IAM role trust policy needs review

Specify who can assume the role and limit its separate permissions policy.

Description

An IAM role’s assume_role_policy is a trust policy defining who can assume the role. A separate permissions policy determines the AWS operations available afterward, so a trust policy should not be confused with a general full-access policy.

Specify trusted identities and the STS actions required for role assumption. A trust policy applies to the role it is attached to and does not specify Resource.

Potential impact

  • An invalid trust policy can prevent role creation or updates, or stop a required service from assuming the role.
  • Trusting unnecessary identities can let them use the role’s permissions and increase the impact of misuse.

Remediation

  • Set Principal to approved services, accounts or roles and allow only the STS actions needed by the authentication method.
  • Remove unsupported Resource elements from trust policies and minimize actual actions and resources in the separate role permissions policy.
  • Verify that required identities can assume the role and unapproved identities are denied after the change.

Examples

These are trust-policy excerpts for an EC2 service role. Actual EC2 use also requires an instance profile and attachment configuration; grant workload permissions through a separate policy.

Before

hcl
resource "aws_iam_role" "service_role" {
  name = "test_role"

  assume_role_policy = <<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": "*",
      "Principal": {
        "Service": "ec2.amazonaws.com"
      },
      "Effect": "Allow",
      "Resource": "*"
    }
  ]
}
EOF
}

This is an invalid trust-policy example containing an unsupported Resource element. It must not be interpreted as a valid policy granting EC2 all AWS operations.

After

hcl
resource "aws_iam_role" "service_role" {
  name = "test_role"

  assume_role_policy = <<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": "sts:AssumeRole",
      "Principal": {
        "Service": "ec2.amazonaws.com"
      },
      "Effect": "Allow"
    }
  ]
}
EOF
}

This permits sts:AssumeRole for the EC2 service and removes the unsupported Resource element. Review the role’s actual AWS permissions separately.

References