AWS mgn: Update MGN connector IAM policy examples and trust policy condition
Summary
Replaces placeholder tokens with concrete example values and changes the trust relationship condition operator from StringLike to ArnLike for aws:SourceArn.
Security assessment
The trust policy condition for aws:SourceArn is corrected from StringLike to ArnLike, which is the appropriate operator for ARN matching and tightens the cross-account assume-role condition; this is IAM hardening guidance rather than a specific vulnerability fix.
Evidence
+ "ArnLike": {
Diff
diff --git a/mgn/latest/ug/create-permissions-console.md b/mgn/latest/ug/create-permissions-console.md index 53d9850c4..4cf714d1b 100644 --- a//mgn/latest/ug/create-permissions-console.md +++ b//mgn/latest/ug/create-permissions-console.md @@ -85 +85 @@ The following policies are attached to the role: -The **MgnConnectorPolicy** inline policy contains the following permissions, where _ACCOUNT-ID_ is the account in which the role is created and _AWS_REGION_ is the Region in which you added the connector: +The **MgnConnectorPolicy** inline policy contains the following permissions. In the example, replace `111122223333` with the ID of the account in which the role is created, and `us-east-1` with the Region in which you added the connector: @@ -94 +94 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe - "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:*" + "Resource": "arn:aws:mgn:us-east-1:111122223333:*" @@ -99 +99 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe - "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:connector/*", + "Resource": "arn:aws:mgn:us-east-1:111122223333:connector/*", @@ -109 +109 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe - "Resource": "arn:aws:iam::*:role/AWSApplicationMigrationConnectorSharingRole_ACCOUNT-ID" + "Resource": "arn:aws:iam::*:role/AWSApplicationMigrationConnectorSharingRole_111122223333" @@ -114 +114 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe - "Resource": "arn:aws:secretsmanager:AWS_REGION:ACCOUNT-ID:secret:*", + "Resource": "arn:aws:secretsmanager:us-east-1:111122223333:secret:*", @@ -125,2 +125,2 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe - "arn:aws:s3:::aws-application-migration-service-AWS_REGION/latest/source-automation-client/linux/ssaf-client/ssaf_client", - "arn:aws:s3:::amazon-ssm-AWS_REGION/*" + "arn:aws:s3:::aws-application-migration-service-us-east-1/latest/source-automation-client/linux/ssaf-client/ssaf_client", + "arn:aws:s3:::amazon-ssm-us-east-1/*" @@ -139,2 +139,2 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe - "arn:aws:logs:AWS_REGION:ACCOUNT-ID:log-group:/aws/ssm/*", - "arn:aws:logs:AWS_REGION:ACCOUNT-ID:log-stream:*" + "arn:aws:logs:us-east-1:111122223333:log-group:/aws/ssm/*", + "arn:aws:logs:us-east-1:111122223333:log-stream:*" @@ -185 +185 @@ The role is created with the following trust relationship, where _management-acc - "aws:SourceAccount": "management-account-id" + "aws:SourceAccount": "111122223333" @@ -187,2 +187,2 @@ The role is created with the following trust relationship, where _management-acc - "StringLike": { - "aws:SourceArn": "arn:aws:mgn:*:management-account-id:*" + "ArnLike": { + "aws:SourceArn": "arn:aws:mgn:*:111122223333:*" @@ -195 +195 @@ The role is created with the following trust relationship, where _management-acc - "AWS": "arn:aws:iam::management-account-id:role/AWSApplicationMigrationConnectorManagementRole" + "AWS": "arn:aws:iam::111122223333:role/AWSApplicationMigrationConnectorManagementRole"