneroute53:ListHostedZonesroute53:ChangeResourceRecordSetsroute53:ListResourceRecordSetsroute53:GetChangeSQS — Queues
Section titled “SQS — Queues”sqs:CreateQueuesqs:DeleteQueuesqs:GetQueueUrlsqs:GetQueueAttributessqs:SetQueueAttributessqs:SendMessagesqs:ReceiveMessagesqs:DeleteMessagesqs:PurgeQueuesqs:ListQueuessqs:TagQueuesqs:UntagQueuesqs:ListQueueTagsGCP IAM Roles
Section titled “GCP IAM Roles”GCP uses predefined roles instead of individual permissions.
Always required (11 roles)
Section titled “Always required (11 roles)”| Role | Purpose |
|---|---|
roles/serviceusage.serviceUsageAdmin |
Enable and manage GCP APIs |
roles/iam.serviceAccountAdmin |
Create service accounts for Cloud Run |
roles/resourcemanager.projectIamAdmin |
Bind IAM policies to project resources |
roles/datastore.owner |
Firestore for deployment state tracking |
roles/run.admin |
Deploy and manage Cloud Run services |
roles/artifactregistry.admin |
Push and manage container images |
roles/secretmanager.admin |
Create and manage secrets |
roles/cloudtasks.admin |
Create and manage task queues |
roles/cloudscheduler.admin |
Create and manage scheduled jobs |
roles/logging.viewer |
Read application logs |
roles/storage.objectAdmin |
Upload and serve static assets |
Conditional roles
Section titled “Conditional roles”| Role | When needed | Purpose |
|---|---|---|
roles/compute.networkAdmin |
Networking | Create VPCs, subnets, firewall rules |
roles/cloudsql.admin |
Databases | Create and manage Cloud SQL instances |
roles/redis.admin |
Caching | Create and manage Memorystore instances |
roles/dns.admin |
Custom domains | Manage Cloud DNS zones and records |
Required GCP APIs
Section titled “Required GCP APIs”These APIs are enabled automatically when you connect a provider. The exception is serviceusage.googleapis.com, which must be enabled manually first.
Core APIs:
iam.googleapis.com, run.googleapis.com, artifactregistry.googleapis.com, firestore.googleapis.com, secretmanager.googleapis.com, cloudtasks.googleapis.com, cloudscheduler.googleapis.com, logging.googleapis.com, cloudresourcemanager.googleapis.com
Infrastructure APIs (enabled when needed):
compute.googleapis.com, sqladmin.googleapis.com, redis.googleapis.com, dns.googleapis.com, storage.googleapis.com