Create an IAM role with only these permissions:
dynamodb:CreateTable
dynamodb:DescribeTable
Or
Create the IAM service role example with this command:
aws cloudformation create-stack \
--stack-name service-role \
--template-body file://service-role.yaml \
--capabilities CAPABILITY_NAMED_IAM
Get the role ARN
Create the stack with the command:
aws cloudformation create-stack \
--stack-name iam-service-roles \
--template-body file://stack.yaml \
--role-arn "<insert iam role arn>"
Remove the example stack with the command:
aws cloudformation delete-stack \
--stack-name iam-service-roles
Then, remove the role stack with this command:
aws cloudformation delete-stack \
--stack-name service-role