I have successfully created a role with policy attached to that role which allows required actions on the bucket. Policy document is:
{ "Version"