AWS AWSEC2: Clarified IAM permissions requirements
Summary
Specified 'launch template user' must have permissions for AMI launch and EBS operations
Security assessment
Explicitly documents IAM permission requirements to prevent privilege escalation risks and unauthorized resource access
Evidence
* To create EBS volumes with tags from existing snapshots, the launch template user must have read access to the snapshots, and permissions to create and tag volumes.
Diff
diff --git a/AWSEC2/latest/UserGuide/permissions-for-launch-templates.md b/AWSEC2/latest/UserGuide/permissions-for-launch-templates.md index 8617fc90e..412a8a633 100644 --- a//AWSEC2/latest/UserGuide/permissions-for-launch-templates.md +++ b//AWSEC2/latest/UserGuide/permissions-for-launch-templates.md @@ -19 +19 @@ You must grant anyone that will use a launch template the permissions required t - * To launch an instance from a shared private Amazon Machine Image (AMI), the user must have launch permission for the AMI. + * To launch an instance from a shared private Amazon Machine Image (AMI), the launch template user must have launch permission for the AMI. @@ -21 +21 @@ You must grant anyone that will use a launch template the permissions required t - * To create EBS volumes with tags from existing snapshots, the user must have read access to the snapshots, and permissions to create and tag volumes. + * To create EBS volumes with tags from existing snapshots, the launch template user must have read access to the snapshots, and permissions to create and tag volumes.