AWS odb: Oracle Database@AWS IAM managed policy docs: new policies and PassRole guidance
Summary
Adds documentation for four new AWS managed policies (AmazonODBAutonomousDatabaseAdmin, AmazonODBExadataVmClusterAdmin, AmazonODBExascaleStorageVaultAdmin, AmazonODBExascaleVmClusterAdmin), updates resource lists, and adds least-privilege guidance for iam:PassRole, secretsmanager:DescribeSecret, and customer-managed KMS encryption, including example scoped policies.
Security assessment
The change documents IAM managed policies and explicitly instructs users to scope iam:PassRole to specific role ARNs and constrain it with the iam:PassedToService condition, plus documents secretsmanager:DescribeSecret and KMS key permissions. This is least-privilege/hardening guidance rather than a fix for a specific vulnerability or incident, so it is security documentation with medium severity.
Evidence
* Permissions for the `iam:PassRole` action, which passes an IAM role to Oracle Database@AWS when you associate that role with a VM cluster. This use of `iam:PassRole` is separate from the one required for customer managed AWS Key Management Service encryption of an Autonomous Database Serverless resource. Scope it to the role ARNs that you choose, and constrain it with the `iam:PassedToService` condition set to `odb.amazonaws.com`. Without this action, requests to associate an IAM role fail. Disassociating an IAM role doesn't require this action. For the specific actions and an example policy, see IAM role association for VM cluster resources.
Diff
diff --git a/odb/latest/UserGuide/odb-security-iam-awsmanpol.md b/odb/latest/UserGuide/odb-security-iam-awsmanpol.md index 37c0bb3d5..20b613e15 100644 --- a//odb/latest/UserGuide/odb-security-iam-awsmanpol.md +++ b//odb/latest/UserGuide/odb-security-iam-awsmanpol.md @@ -7 +7 @@ -AWS managed policy: AmazonODBReadOnlyAccessAWS managed policy: AmazonODBFullAccessAWS managed policy: AmazonODBExadataInfrastructureAdminAWS managed policy: AmazonODBNetworkAdminAWS managed policy: AmazonODBAutonomousVmClusterAdminAWS managed policy: AmazonODBServiceRolePolicyAdditional permissions to add manually +AWS managed policy: AmazonODBReadOnlyAccessAWS managed policy: AmazonODBFullAccessAWS managed policy: AmazonODBExadataInfrastructureAdminAWS managed policy: AmazonODBNetworkAdminAWS managed policy: AmazonODBAutonomousVmClusterAdminAWS managed policy: AmazonODBAutonomousDatabaseAdminAWS managed policy: AmazonODBExadataVmClusterAdminAWS managed policy: AmazonODBExascaleStorageVaultAdminAWS managed policy: AmazonODBExascaleVmClusterAdminAWS managed policy: AmazonODBServiceRolePolicyAdditional permissions to add manually @@ -28,0 +29,8 @@ Additionally, AWS supports managed policies for job functions that span multiple + * AWS managed policy: AmazonODBAutonomousDatabaseAdmin + + * AWS managed policy: AmazonODBExadataVmClusterAdmin + + * AWS managed policy: AmazonODBExascaleStorageVaultAdmin + + * AWS managed policy: AmazonODBExascaleVmClusterAdmin + @@ -42 +50 @@ The policy includes permissions to: - * View all Oracle Database@AWS resources, including Exadata infrastructure, Cloud VM clusters, Autonomous VM clusters, Autonomous Databases and their backups, DB nodes, DB servers, ODB networks, and ODB peering connections + * View and list all Oracle Database@AWS resources, including Exadata infrastructure, Exadata VM cluster resources, Autonomous VM cluster resources, Exascale storage vault resources, Exascale VM cluster resources, Autonomous Databases and their backups, DB nodes, DB servers, ODB networks, and ODB peering connections @@ -46 +54 @@ The policy includes permissions to: - * List DB system shapes, Grid Infrastructure versions, system versions, Autonomous Database versions, and Autonomous Database character sets + * List DB system shapes, flex components, Grid Infrastructure versions, Grid Infrastructure minor versions, system versions, Autonomous Database versions, and Autonomous Database character sets @@ -65 +73,5 @@ The policy includes permissions to: - * Create, view, update, delete, and list all Oracle Database@AWS resources, including Exadata infrastructure, Cloud VM clusters, Autonomous VM clusters, Autonomous Databases and their backups, DB nodes, DB servers, ODB networks, and ODB peering connections + * Create, view, update, delete, and list all Oracle Database@AWS resources, including Exadata infrastructure, Exadata VM cluster resources, Autonomous VM cluster resources, Exascale storage vault resources, Exascale VM cluster resources, Autonomous Databases and their backups, DB nodes, DB servers, ODB networks, and ODB peering connections + + * Attach and detach virtual machines for Exascale VM cluster resources + + * Associate and disassociate IAM roles for VM cluster resources @@ -71 +83 @@ The policy includes permissions to: - * List DB system shapes, Grid Infrastructure versions, system versions, Autonomous Database versions, and Autonomous Database character sets + * List DB system shapes, flex components, Grid Infrastructure versions, Grid Infrastructure minor versions, system versions, Autonomous Database versions, and Autonomous Database character sets @@ -73 +85,5 @@ The policy includes permissions to: - * Manage resource policies and create outbound integrations + * Manage resource policies + + * Create and update outbound