AWS omics: Add 'Trust the workflow owner' warning to cross-account sharing
Summary
Adds a security warning that accepting a shared workflow runs the owner's workflow definition and container images as third-party code in the subscriber's account under the specified IAM service role, recommending a least-privilege role and a session policy.
Security assessment
The new warning highlights a concrete risk (opaque owner-supplied workflow/container code executing in the subscriber account with the run's IAM role) and prescribes mitigations: least-privilege service roles and session policies. It is security hardening guidance rather than a fix for a specific vulnerability or incident.
Evidence
Make sure that you trust the workflow owner before you accept a share. When you run a shared workflow, the workflow definition and container images that the owner provided run in your AWS account. They run with the permissions of the IAM service role that you specify for the run.
Diff
diff --git a/omics/latest/dev/resource-sharing.md b/omics/latest/dev/resource-sharing.md index 9ae8b6b5f..454d0f571 100644 --- a//omics/latest/dev/resource-sharing.md +++ b//omics/latest/dev/resource-sharing.md @@ -18,0 +19,4 @@ Use cross-account sharing to share resources with collaborators without creating +###### Trust the workflow owner + +Make sure that you trust the workflow owner before you accept a share. When you run a shared workflow, the workflow definition and container images that the owner provided run in your AWS account. They run with the permissions of the IAM service role that you specify for the run. The contents of the workflow and its container images aren't visible to you. Running a shared workflow is equivalent to running third-party code in your account. Provide a least-privilege service role, and use a session policy to further restrict permissions for the run. For more information, see [Use session policies to scope down permissions](./permissions-service.html#permissions-service-sessionpolicy). +