# Reducing admin role for serverless deployment

**URL:** <https://forum.serverless.com/t/reducing-admin-role-for-serverless-deployment/6579>\
**Category:** Serverless Framework\
**Tags:** aws, lambda, iam\
**Created:** [November 27, 2018, 12:40pm UTC](https://forum.serverless.com/t/reducing-admin-role-for-serverless-deployment/6579 "2018-11-27T12:40:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![NikitaLiashenko](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/nikitaliashenko/32/2783_2.png) [@NikitaLiashenko](https://forum.serverless.com/u/NikitaLiashenko)\
**Post date:** [November 27, 2018, 12:40pm UTC](https://forum.serverless.com/t/reducing-admin-role-for-serverless-deployment/6579/1 "2018-11-27T12:40:02Z")

</div>

Hi,

I’ve checked a lot of resources regarding Role an permissions user need to deploy Lambda with Serverless Framework including issues on Github(F.e. [this](https://github.com/serverless/serverless/issues/1439)) and topics on this forum.  
What I’ve found now are just some assumptions and no full list of roles.  
What I would like to achieve is a help from the Serverless framework development team, cause using Admin access for deployment could lead to Security issues. This is highly important.

Can anyone from deployment team provide a full list of permissions we need for successful Lambda creation and deployment?

---

<div class="post-metadata">

**Author:** ![NikitaLiashenko](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/nikitaliashenko/32/2783_2.png) [@NikitaLiashenko](https://forum.serverless.com/u/NikitaLiashenko)\
**Post date:** [November 28, 2018, 10:21am UTC](https://forum.serverless.com/t/reducing-admin-role-for-serverless-deployment/6579/2 "2018-11-28T10:21:47Z")

</div>

I’ve tried to do this by myself and here are my results.

### CloudFormation

“cloudformation:CancelUpdateStack”  
“cloudformation:ContinueUpdateRollback”  
“cloudformation:CreateStack”  
“cloudformation:DeleteStack”  
“cloudformation:DeleteStackSet”  
“cloudformation:DescribeChangeSet”  
“cloudformation:DescribeStackEvents”  
“cloudformation:DescribeStackResource\*”  
“cloudformation:DescribeStacks”  
“cloudformation:ExecuteChangeSet”  
“cloudformation:GetStackPolicy”  
“cloudformation:GetTemplate”  
“cloudformation:ListChangeSets”  
“cloudformation:ListStackResources”  
“cloudformation:UpdateStack”  
“cloudformation:ValidateTemplate”

### IAM

“iam:AttachRolePolicy”  
“iam:CreateRole”  
“iam:DeleteRole”  
“iam:DeleteRolePolicy”  
“iam:DetachRolePolicy”  
“iam:GetPolicy”  
“iam:GetRole”  
“iam:ListAttachedRolePolicies”  
“iam:ListPolicies”  
“iam:ListRolePolicies”  
“iam:ListRoles”  
“iam:PutRolePolicy”  
“iam:UpdateRole”  
“iam:PassRole”

### Lambda

“lambda:AddPermission”  
“lambda:CreateAlias”  
“lambda:CreateEventSourceMapping”  
“lambda:CreateFunction”  
“lambda:DeleteAlias”  
“lambda:DeleteEventSourceMapping”  
“lambda:DeleteFunction”  
“lambda:Get\*”  
“lambda:List\*”  
“lambda:PublishVersion”  
“lambda:RemovePermission”  
“lambda:TagResource”  
“lambda:UntagResource”  
“lambda:Update\*”

### CloudWatch Logs

“logs:CreateLogGroup”  
“logs:CreateLogStream”  
“logs:DeleteLogGroup”  
“logs:DeleteLogStream”  
“logs:DeleteRetentionPolicy”  
“logs:DeleteSubscriptionFilter”  
“logs:PutMetricFilter”  
“logs:PutSubscriptionFilter”  
“logs:DescribeLogGroups”

### S3

“s3:DeleteObject”  
“s3:DeleteObjectVersion”  
“s3:GetObject”  
“s3:GetObjectVersion”  
“s3:PutObject”  
“s3:CreateBucket”  
“s3:ListBucket”  
“s3:ListBucketVersions”

This is enough for first deploy and future deploys(Serverless Framework version 1.33.2).  
Also I think it can be reduced too, cause Serverless Framework might not need some of these policies.

If you have some thoughts about this list feel free to comment.

---

<div class="post-metadata">

**Author:** ![webjaros](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/webjaros/32/3037_2.png) [@webjaros](https://forum.serverless.com/u/webjaros)\
**Post date:** [February 12, 2019, 1:42pm UTC](https://forum.serverless.com/t/reducing-admin-role-for-serverless-deployment/6579/3 "2019-02-12T13:42:48Z")

</div>

I think that with IAM policies you’ve mentioned you can get other access easily. So does not seem to be very useful to cut the permissions down.

---

<div class="post-metadata">

**Author:** ![richard-stafflink](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/richard-stafflink/32/8029_2.png) [@richard-stafflink](https://forum.serverless.com/u/richard-stafflink)\
**Post date:** [September 4, 2024, 3:09pm UTC](https://forum.serverless.com/t/reducing-admin-role-for-serverless-deployment/6579/4 "2024-09-04T15:09:35Z")

</div>

Missing `cloudformation:CreateChangeSet` as of 2024
