如何组合AWS IAM角色信任策略的标签与SourceIdentity条件?
问题重现
执行aws sts assume-role同时指定标签和SourceIdentity时,报错:
An error occurred (AccessDenied) when calling the AssumeRole operation: User: arn:aws:sts::ANOTHERACCOUNTID:assumed-role/AWSReservedSSO_team-administrators-role_feadc200cc9855b0/JimSmith is not authorized to perform: sts:SetSourceIdentity on resource: arn:aws:iam::1111122222333:role/team-sso-administrators-role
当前信任策略将sts:AssumeRole、sts:SetSourceIdentity、sts:TagSession放在同一条语句中,并附加了标签相关条件,单独移除其中一组操作(标签或SourceIdentity相关)则可正常工作。
原因分析
信任策略中的条件会作用于语句内的所有操作,但sts:SetSourceIdentity操作不支持aws:RequestTag、aws:TagKeys这类标签相关条件。当把该操作与需要标签条件的sts:AssumeRole/sts:TagSession放在同一条语句时,标签条件会导致sts:SetSourceIdentity操作被拒绝。
正确配置方案
将信任策略拆分为两条独立语句:一条处理带标签要求的sts:AssumeRole和sts:TagSession,另一条处理带SourceIdentity要求的sts:SetSourceIdentity。
示例Terraform配置:
# 语句1:允许带指定标签的角色假定和会话打标签 statement { effect = "Allow" actions = ["sts:AssumeRole", "sts:TagSession"] principals { type = "AWS" identifiers = var.trusted_role_arns } principals { type = "Service" identifiers = var.trusted_role_services } condition { test = "StringEquals" variable = "aws:RequestTag/department" values = ["devops"] } condition { test = "StringEquals" variable = "aws:RequestTag/team" values = ["team"] } condition { test = "ForAllValues:StringEquals" variable = "aws:TagKeys" values = ["department", "team"] } } # 语句2:允许设置SourceIdentity statement { effect = "Allow" actions = ["sts:SetSourceIdentity"] principals { type = "AWS" identifiers = var.trusted_role_arns } principals { type = "Service" identifiers = var.trusted_role_services } condition { test = "StringLike" variable = "sts:SourceIdentity" values = ["*"] } }
验证
重新应用策略后,执行原aws sts assume-role命令即可成功完成角色假定,同时满足标签和SourceIdentity的强制要求。
内容的提问来源于stack exchange,提问作者DmitrySemenov

