AWS mgn: Updated MGN connector IAM roles with least privilege and removed installer role
Summary
Removed MGNConnectorInstallerRole, updated AWSApplicationMigrationConnectorManagementRole policy to use account/region-specific ARNs, and added AWSApplicationMigrationConnectorSharingRole documentation.
Security assessment
The change replaces wildcard resource ARNs with account/region-specific ARNs, enforcing least privilege and reducing risk of unintended access to MGN resources.
Evidence
+ "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:connector/*",
Diff
diff --git a/mgn/latest/ug/create-permissions-manually.md b/mgn/latest/ug/create-permissions-manually.md index e35135011..92a6493e6 100644 --- a//mgn/latest/ug/create-permissions-manually.md +++ b//mgn/latest/ug/create-permissions-manually.md @@ -7 +7 @@ -MGNConnectorInstallerRoleAWSApplicationMigrationConnectorManagementRole +AWSApplicationMigrationConnectorManagementRoleAWSApplicationMigrationConnectorSharingRole_management-account-id @@ -13 +13 @@ NEW - You can now accelerate your migration and modernization with AWS Transform -To create permissions manually, you create the MGNConnectorInstallerRole to install the MGN Connector and the AWSApplicationMigrationConnectorManagementRole needed to enable the connector to run. The connector assumes the AWSApplicationMigrationConnectorSharingRole_`management-account-id` role as needed, for example, to install the replication agent on a source server. +To create permissions manually, you create the **AWSApplicationMigrationConnectorManagementRole** needed to install and run the connector. The connector assumes the **AWSApplicationMigrationConnectorSharingRole_`management-account-id`** role as needed, for example, to install the replication agent on a source server. @@ -15 +15 @@ To create permissions manually, you create the MGNConnectorInstallerRole to inst -## Create the MGNConnectorInstallerRole +###### Note @@ -17 +17 @@ To create permissions manually, you create the MGNConnectorInstallerRole to inst -The **MGNConnectorInstallerRole** role is used to install the Connector. The user or identity that installs the Connector will require permission to assume this role. +The **MGNConnectorInstallerRole** is no longer required and does not need to be created. The permissions to register the connector (`mgn:CreateConnector` and `mgn:TagResource`) are included in the **MgnConnectorPolicy** below. The connector installer obtains the **AWSApplicationMigrationConnectorManagementRole** credentials from the AWS Systems Manager agent, which is registered using the SSM hybrid activation. @@ -19,5 +19 @@ The **MGNConnectorInstallerRole** role is used to install the Connector. The use -To create the role: - - 1. Create a policy from the following JSON: - -JSON +## AWSApplicationMigrationConnectorManagementRole @@ -24,0 +21 @@ JSON +The **AWSApplicationMigrationConnectorManagementRole** role is the role that is assumed by the Connector. The connector installer uses this role's credentials, provided by the AWS Systems Manager agent, to register the connector with MGN. @@ -26 +23 @@ JSON -**** +To create the role: @@ -27,0 +25 @@ JSON + 1. After replacing **ACCOUNT-ID** with your account number, and **AWS_REGION** with the connector region, create a policy from the following JSON: @@ -33,4 +31,7 @@ JSON - "Action": [ - "mgn:TagResource" - ], - "Resource": "arn:aws:mgn:*:*:connector/*", + "Action": "mgn:CreateConnector", + "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:*", + "Effect": "Allow" + }, + { + "Action": "mgn:TagResource", + "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:connector/*", @@ -44,39 +44,0 @@ JSON - { - "Action": [ - "mgn:CreateConnector" - ], - "Resource": "*", - "Effect": "Allow" - } - ] - } - - - 2. Name the policy **MGNConnectorInstallerPolicy**. - - 3. Create a role with your account as the trusted entity. Alternatively use a custom trust policy that will grant the user or identity that will install the Connector, permission to assume this role. - - 4. Attach the **MGNConnectorInstallerPolicy** policy to the Permission policies. - - 5. Name the role **MGNConnectorInstallerRole**. - - - - -## AWSApplicationMigrationConnectorManagementRole - -The **AWSApplicationMigrationConnectorManagementRole** role is the role that is initially assumed by the Connector. - -To create the role: - - 1. After replacing **ACCOUNT-ID** with your account number, and **AWS_REGION** with the connector region, create a policy from the following JSON: - -JSON - - -**** - - - { - "Version":"2012-10-17", - "Statement": [ @@ -95 +57 @@ JSON - "Resource": "arn:aws:secretsmanager:*:*:secret:*", + "Resource": "arn:aws:secretsmanager:AWS_REGION:ACCOUNT-ID:secret:*", @@ -100,3 +62,4 @@ JSON - "Resource": - ["arn:aws:s3:::aws-application-migration-service-AWS_REGION/latest/source-automation-client/linux/ssaf-client/ssaf_client", - "arn:aws:s3:::amazon-ssm-AWS_REGION/*"], + "Resource": [ + "arn:aws:s3:::aws-application-migration-service-AWS_REGION/latest/source-automation-client/linux/ssaf-client/ssaf_client", + "arn:aws:s3:::amazon-ssm-AWS_REGION/*" + ], @@ -136,6 +96,0 @@ JSON -JSON - - -**** - - @@ -166,0 +121,58 @@ JSON +## AWSApplicationMigrationConnectorSharingRole_`management-account-id` + +The **AWSApplicationMigrationConnectorSharingRole_`management-account-id`** role is assumed by the **AWSApplicationMigrationConnectorManagementRole** to perform actions on source servers in member accounts. The role name includes the ID of the account that owns the connector (the management account), which allows a single member account to hold sharing roles for multiple management accounts. + +To create the role: + + 1. Create a policy from the following JSON: + + { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Action": "mgn:StartAgentless", + "Resource": "arn:aws:mgn:*:*:source-server/*" + } + ] + } + + 2. Name the policy **AWSApplicationMigrationAgentInstallationPolicy**. + + 3. Create a role with the following trust relationship, where `management-account-id` is the account in which the connector was created: + + { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Principal": { + "Service": "mgn.amazonaws.com" + }, + "Action": "sts:AssumeRole", + "Condition": { + "StringEquals": { + "aws:SourceAccount": "management-account-id" + }, + "StringLike": { + "aws:SourceArn": "arn:aws:mgn:*:management-account-id:*" + } + } + }, + { + "Effect": "Allow", + "Principal": { + "AWS": "arn:aws:iam::management-account-id:role/AWSApplicationMigrationConnectorManagementRole" + }, + "Action": "sts:AssumeRole" + } + ] + } + + 4. Attach the **AWSApplicationMigrationAgentInstallationPolicy** policy to the Permission policies. + + 5. Name the role **AWSApplicationMigrationConnectorSharingRole_`management-account-id`**, replacing `management-account-id` with the ID of the account in which the connector was created. + + + + @@ -173 +185 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please -IAM roles for connector +Create roles using the console