diff --git a/aws/policy/data-services.yaml b/aws/policy/data-services.yaml index 53eb16f7..a0442cca 100644 --- a/aws/policy/data-services.yaml +++ b/aws/policy/data-services.yaml @@ -96,6 +96,8 @@ Statement: - rds:CreateOptionGroup - rds:ModifyOptionGroup - rds:DeleteOptionGroup + - rds:CreateDBClusterSnapshot + - rds:DeleteDBClusterSnapshot - rds:CreateDBSnapshot - rds:DeleteDBSnapshot Resource: @@ -115,6 +117,7 @@ Statement: - 'arn:aws:rds:{{ aws_region }}:{{ aws_account_id }}:og:*' - 'arn:aws:dms:{{ aws_region }}:{{ aws_account_id }}:endpoint:*' - 'arn:aws:rds:{{ aws_region }}:{{ aws_account_id }}:snapshot:*' + - 'arn:aws:rds:{{ aws_region }}:{{ aws_account_id }}:cluster-snapshot:*' - Sid: AllowGlobalRestrictedResourceActionsWhichIncurFees Effect: Allow Action: