AWS IAM角色清理:Last Activity为None是否代表角色从未被使用?
Great question! Let me break this down clearly based on my experience working with AWS IAM and cleanup tasks:
核心结论:大部分情况下,是的
When an IAM role's Last Activity shows as None, it almost always means the role was created but never actually used to perform any AWS operations. For a role to be "used", some entity (a user, another AWS service, or even another IAM role) has to call the AssumeRole API to obtain temporary credentials tied to that role—and every such call (and subsequent actions using those credentials) gets tracked by AWS CloudTrail, which feeds into the Last Activity metric.
但要注意几个例外情况(避免误删)
There are a few edge cases where a role might have been used but still shows None in Last Activity:
- CloudTrail latency or gaps: AWS CloudTrail can take up to 15 minutes (sometimes longer for large accounts) to process and display API events. If the role was used very recently, the activity might not have synced to the console yet. Worse, if CloudTrail wasn't enabled for the account/region when the role was used, those historical events won't exist at all, leaving Last Activity as
None. - Unrecorded "partial" usage: In extremely rare cases, someone might have attempted to assume the role but failed (e.g., incorrect permissions, invalid trust policy), but even failed
AssumeRolecalls are usually logged in CloudTrail. If those logs aren't available, you might miss that attempt.
怎么确认角色真的没被使用?
To be 100% sure before deleting, I recommend verifying with CloudTrail directly:
- Use the AWS CLI to search for
AssumeRoleevents tied to the role:aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=AssumeRole --filters RoleName=your-target-role-name - Or in the AWS Console, go to the CloudTrail service, navigate to Event History, and search for the role's name. Look for any
AssumeRoleevents (success or failed) to confirm activity.
If you don't find any matching events, and the role has been around long enough for CloudTrail to catch any activity (at least a day), then it's safe to delete.
内容的提问来源于stack exchange,提问作者Pierre-Alexandre

