AWS omics: Batch workflows: session policy mention and run metrics IAM permission
Summary
Adds 'session policy' to the list of parameters in defaultRunSetting, and adds an 'Enable run metrics' section documenting that the batch service role needs cloudwatch:PutMetricData, including a sample IAM policy.
Security assessment
The change documents an IAM permission (cloudwatch:PutMetricData) required by the batch service role and mentions session policies, which are access-control constructs. It is permission/monitoring guidance rather than a fix for a specific vulnerability; the sample policy uses Resource "*", so it is hardening guidance of medium impact.
Evidence
+Run metrics report near real-time resource utilization for the runs in a batch. To enable run metrics, the service role that you use for the batch must have the `cloudwatch:PutMetricData` permission. For more information, see [Run metrics for Private Workflows](./monitoring-run-metrics.html).
Diff
diff --git a/omics/latest/dev/workflows-batch.md b/omics/latest/dev/workflows-batch.md index 05262e335..d76355470 100644 --- a//omics/latest/dev/workflows-batch.md +++ b//omics/latest/dev/workflows-batch.md @@ -63 +63 @@ With batch runs, you can: - * **Default run setting** (`defaultRunSetting`) — Workflow parameters shared across all runs in the batch, such as workflow ID, IAM role, output URI, and common parameters. + * **Default run setting** (`defaultRunSetting`) — Workflow parameters shared across all runs in the batch, such as workflow ID, IAM role, output URI, session policy, and common parameters. @@ -694,0 +695,18 @@ Filter | Description +### Enable run metrics + +Run metrics report near real-time resource utilization for the runs in a batch. To enable run metrics, the service role that you use for the batch must have the `cloudwatch:PutMetricData` permission. For more information, see [Run metrics for Private Workflows](./monitoring-run-metrics.html). + +Add the following permission to the service role that you use for the batch. + + + { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Action": "cloudwatch:PutMetricData", + "Resource": "*" + } + ] + } +