Description
An IAM role’s assume_role_policy is a trust policy defining who can assume the role. A separate permissions policy determines the AWS operations available afterward, so a trust policy should not be confused with a general full-access policy.
Specify trusted identities and the STS actions required for role assumption. A trust policy applies to the role it is attached to and does not specify Resource.
Potential impact
- An invalid trust policy can prevent role creation or updates, or stop a required service from assuming the role.
- Trusting unnecessary identities can let them use the role’s permissions and increase the impact of misuse.
Remediation
- Set Principal to approved services, accounts or roles and allow only the STS actions needed by the authentication method.
- Remove unsupported Resource elements from trust policies and minimize actual actions and resources in the separate role permissions policy.
- Verify that required identities can assume the role and unapproved identities are denied after the change.
Examples
These are trust-policy excerpts for an EC2 service role. Actual EC2 use also requires an instance profile and attachment configuration; grant workload permissions through a separate policy.
Before
resource "aws_iam_role" "service_role" {
name = "test_role"
assume_role_policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "*",
"Principal": {
"Service": "ec2.amazonaws.com"
},
"Effect": "Allow",
"Resource": "*"
}
]
}
EOF
}
This is an invalid trust-policy example containing an unsupported Resource element. It must not be interpreted as a valid policy granting EC2 all AWS operations.
After
resource "aws_iam_role" "service_role" {
name = "test_role"
assume_role_policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "sts:AssumeRole",
"Principal": {
"Service": "ec2.amazonaws.com"
},
"Effect": "Allow"
}
]
}
EOF
}
This permits sts:AssumeRole for the EC2 service and removes the unsupported Resource element. Review the role’s actual AWS permissions separately.