Aviatrix IAM Policy and Roles
When you onboard AWS, Aviatrix creates IAM policies and roles with the following names:aviatrix-role-appThe role that allows Aviatrix PaaS to perform actions in your AWS account.aviatrix-platform-app-policyThe policy attached to theaviatrix-role-approle.aviatrix-role-ec2Minimal IAM role for EC2 instances deployed by Aviatrix. The name of the role must matchAviatrixPrincipalArn, so the name is extracted from the ARN.
- Assume Role: Use STS to assume a role in your AWS account
- Discover Resources: Enumerate and list compute, networking, and quota information
- Manage Network Infrastructure: Create and configure VPCs, transit gateways, and more
- Manage EC2 Instances: Deploy and configure Aviatrix gateways
- Tag Resources: Apply “Aviatrix-Created-Resource” tag to all infrastructure it creates