cancel
Showing results forย 
Search instead forย 
Did you mean:ย 
Administration & Architecture
Explore discussions on Databricks administration, deployment strategies, and architectural best practices. Connect with administrators and architects to optimize your Databricks environment for performance, scalability, and security.
cancel
Showing results forย 
Search instead forย 
Did you mean:ย 

Why does Databricks need ec2:CreateTags and ec2:DeleteTags permissions in the cross-account IAM role?

MoJaMa
Valued Contributor II
Valued Contributor II
1 REPLY 1

MoJaMa
Valued Contributor II
Valued Contributor II

These permissions are one of the list described here in Step 6.c

https://docs.databricks.com/administration-guide/account-api/iam-role.html

It is required because we use tags to identify the owners, and other minimum information, of clusters on AWS. It is not possible to remove these permissions.