AWS omics: Document session policies to scope down HealthOmics run permissions
Summary
Adds an example service role policy for publishing run metrics to CloudWatch and a new section on using inline IAM session policies with the StartRun API/DefaultRunSetting to scope down a run's effective permissions, including an example least-privilege session policy for S3 and CloudWatch Logs.
Security assessment
The added section documents an AWS authorization control that intersects a service role's permissions with a per-run inline session policy, explicitly recommending per-run restriction of sensitive resources (e.g., S3 prefixes) and noting session policies can only restrict, never expand, permissions. This is IAM least-privilege/authorization-scoping guidance with direct security impact.
Evidence
You can use session policies to further restrict the permissions granted by a service role for individual workflow runs. Session policies are inline IAM policies that you provide when starting a run. The effective permissions for the run are the intersection of the service role's permissions and the session policy.
Diff
diff --git a/omics/latest/dev/permissions-service.md b/omics/latest/dev/permissions-service.md index ccc7966a6..b29a9cb1a 100644 --- a//omics/latest/dev/permissions-service.md +++ b//omics/latest/dev/permissions-service.md @@ -7 +7 @@ -Example IAM service policiesExample CloudFormation template +Example IAM service policiesUse session policies to scope down permissionsExample CloudFormation template @@ -43,0 +44,2 @@ The trust policy allows the HealthOmics service to assume the role. + * Use session policies to scope down permissions + @@ -162,0 +165,66 @@ JSON +The following example shows the policy for a service role that publishes run metrics to CloudWatch. For more information, see [Run metrics for Private Workflows](./monitoring-run-metrics.html). + +###### Example Service role policy for run metrics + + + { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Action": "cloudwatch:PutMetricData", + "Resource": "*" + } + ] + } + +## Use session policies to scope down permissions + +You can use session policies to further restrict the permissions granted by a service role for individual workflow runs. Session policies are inline IAM policies that you provide when starting a run. The effective permissions for the run are the intersection of the service role's permissions and the session policy. + +Session policies are useful when you want to: + + * Grant temporary access to specific Amazon S3 buckets or objects for a single run + + * Restrict access to sensitive resources on a per-run basis + + * Apply additional security controls without modifying the service role + + + + +###### Important + +Session policies can only restrict permissions; they cannot grant permissions beyond what the service role already allows. The session policy must include permissions for Amazon CloudWatch Logs (`logs:CreateLogStream` and `logs:PutLogEvents`) because HealthOmics uses the run's credentials to create and write to log groups. + +Session policies have a maximum length of 2,048 characters and must be valid JSON documents. For more information about session policies, see [Session policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session) in the _IAM User Guide_. + +###### Example Session policy for a workflow run + +The following example shows a session policy that restricts a run to access only a specific Amazon S3 prefix for output and requires CloudWatch Logs permissions: + + + { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Action": [ + "s3:PutObject", + "s3:GetObject" + ], + "Resource": "arn:aws:s3:::my-bucket/workflow-outputs/run-123/*" + }, + { + "Effect": "Allow", + "Action": [ + "logs:CreateLogStream", + "logs:PutLogEvents" + ], + "Resource": "arn:aws:logs:*:*:log-group:/aws/omics/WorkflowLog:*" + } + ] + } + +You can specify a session policy when starting a run using the HealthOmics API. The `StartRun` API includes a `sessionPolicy` parameter where you provide the inline policy as a JSON string. For batch runs, you can specify a session policy in the `DefaultRunSetting` that applies to all runs in the batch. +