AWS Security ChangesHomeSearch

AWS rosa: Update ROSA control plane security group tagging policy

Service: rosa · 2026-07-29 · Security-related high

File: rosa/latest/userguide/doc-history.md · Type: iam

Summary

Added documentation about updated ROSAControlPlaneOperatorPolicy allowing tag management with safeguards

Security assessment

Addresses potential privilege escalation via security group tag manipulation by adding safeguards

Evidence

+Updated ROSAControlPlaneOperatorPolicy| Updated the AWS managed policy ROSAControlPlaneOperatorPolicy. With this update, the Control Plane Operator can add and remove tags on Red Hat-managed security groups (`ec2:DeleteTags`). A safeguard prevents the operator from removing the `red-hat-managed` tag itself.

Diff

diff --git a/rosa/latest/userguide/doc-history.md b/rosa/latest/userguide/doc-history.md
index f7a78a1b5..aec52a79f 100644
--- a//rosa/latest/userguide/doc-history.md
+++ b//rosa/latest/userguide/doc-history.md
@@ -12,0 +13 @@ Change| Description| Date
+Updated ROSAControlPlaneOperatorPolicy| Updated the AWS managed policy ROSAControlPlaneOperatorPolicy. With this update, the Control Plane Operator can add and remove tags on Red Hat-managed security groups (`ec2:DeleteTags`). A safeguard prevents the operator from removing the `red-hat-managed` tag itself. For more information, see [ROSA updates to AWS managed policies](https://docs.aws.amazon.com/rosa/latest/userguide/security-iam-awsmanpol.html#security-iam-awsmanpol-account-updates).| July 28, 2026