Restricted IAM permissions for Cloudera AI Registry
Cloudera AI Registry installations require
iam:CreateRole and iam:AttachRolePolicy permissions on the
AWS Cross-Account Role to attach AmazonS3FullAccess to EKS worker node roles.
If your deployment uses restricted IAM policies, pre-created instance profiles, or strict AWS Service Control Policies (SCPs) that block dynamic role actions, you must explicitly grant iam:CreateRole and iam:AttachRolePolicy permissions on the AWS Cross-Account Role during installation:
- Temporary role creation and attachment: Grant
iam:CreateRoleandiam:AttachRolePolicyso setup tasks can manage worker node roles. - S3 policy attachment authorization: Ensure
iam:AttachRolePolicyspecifically permits attaching theAmazonS3FullAccesspolicy to themlinfraworker node roles.
Recommended IAM policy statements
Option 1: Scoped policy statement (Recommended)
{
"Sid": "AllowMLInfraS3PolicyAttachment",
"Effect": "Allow",
"Action": [
"iam:CreateRole",
"iam:AttachRolePolicy"
],
"Resource": "arn:aws:iam::<aws-account-id>:role/liftie-*-mlinfra-eks-worker-nodes",
"Condition": {
"ArnEquals": {
"iam:PolicyARN": "arn:aws:iam::aws:policy/AmazonS3FullAccess"
}
}
}
Option 2: Broad or temporary policy statement (If wildcards are required during setup)
{
"Sid": "AllowMLInfraS3PolicyAttachmentBroad",
"Effect": "Allow",
"Action": [
"iam:CreateRole",
"iam:AttachRolePolicy"
],
"Resource": "*",
"Condition": {
"ArnEquals": {
"iam:PolicyARN": "arn:aws:iam::aws:policy/AmazonS3FullAccess"
}
}
}
