- Assume role policy - EIP attach policy - EBS attach policy - Route53 update policy - S3 policy for bootstrap bucket (place where launcher script is located) - IAM role to encapsulate all of these