Description
An account ARN such as arn:aws:iam::123456789012:root in a role trust policy delegates authority to that account; it does not mean only its root user. The account administrator can delegate access to users or roles with the required permissions. It does not unconditionally allow every AWS account or user to assume the role.
If only a particular role should be trusted, restrict trust to its ARN and appropriate conditions. IAM managed policies cannot use Principal, so distinguish permission policies from role trust policies.
Potential impact
- Account delegation broader than intended can allow additional identities to use the role as that account's permissions change.
- Excessive role permissions can increase the impact of mistaken delegation or credential misuse.
Remediation
- Determine whether account-level delegation is needed. If only a specific identity needs access, specify its approved role ARN in the trust policy's
Principal. - Review cross-account caller permissions and trust conditions together, and minimize the role's permissions. Account delegation is not inherently wrong; assess it against operational requirements.
- Remove unnecessary trust relationships and test successful legitimate assumptions and rejection of unapproved requests.
Examples
The first example is invalid because it places Principal in a managed policy. The second uses the correct policy type to trust a specific role. Replace the account and role ARN with approved values and configure caller and target-role permissions separately.
Before
- name: IAM 정책 생성
community.aws.iam_managed_policy:
policy_name: ManagedPolicy
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: logs:CreateLogGroup
Resource: "*"
Principal:
AWS: arn:aws:iam::123456789012:root
make_default: false
state: present
This configuration does not create valid role trust. The same account ARN, when used in a trust policy, delegates authority to that account.
After
- name: Configure trust for an approved role
amazon.aws.iam_role:
name: log-writer-target-role
assume_role_policy_document: >
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "sts:AssumeRole",
"Principal": {
"AWS": "arn:aws:iam::123456789012:role/log-writer-role"
}
}
]
}
state: present
This trust statement targets only the specified role. Review other trust statements and caller permissions as well.