Skip to content

Commit 2695e72

Browse files
author
MAMIP Bot
committed
SageMakerStudioProjectProvisioningRolePolicy - Policy Version v23
1 parent 01b8ce3 commit 2695e72

File tree

1 file changed

+8
-6
lines changed

1 file changed

+8
-6
lines changed

policies/SageMakerStudioProjectProvisioningRolePolicy

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"PolicyVersion": {
3-
"CreateDate": "2025-10-30T22:19:07Z",
4-
"VersionId": "v22",
3+
"CreateDate": "2025-11-11T23:04:09Z",
4+
"VersionId": "v23",
55
"Document": {
66
"Version": "2012-10-17",
77
"Statement": [
@@ -291,7 +291,6 @@
291291
"iam:PolicyARN": [
292292
"arn:aws:iam::aws:policy/SageMakerStudioProjectUserRolePolicy",
293293
"arn:aws:iam::aws:policy/SageMakerStudioProjectRoleMachineLearningPolicy",
294-
"arn:aws:iam::aws:policy/service-role/SageMakerStudioEMRContainersQueryEngineRolePolicy",
295294
"arn:aws:iam::aws:policy/service-role/SageMakerStudioEMRContainersSystemNamespaceRolePolicy",
296295
"arn:aws:iam::aws:policy/service-role/SageMakerStudioEMRServiceRolePolicy",
297296
"arn:aws:iam::aws:policy/service-role/SageMakerStudioEMRInstanceRolePolicy",
@@ -476,7 +475,8 @@
476475
],
477476
"Resource": [
478477
"arn:aws:iam::*:role/datazone_emr_service_role_*",
479-
"arn:aws:iam::*:role/datazone_emr_ec2_instance_role_*"
478+
"arn:aws:iam::*:role/datazone_emr_ec2_instance_role_*",
479+
"arn:aws:iam::*:role/datazone_emr_containers_system_namespace_role_*"
480480
],
481481
"Effect": "Allow",
482482
"Condition": {
@@ -1767,7 +1767,8 @@
17671767
"arn:aws:iam::*:role/aws-service-role/sagemaker.amazonaws.com/AWSServiceRoleForAmazonSageMakerNotebooks",
17681768
"arn:aws:iam::*:role/aws-service-role/ops.emr-serverless.amazonaws.com/AWSServiceRoleForAmazonEMRServerless",
17691769
"arn:aws:iam::*:role/aws-service-role/airflow.amazonaws.com/AWSServiceRoleForAmazonMWAA",
1770-
"arn:aws:iam::*:role/aws-service-role/elasticmapreduce.amazonaws.com/AWSServiceRoleForEMRCleanup"
1770+
"arn:aws:iam::*:role/aws-service-role/elasticmapreduce.amazonaws.com/AWSServiceRoleForEMRCleanup",
1771+
"arn:aws:iam::*:role/aws-service-role/emr-containers.amazonaws.com/AWSServiceRoleForAmazonEMRContainers"
17711772
],
17721773
"Effect": "Allow",
17731774
"Sid": "CreateSLR"
@@ -1931,7 +1932,6 @@
19311932
},
19321933
{
19331934
"Action": [
1934-
"sagemaker:CreateDomain",
19351935
"sagemaker:AddTags"
19361936
],
19371937
"Resource": [
@@ -3027,6 +3027,8 @@
30273027
"emr-containers:DeleteSecurityConfiguration",
30283028
"emr-containers:DeleteVirtualCluster",
30293029
"emr-containers:DescribeSecurityConfiguration",
3030+
"emr-containers:DescribeVirtualCluster",
3031+
"emr-containers:DescribeManagedEndpoint",
30303032
"emr-containers:TagResource"
30313033
],
30323034
"Resource": "*",

0 commit comments

Comments
 (0)