Existing resources

When a resource already runs with a privileged role, you do not need iam:PassRole: you only need permission to change what that resource runs. Overwriting its code or configuration makes the existing role execute your payload.

Paths#

  • UpdateStack: change a CloudFormation stack that carries a privileged stack role.
  • UpdateDevEndpoint: push an SSH key to a Glue dev endpoint running a privileged role.
  • UpdateFunctionCode: overwrite a Lambda that already runs a privileged execution role.
  • Presigned URL: mint time-limited signed access to resources under your own permissions.
  • Instance Connect: push a temporary SSH key to an instance carrying a privileged profile.
  • AssociateInstanceProfile: attach a privileged instance profile to an instance you already control.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more