iam:PassRole is the permission to hand an IAM role to an AWS service. On its own it does nothing; combined with an action that creates or updates a resource that runs with a role, it lets you pass a role more privileged than your own to something that will execute your code or return its credentials. The target role only needs a trust policy allowing the service (for example ec2.amazonaws.com), which is the default when the role was built for that service.
The pattern is always: find a passable privileged role (iam:ListRoles, or the graph from enumeration), then drive it through one of the service creations below.
Targets#
- EC2: launch an instance with a privileged instance profile, then read its credentials from IMDS.
- Lambda: create a function with a privileged execution role and invoke it.
- Glue: a Glue job or dev endpoint running as a passed role.
- CloudFormation: deploy a stack with a passed service role.
- Data Pipeline: a pipeline whose activities run as a passed role.
- CodeBuild: a build project running as a passed service role.
- SageMaker: a notebook or training job running as a passed role.
- Step Functions: a state machine whose tasks run as a passed role.
- CodeStar: a project toolchain deployed as a passed role, or self-adding as project owner.
Finding passable roles#
aws iam list-roles --query 'Roles[].Arn'
# a role is useful if its trust policy allows the service you can drive
aws iam get-role --role-name <r> --query 'Role.AssumeRolePolicyDocument'