Restricted IAM permissions for Cloudera AI Registry

Cloudera AI Registry installations require iam:CreateRole and iam:AttachRolePolicy permissions on the AWS Cross-Account Role to attach AmazonS3FullAccess to EKS worker node roles.

If your deployment uses restricted IAM policies, pre-created instance profiles, or strict AWS Service Control Policies (SCPs) that block dynamic role actions, you must explicitly grant iam:CreateRole and iam:AttachRolePolicy permissions on the AWS Cross-Account Role during installation:

  • Temporary role creation and attachment: Grant iam:CreateRole and iam:AttachRolePolicy so setup tasks can manage worker node roles.
  • S3 policy attachment authorization: Ensure iam:AttachRolePolicy specifically permits attaching the AmazonS3FullAccess policy to the mlinfra worker node roles.