Skip to content

Commit bd1f51b

Browse files
author
MAMIP Bot
committed
AmazonEKSMCPReadOnlyAccess - Policy Version v1
1 parent 09e2a97 commit bd1f51b

File tree

1 file changed

+80
-0
lines changed

1 file changed

+80
-0
lines changed
Lines changed: 80 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,80 @@
1+
{
2+
"PolicyVersion": {
3+
"CreateDate": "2025-11-20T17:19:10Z",
4+
"VersionId": "v1",
5+
"Document": {
6+
"Version": "2012-10-17",
7+
"Statement": [
8+
{
9+
"Action": [
10+
"eks:DescribeCluster",
11+
"eks:ListClusters",
12+
"eks:DescribeNodegroup",
13+
"eks:ListNodegroups",
14+
"eks:DescribeAddon",
15+
"eks:ListAddons",
16+
"eks:DescribeAccessEntry",
17+
"eks:ListAccessEntries",
18+
"eks:DescribeInsight",
19+
"eks:ListInsights",
20+
"eks:AccessKubernetesApi"
21+
],
22+
"Resource": "*",
23+
"Effect": "Allow"
24+
},
25+
{
26+
"Action": [
27+
"iam:GetRole",
28+
"iam:ListRolePolicies",
29+
"iam:ListAttachedRolePolicies",
30+
"iam:GetRolePolicy",
31+
"iam:GetPolicy",
32+
"iam:GetPolicyVersion"
33+
],
34+
"Resource": "*",
35+
"Effect": "Allow"
36+
},
37+
{
38+
"Action": [
39+
"ec2:DescribeVpcs",
40+
"ec2:DescribeSubnets",
41+
"ec2:DescribeRouteTables"
42+
],
43+
"Resource": "*",
44+
"Effect": "Allow"
45+
},
46+
{
47+
"Action": [
48+
"sts:GetCallerIdentity"
49+
],
50+
"Resource": "*",
51+
"Effect": "Allow"
52+
},
53+
{
54+
"Action": [
55+
"logs:StartQuery",
56+
"logs:GetQueryResults"
57+
],
58+
"Resource": "*",
59+
"Effect": "Allow"
60+
},
61+
{
62+
"Action": [
63+
"cloudwatch:GetMetricData"
64+
],
65+
"Resource": "*",
66+
"Effect": "Allow"
67+
},
68+
{
69+
"Action": [
70+
"eks-mcp:InvokeMcp",
71+
"eks-mcp:CallReadOnlyTool"
72+
],
73+
"Resource": "*",
74+
"Effect": "Allow"
75+
}
76+
]
77+
},
78+
"IsDefaultVersion": true
79+
}
80+
}

0 commit comments

Comments
 (0)