AWS AmazonCloudWatch: Scope iam:PassRole with conditions in telemetry pipeline IAM examples
Summary
Splits iam:PassRole out of the broad CreateTelemetryPipeline statement into dedicated statements (PassRoleForApiPullPipeline, PassRoleForS3Pipeline, PassRoleForLogsPipeline) that restrict the action to a specific role ARN and add StringEquals conditions on iam:PassedToService and iam:AssociatedResourceARN.
Security assessment
The change replaces an unscoped iam:PassRole with a least-privilege version constrained by iam:PassedToService and iam:AssociatedResourceARN conditions, reducing the risk of privilege escalation via role passing. This is IAM permission-scoping hardening guidance rather than a fix for a named vulnerability.
Evidence
+ "iam:AssociatedResourceARN": [
Diff
diff --git a/AmazonCloudWatch/latest/monitoring/pipeline-iam-reference.md b/AmazonCloudWatch/latest/monitoring/pipeline-iam-reference.md index 4640383c1..9c76af774 100644 --- a//AmazonCloudWatch/latest/monitoring/pipeline-iam-reference.md +++ b//AmazonCloudWatch/latest/monitoring/pipeline-iam-reference.md @@ -187,4 +187 @@ The following example shows all the IAM policies needed to create a third-party - "Action": [ - "observabilityadmin:CreateTelemetryPipeline", - "iam:PassRole" - ], + "Action": "observabilityadmin:CreateTelemetryPipeline", @@ -191,0 +189,16 @@ The following example shows all the IAM policies needed to create a third-party + }, + { + "Sid": "PassRoleForApiPullPipeline", + "Effect": "Allow", + "Action": "iam:PassRole", + "Resource": "arn:aws:iam::111122223333:role/your-source-role", + "Condition": { + "StringEquals": { + "iam:PassedToService": [ + "telemetry-pipelines.observabilityadmin.amazonaws.com" + ], + "iam:AssociatedResourceARN": [ + "arn:aws:observabilityadmin:us-east-1:111122223333:telemetry-pipeline/*" + ] + } + } @@ -313,4 +326 @@ The following example shows all the IAM policies needed to create an S3 delivery - "Action": [ - "observabilityadmin:CreateTelemetryPipeline", - "iam:PassRole" - ], + "Action": "observabilityadmin:CreateTelemetryPipeline", @@ -317,0 +328,16 @@ The following example shows all the IAM policies needed to create an S3 delivery + }, + { + "Sid": "PassRoleForS3Pipeline", + "Effect": "Allow", + "Action": "iam:PassRole", + "Resource": "arn:aws:iam::111122223333:role/your-source-role", + "Condition": { + "StringEquals": { + "iam:PassedToService": [ + "telemetry-pipelines.observabilityadmin.amazonaws.com" + ], + "iam:AssociatedResourceARN": [ + "arn:aws:observabilityadmin:us-east-1:111122223333:telemetry-pipeline/*" + ] + } + } @@ -473,2 +499 @@ The following example shows all the IAM policies needed to create a CloudWatch L - "logs:DeletePipelineRule", - "iam:PassRole" + "logs:DeletePipelineRule" @@ -476,0 +502,16 @@ The following example shows all the IAM policies needed to create a CloudWatch L + }, + { + "Sid": "PassRoleForLogsPipeline", + "Effect": "Allow", + "Action": "iam:PassRole", + "Resource": "arn:aws:iam::111122223333:role/your-source-role", + "Condition": { + "StringEquals": { + "iam:PassedToService": [ + "logs.amazonaws.com" + ], + "iam:AssociatedResourceARN": [ + "arn:aws:observabilityadmin:us-east-1:111122223333:telemetry-pipeline/*" + ] + } + }