4 ms·
Be careful with SSM in general. The documentation suggests adding the AmazonEC2RoleforSSM policy to the role of the EC2 instances you want to access via Session
by mishappen 7y ago
Be careful with SSM in general. The documentation suggests adding the AmazonEC2RoleforSSM policy to the role of the EC2 instances you want to access via Session Manager. This role grants read/write to all S3 buckets in your account (amongst other things). See this article for better steps and unavoidable risky things: https://cloudonaut.io/aws-ssm-is-a-trojan-horse-fix-it-now/ https://cloudonaut.io/aws-ssm-is-a-trojan-horse-fix-it-now/
- jon918 7y agoGood call to watch out for this stuff. The examples in the repo we set up use the AmazonSSMManagedInstanceCore managed policy, which does not grant any S3 permissions, just various ssm, ssmmessages, and ec2messages permissions.
- jcrites 7y ago> The documentation suggests adding the AmazonEC2RoleforSSM policy to the role of the EC2 instances Which documentation do you mean? The article mentions the policy AmazonSSMManagedInstanceCore, which is the same as what's mentioned in the SSM setup guide: https://docs.aws.amazon.com/systems-manager/latest/userguide/setup-instance-profile.html https://docs.aws.amazon.com/systems-manager/latest/userguide...
- x3n0ph3n3 7y agoAmazonSSMManagedInstanceCore is still too much access, it has unscoped ssm:GetParameter! I hope you weren't trying to protect any secrets in ParameterStore!
- acdha 7y agoDoesn’t that still fail if you don’t also have the corresponding decrypt KMS permission?
- mishappen 7y agoThanks for clarifying, I didn’t recheck since we rolled out SSM in mid-2019 and then scrambled when we realised we’d granted account wide S3 permissions. The article I linked to also has a recommended minimal IAM policy for Run Command and SSM. I’ll update my comment to mention this.
- mishappen 7y agoIt looks like the docs were update in June 2019 (https://github.com/awsdocs/aws-systems-manager-user-guide/commit/cad52f970cb1e00e8127fcc417dac196d5d402d5#diff-38461af5d055b906d0f68f62eb38e62a https://github.com/awsdocs/aws-systems-manager-user-guide/co...)
- NikolaeVarius 7y agoThis has not been true for a while. The IAM policy also indicates it is deprecated in the description. Though I always suggest to read what managed profiles are doing. Many of them are very permissive
- WatchDog 7y agoThere are so many AWS managed policies that provide access far beyond what one might suspect given the policy name and description. Implementing least privilege with IAM can be really difficult in any moderately complex environment.
- LilBytes 7y agoAnd close to impossible in highly complex environments. We're looking to adopt using AWS accounts to achieve a few objectives but one being reducing the blast radius of potential breaches and outages.