Service execution role permissions reference
This topic describes the minimal permissions that the Amazon MSK Replicator service execution role requires for each replicator feature. When you create a replicator, some features are enabled by default and others are optional. Use this reference to build a least-privilege policy tailored to the features you enable.
The following table summarizes which features require permissions on the source cluster, target cluster, and caller role.
| Feature | Optional | Source cluster permissions | Target cluster permissions |
|---|---|---|---|
Topic replication |
No |
||
Topic configuration replication ( |
Yes (enabled by default) |
||
Access control list (ACL) replication ( |
Yes (enabled by default) |
||
Consumer group offset sync ( |
Yes (enabled by default) |
Note
You attach log delivery permissions to the caller role (the IAM principal that calls CreateReplicator), not to the service execution role. For more information, see Log delivery permissions.