IAM group has excessive glue:UpdateDevEndpoint permissions

Limit permission to modify Glue development endpoints.

Description

glue:UpdateDevEndpoint can change a development endpoint’s public keys and libraries. A group member who gains control of an accessible endpoint can perform work with its attached role’s permissions.

Potential impact

A powerful endpoint role can give group members access to more data and resources than intended.

Remediation

Remove unnecessary update permission or limit it to approved development endpoints. Give the endpoint role only the permissions it needs.

Examples

The examples restrict the same group to EC2 describe actions. Choose permissions for the actual workload and review other attached policies too.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "glue:UpdateDevEndpoint",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name = "inline_policy_run_instances"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

References