Description
An IAM policy allowing Action: * on all resources can grant very broad permissions across services. iam:* covers IAM administration and can enable permission escalation if misused, but is not itself every AWS service action.
Explicit denies, permissions boundaries and organization policies can also limit effective permissions.
Potential impact
- Misused excessive permissions can cause resource changes, deletion or information disclosure.
- Abuse of IAM administration can expand an incident by changing trusted identities or policies.
Remediation
- Replace all-action grants with the operations required by the workload.
- Scope actions supporting resource-level permissions to required ARNs, and separate actions that require Resource: * into their own statements.
- Manage administrative access through approved separate roles, and verify intended operations and denial of unapproved actions after changes.
Examples
These excerpts narrow an inline policy on the same role to log-stream writes. Prepare the role and log group separately and replace the ARN’s Region, account and group name. Review the complete API Gateway logging configuration separately.
Before
resource "aws_iam_role_policy" "example" {
name = "apigateway-cloudwatch-logging"
role = aws_iam_role.apigateway_cloudwatch_logging.id
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["*"],
"Resource": "*"
}
]
}
EOF
}
This adds a broad grant for all actions and resources. Reduce unnecessary permissions even when other controls also apply.
After
resource "aws_iam_role_policy" "example" {
name = "apigateway-cloudwatch-logging"
role = aws_iam_role.apigateway_cloudwatch_logging.id
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["logs:CreateLogStream", "logs:PutLogEvents"],
"Resource": "arn:aws:logs:us-east-1:111122223333:log-group:/aws/apigateway/example:log-stream:*"
}
]
}
EOF
}
This permits only stream creation and event writes in the specified log group. Review any additional log-query or configuration permissions separately.