aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

chore(compute): re-tighten MicroVM-facing IAM if AWS exposes usable condition keys

Ouverte
#736 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
TypeScript
Étoiles
146
Forks
46
Merge moyen
3 j 10 h
PR mergées (30 j)
24

Description

### Context

ADR-021's Lambda MicroVMs backend runs with deliberately relaxed IAM in two places, both proven necessary by controlled live experiments (evidence: ADR-021 §4 + `docs/verification/645-p2-smoke-runbook.md`):

1. **Role trust**: the build, execution, and connector-operator roles trust `lambda.amazonaws.com` with **no** `aws:SourceAccount`/`aws:SourceArn` condition — the service presents no source key when assuming them (conditioned trust → deterministic `CREATE_FAILED` / unassumable role).
2. **PassRole**: the orchestrator's grant on the execution role and the bootstrap `MicrovmPassRoles` statement carry **no** `iam:PassedToService` condition — the condition is denied on the `RunMicrovm` and CloudFormation paths (two-arm experiments, verbatim denials in the ADR). Candidate service principals (`microvms.lambda.amazonaws.com` etc.) were all `implicitDeny`, and CloudTrail emits no `lambda-microvms` events, so the value the authorizer would match cannot currently be observed.

Compensating controls in place: exact-ARN / name-prefix resource scoping, backend-conditional bootstrap policy, orchestrator-only pass path for the execution role.

### Ask

When AWS documents (or the service starts presenting) usable condition keys for Lambda MicroVMs role assumption and PassRole:
- add the trust conditions back to all three roles
- restore `iam:PassedToService` on both PassRole grants
- delete the compensating-control prose from ADR-021 §4 / SECURITY.md / DEPLOYMENT_ROLES.md

The ADR says "revisit if AWS documents it" — this issue is that revisit's handle. Consider also raising via internal AWS channels: the service team may simply need to publish the authorization-context documentation.

Refs #645, PR #733, ADR-021.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par ADR-021 §4 et docs/verification/645-p2-smoke-runbook.md, puis examinez les trois politiques de confiance des rôles et les deux autorisations PassRole décrites dans l’issue. Ne poursuivez qu’une fois qu’AWS aura documenté ou exposé des clés de condition Lambda MicroVM utilisables ; le travail est considéré comme terminé lorsque les conditions trust et iam:PassedToService sont rétablies et que le texte sur les contrôles compensatoires est supprimé de ADR-021 §4, SECURITY.md et DEPLOYMENT_ROLES.md.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
aws
Domaine
authorization, cloud, security
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
Calme
Clarté
Plutôt claire
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.