AWS deadline-cloud: Clarify Deadline Cloud fleet role CloudWatch Logs and KMS permissions
Summary
Reworks the fleet-role IAM section: states every fleet role needs both the AWSDeadlineCloud-FleetWorker managed policy and a policy granting access to the fleet's CloudWatch Logs log group, explains the aws:CalledVia condition on logs:CreateLogStream and least-privilege scoping of logs permissions, notes the AccessDeniedException/fleet-unhealthy failure mode when logs:CreateLogStream is missing, and relocates the KMS permissions section. Also changes the kms:ViaService example value from 'deadline.REGION.amazonaws.com' to 'deadline.amazonaws.com'.
Security assessment
The change documents IAM policy requirements for Deadline Cloud fleet roles, including least-privilege scoping of CloudWatch Logs permissions to farm log groups and the aws:CalledVia condition restricting logs:CreateLogStream to calls made through the Deadline Cloud service. This is security guidance/hardening for service roles rather than a fix for a specific vulnerability or incident (no CVE, no disclosure of an exploited weakness), so it is documented security content but not incident-related.
Evidence
+The managed policy doesn't include CloudWatch Logs permissions because they're scoped to the log groups in your farm. Add the following policy to your fleet role as well. When you create a fleet, Deadline Cloud creates a CloudWatch Logs log group for it. When a worker starts, Deadline Cloud uses the fleet role to create a log stream for that worker, so the `logs:CreateLogStream` statement uses the `aws:CalledVia` condition to allow the call only when it comes through the Deadline Cloud service. After the worker is running, it uses `logs:PutLogEvents` to send its log events directly to CloudWatch Logs, and the Deadline Cloud monitor uses `logs:GetLogEvents` to read them.
Diff
diff --git a/deadline-cloud/latest/developerguide/security-iam-service-roles.md b/deadline-cloud/latest/developerguide/security-iam-service-roles.md index 334068be5..4d2aa4380 100644 --- a//deadline-cloud/latest/developerguide/security-iam-service-roles.md +++ b//deadline-cloud/latest/developerguide/security-iam-service-roles.md @@ -84,0 +85,2 @@ As a best practice, the trust policy should include security conditions for Conf +Every fleet role needs two policies: the `AWSDeadlineCloud-FleetWorker` managed policy for Deadline Cloud API operations, and a policy you create that grants access to the fleet's CloudWatch Logs log group. Workers can't start until the fleet role has both. + @@ -104,7 +106 @@ This managed policy provides permissions for: -### Add KMS permissions for encrypted farms - -If your farm was created using a KMS key, add these permissions to your fleet role to ensure the worker can access encrypted data in the farm. - -The KMS permissions are only necessary if your farm has an associated KMS key. The `kms:ViaService` condition must use the format `deadline.`{region}`.amazonaws.com`. - -When creating a fleet, a CloudWatch Logs log group is created for that fleet. The worker's permissions are used by the Deadline Cloud service to create a log stream specifically for that particular worker. After the worker is set up and running, the worker will use these permissions to send log events directly to CloudWatch Logs. +The managed policy doesn't include CloudWatch Logs permissions because they're scoped to the log groups in your farm. Add the following policy to your fleet role as well. When you create a fleet, Deadline Cloud creates a CloudWatch Logs log group for it. When a worker starts, Deadline Cloud uses the fleet role to create a log stream for that worker, so the `logs:CreateLogStream` statement uses the `aws:CalledVia` condition to allow the call only when it comes through the Deadline Cloud service. After the worker is running, it uses `logs:PutLogEvents` to send its log events directly to CloudWatch Logs, and the Deadline Cloud monitor uses `logs:GetLogEvents` to read them. @@ -126 +122 @@ When creating a fleet, a CloudWatch Logs log group is created for that fleet. Th - "deadline.REGION.amazonaws.com" + "deadline.amazonaws.com" @@ -139 +135,16 @@ When creating a fleet, a CloudWatch Logs log group is created for that fleet. Th - }, + } + ] + } + +If the fleet role is missing `logs:CreateLogStream`, Deadline Cloud can't create the worker's log stream and the worker fails to start with an `AccessDeniedException`. On a service-managed fleet, the workers that Deadline Cloud launches can't start, so the fleet stays unhealthy until you add the permission. + +### Add KMS permissions for encrypted farms + +If your farm was created using a KMS key, also add these permissions to your fleet role so the worker can access encrypted data in the farm. + +The KMS permissions are only necessary if your farm has an associated KMS key. The `kms:ViaService` condition must use the format `deadline.`{region}`.amazonaws.com`. + + + { + "Version": "2012-10-17", + "Statement": [