Amazon managed policies for Amazon Route 53 Application Recovery Controller - Amazon Route 53 Application Recovery Controller
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Amazon managed policies for Amazon Route 53 Application Recovery Controller

For information about the Amazon managed policies for the Amazon Route 53 Application Recovery Controller capabilities with managed policies, including a managed policy for a service-linked role, see the following topics:

Updates to Amazon managed policies for Amazon Route 53 Application Recovery Controller

View details about updates to Amazon managed policies for capabilities in Route 53 ARC since this service began tracking these changes. For automatic alerts about changes to this page, subscribe to the RSS feed on the Route 53 ARC Document history page.

Change Description Date

AWSServiceRoleForPercPracticePolicy – New policy

Route 53 ARC added a new service-linked role for autoshift and practice runs.

Route 53 ARC uses the permissions enabled by the service-linked role to monitor customer-provided Amazon CloudWatch alarms and customer Amazon Health Dashboard events for practice runs, and to start practice runs.

To learn more about the new service-linked role, see Service-linked role permissions for AWSServiceRoleForZonalAutoshiftPracticeRun.

November 30, 2023

AmazonRoute53RecoveryControlConfigReadOnlyAccess – Updated policy

Adds permissions for GetResourcePolicy, to support returning details about Amazon Resource Access Manager resource policies for shared resources.

October 18, 2023

Route53RecoveryReadinessServiceRolePolicy – Updated policy

Route 53 ARC added new permissions to query information about Amazon EC2 instances.

Route 53 ARC uses the following permissions to support polling Amazon EC2 instances, to run readiness checks and determine the readiness status for the instances.

ec2:DescribeVpnGateways

ec2:DescribeCustomerGateways

February 17, 2023

Route53RecoveryReadinessServiceRolePolicy – Updated policy

Route 53 ARC added a new permission to query information about Lambda functions.

Route 53 ARC uses the following permission to query information about Lambda functions to run readiness checks and determine the readiness status for the functions.

lambda:ListProvisionedConcurrencyConfigs

August 31, 2022

AmazonRoute53RecoveryControlConfigFullAccess – Updated policy

Removed Amazon Route 53 permissions from the policy and added note listing the optional permissions.

May 26, 2022

AmazonRoute53RecoveryControlConfigFullAccess – Updated policy

Added missing required Amazon Route 53 permissions to the policy.

April 15, 2022

AmazonRoute53RecoveryClusterReadOnlyAccess – Updated policy

Route 53 ARC added a new permission, route53-recovery-cluster:ListRoutingControls, to allow listing routing control ARNs with high availability.

March 15, 2022

AmazonRoute53RecoveryControlConfigReadOnlyAccess – Updated policy

Route 53 ARC added a new permission, route53-recovery-control-config:ListTagsForResources, to allow listing tags for a resource.

December 20, 2021

Route53RecoveryReadinessServiceRolePolicy – Updated policy

Route 53 ARC added a new permission to query information about Amazon API Gateway.

Route 53 ARC uses the permission, apigateway:GET, to query information about API Gateway to run readiness checks and determine the readiness status.

October 28, 2021

AmazonRoute53RecoveryReadinessReadOnlyAccess – Added new permissions

Route 53 ARC added two new permissions to AmazonRoute53RecoveryReadinessReadOnlyAccess:

Route 53 ARC uses route53-recovery-readiness:GetArchitectureRecommendations and route53-recovery-readiness:GetCellReadinessSummary to allow read-only access to these actions for working with recovery readiness.

October 15, 2021

Route53RecoveryReadinessServiceRolePolicy – Updated policy

Route 53 ARC added new permissions to query information about Lambda functions.

Route 53 ARC uses the following permissions to query information about Lambda functions to run readiness checks and determine the readiness status for those functions.

lambda:GetFunctionConcurrency

lambda:GetFunctionConfiguration

lambda:GetProvisionedConcurrencyConfig

lambda:ListAliases

lambda:ListVersionsByFunction

lambda:ListEventSourceMappings

lambda:ListFunctions

October 8, 2021

Route53RecoveryReadinessServiceRolePolicy – Added new managed policies

Route 53 ARC added the following new managed policies:

AmazonRoute53RecoveryReadinessFullAccess

AmazonRoute53RecoveryReadinessReadOnlyAccess

AmazonRoute53RecoveryClusterFullAccess

AmazonRoute53RecoveryClusterReadOnlyAccess

AmazonRoute53RecoveryControlConfigFullAccess

AmazonRoute53RecoveryControlConfigReadOnlyAccess

August 18, 2021

Route 53 ARC started tracking changes

Route 53 ARC started tracking changes for its Amazon managed policies.

July 27, 2021