When a resource already runs with a privileged role, you do not need iam:PassRole: you only need permission to change what that resource runs. Overwriting its code or configuration makes the existing role execute your payload.
Paths#
- UpdateStack: change a CloudFormation stack that carries a privileged stack role.
- UpdateDevEndpoint: push an SSH key to a Glue dev endpoint running a privileged role.
- UpdateFunctionCode: overwrite a Lambda that already runs a privileged execution role.
- Presigned URL: mint time-limited signed access to resources under your own permissions.
- Instance Connect: push a temporary SSH key to an instance carrying a privileged profile.
- AssociateInstanceProfile: attach a privileged instance profile to an instance you already control.