AWS IAM权限配置问询:允许用户管理特定服务角色并限制权限
AWS IAM Permission Configuration for Service Role Management
Let’s break down your two scenarios with practical, secure IAM policy solutions—this is exactly the kind of granular access control IAM was built for.
Scenario 1: Allow Creating/Deleting Service Roles, No Tampering with Other Roles
To restrict users to only service roles (and leave other roles untouched), we’ll use IAM conditions to enforce that any created role has a service trust policy, and limit delete/modify actions to those same service roles.
Here’s a sample policy that achieves this:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "iam:CreateRole", "Resource": "arn:aws:iam::*:role/*", "Condition": { "StringLike": { "iam:AssumeRolePolicyDocument": "{\"Statement\":[{\"Principal\":{\"Service\":\"*.amazonaws.com\"}}]}" } } }, { "Effect": "Allow", "Action": [ "iam:DeleteRole", "iam:GetRole", "iam:ListRolePolicies", "iam:ListAttachedRolePolicies" ], "Resource": "arn:aws:iam::*:role/*", "Condition": { "StringLike": { "iam:RoleTrustPolicy": "{\"Statement\":[{\"Principal\":{\"Service\":\"*.amazonaws.com\"}}]}" } } }, { "Effect": "Deny", "Action": [ "iam:UpdateRole", "iam:PutRolePolicy", "iam:AttachRolePolicy", "iam:DetachRolePolicy", "iam:DeleteRolePolicy" ], "Resource": "arn:aws:iam::*:role/*", "Condition": { "StringNotLike": { "iam:RoleTrustPolicy": "{\"Statement\":[{\"Principal\":{\"Service\":\"*.amazonaws.com\"}}]}" } } } ] }
Key Notes:
- The
CreateRolecondition ensures the new role’s trust policy targets an AWS service (matches*.amazonaws.com). - The
DeleteRoleand read actions are limited to roles with a service trust policy. - The final Deny statement blocks modification of any non-service roles, preventing tampering with user roles or other custom roles.
Scenario 2: Restrict to Specific Services, Approved Policies, and Self-Created Roles Only
Yes, this is fully achievable with IAM’s combination of conditions, resource restrictions, and tagging. We’ll layer in additional controls to meet all your requirements:
Breakdown of Controls:
- Limit service roles to specific AWS services
- Only allow attaching approved policies
- Block non-service role creation
- Prevent modifying/deleting roles not created by the user (or protected roles)
Here’s a comprehensive policy example:
{ "Version": "2012-10-17", "Statement": [ // Allow creating service roles for specific services (EC2, Lambda here) { "Effect": "Allow", "Action": "iam:CreateRole", "Resource": "arn:aws:iam::*:role/ServiceRole-*", "Condition": { "StringEquals": { "iam:AssumeRolePolicyDocument": "{\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"Service\":[\"ec2.amazonaws.com\",\"lambda.amazonaws.com\"]},\"Action\":\"sts:AssumeRole\"}]}" }, "StringEquals": { "aws:RequestTag/CreatedBy": "${aws:username}" } } }, // Require tagging self-created roles (enforce via condition) { "Effect": "Deny", "Action": "iam:CreateRole", "Resource": "arn:aws:iam::*:role/*", "Condition": { "StringNotEquals": { "aws:RequestTag/CreatedBy": "${aws:username}" } } }, // Allow deleting/modifying only self-created service roles { "Effect": "Allow", "Action": [ "iam:DeleteRole", "iam:UpdateRole", "iam:ListRolePolicies", "iam:ListAttachedRolePolicies" ], "Resource": "arn:aws:iam::*:role/*", "Condition": { "StringEquals": { "aws:ResourceTag/CreatedBy": "${aws:username}" }, "StringLike": { "iam:RoleTrustPolicy": "{\"Statement\":[{\"Principal\":{\"Service\":[\"ec2.amazonaws.com\",\"lambda.amazonaws.com\"]}}]}" } } }, // Allow attaching ONLY approved policies to these roles { "Effect": "Allow", "Action": "iam:AttachRolePolicy", "Resource": "arn:aws:iam::*:role/ServiceRole-*", "Condition": { "StringEquals": { "aws:ResourceTag/CreatedBy": "${aws:username}" } }, "Resource": [ "arn:aws:iam::123456789012:policy/EC2ServiceRoleApprovedPolicy", "arn:aws:iam::123456789012:policy/LambdaServiceRoleApprovedPolicy" ] }, // Block creation of non-service roles entirely { "Effect": "Deny", "Action": "iam:CreateRole", "Resource": "arn:aws:iam::*:role/*", "Condition": { "StringNotEquals": { "iam:AssumeRolePolicyDocument": "{\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"Service\":[\"ec2.amazonaws.com\",\"lambda.amazonaws.com\"]},\"Action\":\"sts:AssumeRole\"}]}" } } }, // Deny access to protected role set { "Effect": "Deny", "Action": [ "iam:*Role*", "iam:*RolePolicy*" ], "Resource": [ "arn:aws:iam::123456789012:role/ProtectedAdminRole", "arn:aws:iam::123456789012:role/BillingProtectedRole" ] } ] }
Key Notes:
- We enforce a
CreatedBytag tied to the user’s username, so they can only modify roles they created. - The
CreateRoleaction is restricted to specific services (EC2, Lambda) and uses aServiceRole-*naming pattern (optional but helps with organization). - Attaching policies is limited to a predefined list of approved policy ARNs—eliminating risk of permission elevation.
- A final Deny statement locks down access to your protected role collection, ensuring they can’t touch those at all.
内容的提问来源于stack exchange,提问作者Nathan
相关产品推荐
相关产品推荐

