AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: Scope iam:PassRole with conditions in telemetry pipeline IAM examples

Service: AmazonCloudWatch · 2026-09-27 · Documentation high

File: AmazonCloudWatch/latest/monitoring/pipeline-iam-reference.md · Type: iam

Summary

Splits iam:PassRole out of the broad CreateTelemetryPipeline statement into dedicated statements (PassRoleForApiPullPipeline, PassRoleForS3Pipeline, PassRoleForLogsPipeline) that restrict the action to a specific role ARN and add StringEquals conditions on iam:PassedToService and iam:AssociatedResourceARN.

Security assessment

The change replaces an unscoped iam:PassRole with a least-privilege version constrained by iam:PassedToService and iam:AssociatedResourceARN conditions, reducing the risk of privilege escalation via role passing. This is IAM permission-scoping hardening guidance rather than a fix for a named vulnerability.

Evidence

+                        "iam:AssociatedResourceARN": [

Diff

diff --git a/AmazonCloudWatch/latest/monitoring/pipeline-iam-reference.md b/AmazonCloudWatch/latest/monitoring/pipeline-iam-reference.md
index 4640383c1..9c76af774 100644
--- a//AmazonCloudWatch/latest/monitoring/pipeline-iam-reference.md
+++ b//AmazonCloudWatch/latest/monitoring/pipeline-iam-reference.md
@@ -187,4 +187 @@ The following example shows all the IAM policies needed to create a third-party
-                "Action": [
-                    "observabilityadmin:CreateTelemetryPipeline",
-                    "iam:PassRole"
-                ],
+                "Action": "observabilityadmin:CreateTelemetryPipeline",
@@ -191,0 +189,16 @@ The following example shows all the IAM policies needed to create a third-party
+            },
+            {
+                "Sid": "PassRoleForApiPullPipeline",
+                "Effect": "Allow",
+                "Action": "iam:PassRole",
+                "Resource": "arn:aws:iam::111122223333:role/your-source-role",
+                "Condition": {
+                    "StringEquals": {
+                        "iam:PassedToService": [
+                            "telemetry-pipelines.observabilityadmin.amazonaws.com"
+                        ],
+                        "iam:AssociatedResourceARN": [
+                            "arn:aws:observabilityadmin:us-east-1:111122223333:telemetry-pipeline/*"
+                        ]
+                    }
+                }
@@ -313,4 +326 @@ The following example shows all the IAM policies needed to create an S3 delivery
-                "Action": [
-                    "observabilityadmin:CreateTelemetryPipeline",
-                    "iam:PassRole"
-                ],
+                "Action": "observabilityadmin:CreateTelemetryPipeline",
@@ -317,0 +328,16 @@ The following example shows all the IAM policies needed to create an S3 delivery
+            },
+            {
+                "Sid": "PassRoleForS3Pipeline",
+                "Effect": "Allow",
+                "Action": "iam:PassRole",
+                "Resource": "arn:aws:iam::111122223333:role/your-source-role",
+                "Condition": {
+                    "StringEquals": {
+                        "iam:PassedToService": [
+                            "telemetry-pipelines.observabilityadmin.amazonaws.com"
+                        ],
+                        "iam:AssociatedResourceARN": [
+                            "arn:aws:observabilityadmin:us-east-1:111122223333:telemetry-pipeline/*"
+                        ]
+                    }
+                }
@@ -473,2 +499 @@ The following example shows all the IAM policies needed to create a CloudWatch L
-                    "logs:DeletePipelineRule",
-                    "iam:PassRole"
+                    "logs:DeletePipelineRule"
@@ -476,0 +502,16 @@ The following example shows all the IAM policies needed to create a CloudWatch L
+            },
+            {
+                "Sid": "PassRoleForLogsPipeline",
+                "Effect": "Allow",
+                "Action": "iam:PassRole",
+                "Resource": "arn:aws:iam::111122223333:role/your-source-role",
+                "Condition": {
+                    "StringEquals": {
+                        "iam:PassedToService": [
+                            "logs.amazonaws.com"
+                        ],
+                        "iam:AssociatedResourceARN": [
+                            "arn:aws:observabilityadmin:us-east-1:111122223333:telemetry-pipeline/*"
+                        ]
+                    }
+                }