AWS AmazonCloudWatch: Document safe reuse of existing IAM role for CloudWatch agent
Summary
Adds a 'Reusing an existing IAM role' section explaining that the AWS trust step merges Azure/OIDC trust into an existing role's trust policy rather than replacing it, attaches CloudWatchAgentServerPolicy only if absent, and leaves other policies unchanged; also adds CWAGENT_AWS_ROLE_ARN example and backtick formatting.
Security assessment
The added text documents IAM trust-policy and policy-attachment behavior, reassuring users that existing trust statements and policies are preserved (non-destructive, least-privilege-preserving). It is security-relevant guidance about IAM role trust handling but does not fix a specific vulnerability.
Evidence
+Both scripts are safe to run even if the IAM role already exists. The AWS trust step merges the Azure trust into the role's existing trust policy instead of replacing it, so other trust statements remain. It attaches `CloudWatchAgentServerPolicy` only if the role doesn't already have it, and leaves the role's other policies unchanged.
Diff
diff --git a/AmazonCloudWatch/latest/monitoring/install-CloudWatch-Agent-on-Azure.md b/AmazonCloudWatch/latest/monitoring/install-CloudWatch-Agent-on-Azure.md index 66ffd2159..fc7eec4e5 100644 --- a//AmazonCloudWatch/latest/monitoring/install-CloudWatch-Agent-on-Azure.md +++ b//AmazonCloudWatch/latest/monitoring/install-CloudWatch-Agent-on-Azure.md @@ -55,0 +56,4 @@ Run the Azure step first, then the AWS trust step. Provide the role ARN that the +###### Reusing an existing IAM role + +Both scripts are safe to run even if the IAM role already exists. The AWS trust step merges the Azure trust into the role's existing trust policy instead of replacing it, so other trust statements remain. It attaches `CloudWatchAgentServerPolicy` only if the role doesn't already have it, and leaves the role's other policies unchanged. + @@ -67 +71 @@ Run the Azure step first, then the AWS trust step. Provide the role ARN that the - 2. On a machine with AWS credentials that have IAM write access to the target account (for example, AWS CloudShell), run the AWS trust step with the tenant ID from the previous step. The script creates the role, attaches CloudWatchAgentServerPolicy, and adds the Azure web-identity trust. + 2. On a machine with AWS credentials that have IAM write access to the target account (for example, AWS CloudShell), run the AWS trust step with the tenant ID from the previous step. The script creates the role, attaches `CloudWatchAgentServerPolicy`, and adds the Azure web-identity trust. @@ -71,0 +76 @@ Run the Azure step first, then the AWS trust step. Provide the role ARN that the + CWAGENT_AWS_ROLE_ARN=role-arn \ @@ -153,0 +159,4 @@ Run the Azure step first, then the AWS trust step. The AWS trust step needs the +###### Reusing an existing IAM role + +Both scripts are safe to run even if the IAM role already exists. The AWS trust step merges the Azure trust into the role's existing trust policy instead of replacing it, so other trust statements remain. It attaches `CloudWatchAgentServerPolicy` only if the role doesn't already have it, and leaves the role's other policies unchanged. + @@ -165 +174 @@ Run the Azure step first, then the AWS trust step. The AWS trust step needs the - 2. On a machine with AWS credentials that have IAM write access to the target account (for example, AWS CloudShell), run the AWS trust step with the OIDC issuer URL from the previous step. The script creates the role, attaches CloudWatchAgentServerPolicy, and federates the cluster issuer. + 2. On a machine with AWS credentials that have IAM write access to the target account (for example, AWS CloudShell), run the AWS trust step with the OIDC issuer URL from the previous step. The script creates the role, attaches `CloudWatchAgentServerPolicy`, and federates the cluster issuer. @@ -169,0 +179 @@ Run the Azure step first, then the AWS trust step. The AWS trust step needs the + CWAGENT_AWS_ROLE_ARN=role-arn \