AWS deadline-cloud: Document CloudWatch Logs and KMS permissions for Deadline Cloud fleet roles
Summary
Restructures the fleet role IAM guidance: adds a required CloudWatch Logs policy (logs:CreateLogStream with aws:CalledVia, logs:PutLogEvents, logs:GetLogEvents), explains that workers fail with AccessDeniedException without logs:CreateLogStream, moves the KMS permissions section, and changes the kms:ViaService example value from deadline.REGION.amazonaws.com to deadline.amazonaws.com.
Security assessment
The change documents least-privilege IAM permissions for fleet service roles, including a condition (aws:CalledVia) that scopes log-stream creation to calls made through the Deadline Cloud service, and clarifies the kms:ViaService condition format for encrypted farms. This is security best-practice documentation rather than a fix for a specific vulnerability; the example value edit (deadline.amazonaws.com) is a doc consistency change.
Evidence
+Every fleet role needs two policies: the `AWSDeadlineCloud-FleetWorker` managed policy for Deadline Cloud API operations, and a policy you create that grants access to the fleet's CloudWatch Logs log group. Workers can't start until the fleet role has both.
Diff
diff --git a/deadline-cloud/latest/userguide/security-iam-service-roles.md b/deadline-cloud/latest/userguide/security-iam-service-roles.md index 1a1b6bfce..56bb02f98 100644 --- a//deadline-cloud/latest/userguide/security-iam-service-roles.md +++ b//deadline-cloud/latest/userguide/security-iam-service-roles.md @@ -84,0 +85,2 @@ As a best practice, the trust policy should include security conditions for Conf +Every fleet role needs two policies: the `AWSDeadlineCloud-FleetWorker` managed policy for Deadline Cloud API operations, and a policy you create that grants access to the fleet's CloudWatch Logs log group. Workers can't start until the fleet role has both. + @@ -104,7 +106 @@ This managed policy provides permissions for: -### Add KMS permissions for encrypted farms - -If your farm was created using a KMS key, add these permissions to your fleet role to ensure the worker can access encrypted data in the farm. - -The KMS permissions are only necessary if your farm has an associated KMS key. The `kms:ViaService` condition must use the format `deadline.`{region}`.amazonaws.com`. - -When creating a fleet, a CloudWatch Logs log group is created for that fleet. The worker's permissions are used by the Deadline Cloud service to create a log stream specifically for that particular worker. After the worker is set up and running, the worker will use these permissions to send log events directly to CloudWatch Logs. +The managed policy doesn't include CloudWatch Logs permissions because they're scoped to the log groups in your farm. Add the following policy to your fleet role as well. When you create a fleet, Deadline Cloud creates a CloudWatch Logs log group for it. When a worker starts, Deadline Cloud uses the fleet role to create a log stream for that worker, so the `logs:CreateLogStream` statement uses the `aws:CalledVia` condition to allow the call only when it comes through the Deadline Cloud service. After the worker is running, it uses `logs:PutLogEvents` to send its log events directly to CloudWatch Logs, and the Deadline Cloud monitor uses `logs:GetLogEvents` to read them. @@ -126 +122 @@ When creating a fleet, a CloudWatch Logs log group is created for that fleet. Th - "deadline.REGION.amazonaws.com" + "deadline.amazonaws.com" @@ -139 +135,16 @@ When creating a fleet, a CloudWatch Logs log group is created for that fleet. Th - }, + } + ] + } + +If the fleet role is missing `logs:CreateLogStream`, Deadline Cloud can't create the worker's log stream and the worker fails to start with an `AccessDeniedException`. On a service-managed fleet, the workers that Deadline Cloud launches can't start, so the fleet stays unhealthy until you add the permission. + +### Add KMS permissions for encrypted farms + +If your farm was created using a KMS key, also add these permissions to your fleet role so the worker can access encrypted data in the farm. + +The KMS permissions are only necessary if your farm has an associated KMS key. The `kms:ViaService` condition must use the format `deadline.`{region}`.amazonaws.com`. + + + { + "Version": "2012-10-17", + "Statement": [