integrations + + * Create, update, and delete grant shares, which share Oracle Database@AWS entitlements with other AWS accounts through AWS License Manager @@ -79 +95 @@ The policy includes permissions to: - * Create, modify, and delete ODB network peering in Amazon EC2 (requires `aws:CalledVia` equal to `odb.amazonaws.com`) + * Create, modify, and delete ODB network peering in Amazon EC2 @@ -93,0 +110,6 @@ This policy lacks the following permissions. Add each through your own customer + * Permissions for the `iam:PassRole` action, which passes an IAM role to Oracle Database@AWS when you associate that role with a VM cluster. This use of `iam:PassRole` is separate from the one required for customer managed AWS Key Management Service encryption of an Autonomous Database Serverless resource. Scope it to the role ARNs that you choose, and constrain it with the `iam:PassedToService` condition set to `odb.amazonaws.com`. Without this action, requests to associate an IAM role fail. Disassociating an IAM role doesn't require this action. For the specific actions and an example policy, see IAM role association for VM cluster resources. + + * Permissions for the `iam:PassRole` action and for describing the AWS Key Management Service key. You need these actions when you update the encryption key on an existing Autonomous Database Serverless resource to use a customer managed AWS Key Management Service key. For the specific actions and an example policy, see Customer-managed KMS encryption for Autonomous Database Serverless. + + * Permissions for the `secretsmanager:DescribeSecret` action for the Autonomous Database Serverless AWS Secrets Manager integration. You need this action only when you supply a customer managed AWS Secrets Manager secret for an Autonomous Database Serverless admin password or wallet password. The integration also requires `iam:PassRole` for the role that you supply with the secret. For the specific actions and an example policy, see AWS Secrets Manager integration for Autonomous Database Serverless. + @@ -101 +123 @@ To view the permissions for this policy, see [AmazonODBFullAccess](https://docs. -You can attach the `AmazonODBExadataInfrastructureAdmin` policy to your IAM identities. With this policy attached, you can create and manage Oracle Exadata infrastructure resources. You can also list Cloud VM clusters and Autonomous VM clusters, which are visible in the Oracle Database@AWS console. +You can attach the `AmazonODBExadataInfrastructureAdmin` policy to your IAM identities. With this policy attached, you can create and manage Oracle Exadata infrastructure resources. You can also list Exadata VM clusters and Autonomous VM clusters, which are visible in the Oracle Database@AWS console. @@ -111 +133 @@ The policy includes permissions to: - * List Cloud VM clusters and Autonomous VM clusters + * List Exadata VM clusters and Autonomous VM clusters @@ -114,0 +137,2 @@ The policy includes permissions to: + * List flex components for Exadata infrastructure + @@ -146 +170 @@ The policy includes permissions to: - * Create, modify, and delete ODB network peering in Amazon EC2 (requires `aws:CalledVia` equal to `odb.amazonaws.com`) + * Create, modify, and delete ODB network peering in Amazon EC2 @@ -175,0 +200,2 @@ The policy includes permissions to: + * Associate and disassociate IAM roles for Autonomous VM cluster resources + @@ -192 +218 @@ The policy includes permissions to: - * Create outbound integrations for Autonomous VM cluster resources + * Create and update outbound integrations for Autonomous VM cluster resources @@ -199 +225 @@ This policy lacks the following permissions. Add each through your own customer - * Permissions for the `iam:PassRole` action, which passes the encryption role to Oracle Database@AWS. You need this action when you use a customer managed AWS Key Management Service key to encrypt an Autonomous VM cluster. Scope it to the specific role and constrain it with the `iam:PassedToService` condition set to `odb.amazonaws.com`. + * Permissions for the `iam:PassRole` action, which passes an IAM role to Oracle Database@AWS when you associate that role with an Autonomous VM cluster. Scope it to the role ARNs that you choose, and constrain it with the `iam:PassedToService` condition set to `odb.amazonaws.com`. Without this action, requests to associate an IAM role fail. Disassociating an IAM role doesn't require this action. For the specific actions and an example policy, see IAM role association for VM cluster resources. @@ -205,0 +232,161 @@ To view the permissions for this policy, see [AmazonODBAutonomousVmClusterAdmin] +## AWS managed policy: AmazonODBAutonomousDatabaseAdmin + +You can attach the `AmazonODBAutonomousDatabaseAdmin` policy to your IAM identities. With this policy attached, you can manage Autonomous Database Serverless resources and their backups. You can also view the ODB network resources that an Autonomous Database Serverless resource attaches to. + +The policy includes permissions to: + + * Initialize the Oracle Database@AWS service + + * Create, view, update, delete, and list Autonomous Databases, including their clones and peers + + * Manage the Autonomous Database lifecycle, including start, stop, reboot, shrink, switchover, failover, and restore + + * Create and retrieve Autonomous Database wallet