Restricting Machine API IAM policy on AWS

Solution Verified - Updated -

Issue

On AWS, the default Identity and Access Management (IAM) policy requested by the Machine API includes wide permissions for the iam:PassRole permission. It defaults to '*', which allows any administrator with access to create or modify compute machine sets to assume any IAM policy when creating new machines.

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content