그룹에 속하지 않은 IAM 사용자

사용자 권한을 공통 업무 기준으로 관리할 수 있는지 확인하세요.

설명

IAM 사용자가 그룹에 속하지 않으면 사용자별로 권한을 따로 관리하게 될 수 있습니다. 그룹이 없다는 사실만으로 권한이 부여되거나 계정이 공개되는 것은 아닙니다.

잠재적 영향

개별 예외가 늘어나면 권한 검토와 회수 시 누락이 생길 수 있습니다.

해결 방법

공통 권한이 필요한 사용자는 적절한 Groups에 포함하고 그룹 정책과 멤버십을 함께 검토하세요. 불필요한 그룹 권한을 추가하지 마세요.

예시

그룹 멤버십을 추가하는 발췌입니다. QAGroup, myqueue와 ConsolePassword 시크릿의 password 값은 별도로 준비하며, 예시에 남은 직접 정책도 이전 필요성을 검토하세요.

변경 전

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: 그룹 멤버십 비교 예시
Resources:
    MyUser:
      Type: AWS::IAM::User
      Properties:
        Path: "/"
        LoginProfile:
          Password: '{{resolve:secretsmanager:ConsolePassword:SecretString:password}}'
        Policies:
        - PolicyName: giveaccesstoqueueonly
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
            - Effect: Allow
              Action:
              - sqs:*
              Resource:
              - !GetAtt myqueue.Arn
            - Effect: Deny
              Action:
              - sqs:*
              NotResource:
              - !GetAtt myqueue.Arn
        Tags:
          - Key: Name
            Value: QAUser
        UserName: TestUser

변경 후

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: 그룹 멤버십 비교 예시
Resources:
  addUserToGroup2:
    Type: AWS::IAM::User
    Properties:
      Groups:
        - QAGroup
      LoginProfile:
          Password: '{{resolve:secretsmanager:ConsolePassword:SecretString:password}}'
      Path: "/"
      Policies:
        - PolicyName: giveaccesstoqueueonly
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
            - Effect: Allow
              Action:
              - sqs:*
              Resource:
              - !GetAtt myqueue.Arn
            - Effect: Deny
              Action:
              - sqs:*
              NotResource:
              - !GetAtt myqueue.Arn
      Tags:
        - Key: Name
          Value: QAUser
      UserName: TestUser

참조