Description
A wildcard Principal in a role trust policy can include identities that were not intended to be trusted. Actual role assumption also depends on actions, conditions and caller permissions, so review the complete trust relationship.
IAM managed policies cannot contain Principal. A managed policy defines permissions for the identity it is attached to; a role trust policy defines who may assume the role. Distinguish service permissions from trust for sts:AssumeRole.
Potential impact
- Broad trust combined with the required caller permissions can let unintended identities use the role's permissions.
- A principal in the wrong policy type can cause deployment to fail, leaving intended access controls unapplied.
Remediation
- Check the policy type and limit role assumption to approved role ARNs or service principals in the role's trust policy.
- For cross-account access, review both caller permissions and trust conditions. For third parties acting for multiple customers, use the customer-specific external ID managed by the actual provider.
- Minimize the role's own permissions and test legitimate assumptions and rejection of unapproved requests.
Examples
The first example incorrectly puts Principal in a managed policy. The second configures EC2 role trust; role permissions and instance-profile association are omitted. Review the complete trust and permission configuration before changing an existing role.
Before
- name: IAM 정책 생성
community.aws.iam_managed_policy:
policy_name: ManagedPolicy
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: logs:CreateLogGroup
Resource: "*"
Principal:
Service: ec2.amazonaws.com
AWS: "*"
make_default: false
state: present
This managed policy is invalid, and logs:CreateLogGroup is not a role-assumption action. This configuration does not establish role trust.
After
- name: Configure EC2 role trust
amazon.aws.iam_role:
name: ec2-service-role
assume_role_policy_document: >
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "sts:AssumeRole",
"Principal": {"Service": "ec2.amazonaws.com"}
}
]
}
state: present
This limits role trust to the EC2 service. Separately grant only the permissions needed by the actual EC2 workload.