AWS omics: HealthOmics start-a-run: session policies and run metrics permissions
Summary
Adds 'Enable run metrics' to the page nav and a new 'Enable run metrics' section documenting that the run's service role needs cloudwatch:PutMetricData (with a sample policy using Resource "*"), and adds a note that session policies can be used to further restrict permissions for individual runs.
Security assessment
The changed service-role bullet explicitly documents using session policies to further restrict permissions for individual runs, a least-privilege hardening practice for the IAM role HealthOmics assumes. The new run-metrics section scopes an added service-role permission (cloudwatch:PutMetricData with Resource "*"), which is IAM permission guidance with security impact but documents no vulnerability or CVE fix.
Evidence
2. **Service role** – Specify an IAM service role that grants HealthOmics permissions to access the resources needed for the run. Optionally, the console can create the service role for you. You can also use session policies to further restrict permissions for individual runs. For more information, see [Service roles for AWS HealthOmics](./permissions-service.html).
Diff
diff --git a/omics/latest/dev/starting-a-run.md b/omics/latest/dev/starting-a-run.md index f115395af..8489f699e 100644 --- a//omics/latest/dev/starting-a-run.md +++ b//omics/latest/dev/starting-a-run.md @@ -7 +7 @@ -Starting a run using the consoleStarting a run using the APISpecify Nextflow engine settingsVPC networking +Starting a run using the consoleStarting a run using the APISpecify Nextflow engine settingsVPC networkingEnable run metrics @@ -15 +15 @@ When you start a run, you specify the resources that HealthOmics allocates for t - 2. **Service role** – Specify an IAM service role that grants HealthOmics permissions to access the resources needed for the run. Optionally, the console can create the service role for you. For more information, see [Service roles for AWS HealthOmics](./permissions-service.html). + 2. **Service role** – Specify an IAM service role that grants HealthOmics permissions to access the resources needed for the run. Optionally, the console can create the service role for you. You can also use session policies to further restrict permissions for individual runs. For more information, see [Service roles for AWS HealthOmics](./permissions-service.html). @@ -41,0 +42,2 @@ When you start a run, you specify the resources that HealthOmics allocates for t + * Enable run metrics + @@ -323,0 +326,18 @@ For more information, see [Connecting HealthOmics workflows to a VPC](./workflow +## Enable run metrics + +Run metrics report near real-time resource utilization for a run. To enable run metrics, the service role that you use for the run must have the `cloudwatch:PutMetricData` permission. For more information, see [Run metrics for Private Workflows](./monitoring-run-metrics.html). + +Add the following permission to the service role that you use for the run. + + + { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Action": "cloudwatch:PutMetricData", + "Resource": "*" + } + ] + } +