AWS rosa: Update ROSA control plane security group tagging policy
Summary
Added documentation about updated ROSAControlPlaneOperatorPolicy allowing tag management with safeguards
Security assessment
Addresses potential privilege escalation via security group tag manipulation by adding safeguards
Evidence
+Updated ROSAControlPlaneOperatorPolicy| Updated the AWS managed policy ROSAControlPlaneOperatorPolicy. With this update, the Control Plane Operator can add and remove tags on Red Hat-managed security groups (`ec2:DeleteTags`). A safeguard prevents the operator from removing the `red-hat-managed` tag itself.
Diff
diff --git a/rosa/latest/userguide/doc-history.md b/rosa/latest/userguide/doc-history.md index f7a78a1b5..aec52a79f 100644 --- a//rosa/latest/userguide/doc-history.md +++ b//rosa/latest/userguide/doc-history.md @@ -12,0 +13 @@ Change| Description| Date +Updated ROSAControlPlaneOperatorPolicy| Updated the AWS managed policy ROSAControlPlaneOperatorPolicy. With this update, the Control Plane Operator can add and remove tags on Red Hat-managed security groups (`ec2:DeleteTags`). A safeguard prevents the operator from removing the `red-hat-managed` tag itself. For more information, see [ROSA updates to AWS managed policies](https://docs.aws.amazon.com/rosa/latest/userguide/security-iam-awsmanpol.html#security-iam-awsmanpol-account-updates).| July 28, 2026