AWS AmazonCloudWatch: Synthetics canary docs: note on role manager auto-attaching IAM role
Summary
Adds a note that when IAM role manager is enabled in the account, CloudWatch attaches the canary role automatically and the role options (e.g. 'Create new role') are replaced by a 'Customize' option, with a link to the IAM User Guide's role-creation topic.
Security assessment
The change is IAM-adjacent documentation about how a canary's execution role is attached (relevant given the surrounding PassRole permission context), but it only describes console behavior when role manager is enabled and links to generic IAM role-creation docs. It documents no new security control, guidance, or fix, so severity is low.
Evidence
+If role manager is enabled in your account, CloudWatch attaches the role for you, and the role options described here (for example the **Create new role** button) are replaced by a **Customize** option. To use a different role, choose **Customize**. For more information about IAM role creation, see [IAM role creation](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create.html) in the _IAM User Guide_.
Diff
diff --git a/AmazonCloudWatch/latest/monitoring/CloudWatch_Synthetics_Canaries_Create.md b/AmazonCloudWatch/latest/monitoring/CloudWatch_Synthetics_Canaries_Create.md index 5aba7cd60..5216be444 100644 --- a//AmazonCloudWatch/latest/monitoring/CloudWatch_Synthetics_Canaries_Create.md +++ b//AmazonCloudWatch/latest/monitoring/CloudWatch_Synthetics_Canaries_Create.md @@ -88,0 +89,4 @@ To use an existing role, you must have the `iam:PassRole` permission to pass tha +###### Note + +If role manager is enabled in your account, CloudWatch attaches the role for you, and the role options described here (for example the **Create new role** button) are replaced by a **Customize** option. To use a different role, choose **Customize**. For more information about IAM role creation, see [IAM role creation](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create.html) in the _IAM User Guide_. +