details + + * Create, view, update, delete, and list Autonomous Database backups + + * View and list ODB network resources + + * List Autonomous Database versions and Autonomous Database character sets + + * List tags for Oracle Database@AWS resources + + * View Availability Zones + + * Create the service-linked role for Oracle Database@AWS + + * Tag and untag Autonomous Database and Autonomous Database backup resources + + * Create and update outbound integrations for Autonomous Database resources + + + + +This policy lacks the following permissions. Add each through your own customer managed policy: + + * Permissions for the `iam:PassRole` action and for describing the AWS Key Management Service key. You need these actions when you update the encryption key on an existing Autonomous Database Serverless resource to use a customer managed AWS Key Management Service key. For the specific actions and an example policy, see Customer-managed KMS encryption for Autonomous Database Serverless. + + * Permissions for the `secretsmanager:DescribeSecret` action for the Autonomous Database Serverless AWS Secrets Manager integration. You need this action only when you supply a customer managed AWS Secrets Manager secret for an Autonomous Database Serverless admin password or wallet password. The integration also requires `iam:PassRole` for the role that you supply with the secret. For the specific actions and an example policy, see AWS Secrets Manager integration for Autonomous Database Serverless. + + + + +To view the permissions for this policy, see [AmazonODBAutonomousDatabaseAdmin](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonODBAutonomousDatabaseAdmin.html) in the _AWS Managed Policy Reference Guide_. + +## AWS managed policy: AmazonODBExadataVmClusterAdmin + +You can attach the `AmazonODBExadataVmClusterAdmin` policy to your IAM identities. With this policy attached, you can manage Exadata VM cluster resources and their DB nodes. You can also view Exadata infrastructure and ODB network resources, which are required dependencies for Exadata VM cluster resources. + +The policy includes permissions to: + + * Initialize the Oracle Database@AWS service + + * View and list Exadata infrastructure resources and their unallocated resources + + * Create, view, delete, and list Exadata VM cluster resources + + * Associate and disassociate IAM roles for Exadata VM cluster resources + + * Create, view, reboot, start, stop, delete, and list DB nodes + + * View and list DB servers + + * View and list ODB network resources + + * List DB system shapes, flex components, Grid Infrastructure versions, and system versions + + * List tags for Oracle Database@AWS resources + + * View Availability Zones + + * Tag and untag Exadata VM cluster and DB node resources + + * Create and update outbound integrations for Exadata VM cluster resources + + + + +This policy lacks the following permissions. Add each through your own customer managed policy: + + * Permissions for the `iam:PassRole` action, which passes an IAM role to Oracle Database@AWS when you associate that role with an Exadata VM cluster. Scope it to the role ARNs that you choose, and constrain it with the `iam:PassedToService` condition set to `odb.amazonaws.com`. Without this action, requests to associate an IAM role fail. Disassociating an IAM role doesn't require this action. For the specific actions and an example policy, see IAM role association for VM cluster resources. + + + + +To view the permissions for this policy, see [AmazonODBExadataVmClusterAdmin](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonODBExadataVmClusterAdmin.html) in the _AWS Managed Policy Reference Guide_. + +## AWS managed policy: AmazonODBExascaleStorageVaultAdmin + +You can attach the `AmazonODBExascaleStorageVaultAdmin` policy to your IAM identities. With this policy attached, you can create and manage Exascale storage vault resources. You can also list Exascale VM cluster resources and view the DB servers that use an Exascale storage vault. + +The policy includes permissions to: + + * Initialize the Oracle Database@AWS service + + * Create, view, update, delete, and list Exascale storage vault resources + + * List Exascale VM cluster resources + + * View and list DB servers + + * List DB system shapes and flex components + + * Put, get, and delete resource policies + + * List tags for Oracle Database@AWS resources + + * View Availability Zones + + * Create the service-linked role for Oracle Database@AWS + + * Tag and untag Exascale storage vault resources + + + + +To view the permissions for this policy, see [AmazonODBExascaleStorageVaultAdmin](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonODBExascaleStorageVaultAdmin.html) in the _AWS Managed Policy Reference Guide_. + +## AWS managed policy: AmazonODBExascaleVmClusterAdmin + +You can attach the `AmazonODBExascaleVmClusterAdmin` policy to your IAM identities. With this policy attached, you can manage Exascale VM cluster resources and their DB nodes. You can also view the Exascale storage vault and ODB network resources that an Exascale VM cluster attaches to. + +The policy includes permissions to: + + * Initialize the Oracle Database@AWS service + + * View and list Exascale storage vault resources + + * Create, view, update, delete, and list Exascale VM cluster resources +