Description
An account root ARN in a role trust policy delegates role access to that account. It does not mean only its root user, or public access for every AWS account. A cross-account caller also needs permission to assume the role in its own account.
If account-wide delegation is unnecessary, narrow trust to the actual calling role. Where account delegation is required, document its purpose and conditions, and limit the role’s workload permissions in a separate policy.
Potential impact
- Unexpected role use can become possible if the trusted account grants calling permission to more identities than intended.
- Compromise of the external account or excessive role permissions can increase harm to delegated resources.
Remediation
- Specify a trusted role ARN, or verify why account-wide delegation is required and how permission is delegated within it.
- Allow only required STS actions and usage conditions, with additional controls appropriate to the cross-account integration.
- Review caller-side and workload permissions together, and verify intended role use and denial of unapproved access.
Examples
These excerpts narrow the trusted principal on the same role. Replace account and role ARNs and the name variable with actual values, and prepare the calling role first. Grant actual logging permissions through a separate policy.
Before
resource "aws_iam_role" "example" {
name = "${var.name_tag_prefix}-openshift-instance-forward-logs"
path = "/"
description = "Allows an instance to forward logs to CloudWatch"
assume_role_policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Principal": {
"AWS": "arn:aws:iam::111122223333:root"
},
"Effect": "Allow",
"Action": "sts:AssumeRole"
}
]
}
EOF
}
This delegates role access to a specific account. It does not by itself allow every identity, but the account’s delegation scope needs review.
After
resource "aws_iam_role" "example" {
name = "${var.name_tag_prefix}-openshift-instance-forward-logs"
path = "/"
description = "Allows an instance to forward logs to CloudWatch"
assume_role_policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Principal": {
"AWS": "arn:aws:iam::111122223333:role/log-forwarder"
},
"Effect": "Allow",
"Action": "sts:AssumeRole"
}
]
}
EOF
}
This trusts only the specified log-forwarder role on the same target role. Check the actual calling path and separate logging permissions.