IAM rights provided by @awscloud are incredibly poor design. Assign rights to a node requires allowing it affect EVERY node in account #fail