given the following role, why can my test IAM user not see any EC2 instances? When I login with the test user and go to EC2 I just see "You are not authorized to perform this operation".
As you can see, I built this through the GUI editor. What am I missing?
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"ec2:StartInstances",
"ec2:StopInstances",
"ec2:DescribeHostReservations",
"ec2:DescribeAddresses",
"ec2:DescribeInstances",
"ec2:DescribeTags",
"ec2:DescribeDhcpOptions",
"ec2:DescribeInstanceEventNotificationAttributes",
"ec2:DescribeInstanceCreditSpecifications",
"ec2:DescribeHosts",
"ec2:DescribeVolumeStatus",
"ec2:DescribeInstanceTypeOfferings",
"ec2:DescribeVolumes",
"ec2:DescribeInstanceTypes",
"ec2:DescribeKeyPairs",
"ec2:DescribeInstanceStatus"
],
"Resource": [
"arn:aws:license-manager:*:<redacted>:license-configuration:*",
"arn:aws:ec2:*:<redacted>:instance/*"
],
"Condition": {
"StringEquals": {
"aws:ResourceTag/Product": "Website"
}
}
}
]
}