Skip to main content
This guide lists the AWS IAM permissions required to deploy a Maia runner using the CloudFormation templates Matillion provides. It covers the permissions needed by the deploying user or role—the identity that runs the CloudFormation stack—rather than the permissions the running Maia runner itself needs, which are covered separately in AWS IAM roles. Always follow the principle of least privilege and assign only the minimum permissions required for the specific task.

Deployer permissions

The user or role deploying the CloudFormation stack requires permissions across several AWS services, including IAM, EC2, CloudWatch Logs, Secrets Manager, and ECS.

Coarse-grained

The following AWS managed policies cover all deployment requirements:
  • AmazonECS_FullAccess
  • CloudWatchFullAccess
  • SecretsManagerReadWrite
  • IAMFullAccess
  • AmazonS3FullAccess

Fine-grained

If you prefer to scope permissions more tightly than the managed policies above, the following actions are required.
You can refer to the IAM roles documentation for more detailed information on the task role and task execution role that the CloudFormation stack creates.

AWS service-linked roles

Before deploying a Maia runner, confirm the existence of a service-linked role for Amazon ECS in your AWS account. For details, read Prerequisites in the AWS Fargate manual setup guide.
For S3 and Azure Blob Storage permissions used by pipeline components, read Cloud provider credentials.