IAM service-role trust principals need review

Trust only the actual services and approved AWS principals that need the role.

Description

An IAM role trust policy determines who can assume the role. Allowing AWS: * alongside a required service does not restrict trust to that service.

Actual role assumption also depends on caller permissions and trust conditions. Permissions available after assumption depend on the role’s permission policies and other limits.

Potential impact

  • Unnecessary principals that assume a role can access the resources permitted to that role.
  • Broad trust in a powerful role can increase the impact of credential misuse.

Remediation

  • Remove unnecessary AWS wildcard principals and retain only the actual service principals required by a service role.
  • If external-account access is needed, restrict it to approved accounts or roles and trust conditions appropriate to the purpose.
  • Review role permissions and trust changes together, and verify intended service operation and denial of unapproved role assumption.

Examples

These excerpts show an EC2 instance role’s trust policy. Configure the name_tag_prefix variable, instance profile and role permissions separately.

Before

hcl
resource "aws_iam_role" "example" {
  name = "${var.name_tag_prefix}-openshift-instance-role"

  assume_role_policy = <<EOF
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Action": "sts:AssumeRole",
            "Principal": {
                "Service": "ec2.amazonaws.com",
                "AWS": "*"
            },
            "Effect": "Allow",
            "Sid": ""
        }
    ]
}
EOF
}

This extends trust to all AWS principals in addition to EC2. The Service entry does not restrict AWS: * to EC2.

After

hcl
resource "aws_iam_role" "example" {
  name = "${var.name_tag_prefix}-openshift-instance-role"

  assume_role_policy = <<EOF
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Action": "sts:AssumeRole",
            "Principal": {
                "Service": "ec2.amazonaws.com"
            },
            "Effect": "Allow",
            "Sid": ""
        }
    ]
}
EOF
}

This limits the trust principal to the EC2 service. Also minimize the role’s action permissions and permission to attach it to an instance.

References