CodeDeploy is a permissions mess. Just use the arn:aws:iam::aws:policy/AWSCodeDeployRoleForECS role for the code deployment group.
arn:aws:iam::aws:policy/AWSCodeDeployRoleForECS