- allow setting ECR repository policies - add IAM role lifecycle and PassRole permissions - grant Secrets Manager read access - enable S3 bucket notification updates - allow CodePipeline updates - allow EventBridge rule and target management |
||
|---|---|---|
| .. | ||
| cloudformation-write-role.yaml | ||