Restricting Machine API IAM policy on AWS
Issue
On AWS, the default Identity and Access Management (IAM) policy requested by the Machine API includes wide permissions for the iam:PassRole permission. It defaults to '*', which allows any administrator with access to create or modify compute machine sets to assume any IAM policy when creating new machines.
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.