AWS Glue runs ETL jobs and development endpoints under a service role. With iam:PassRole and glue:CreateJob (or glue:CreateDevEndpoint), you attach a privileged role to a job whose script is yours, then start it, running your code with the passed role's credentials.
Job path#
aws glue create-job --name x \
--role arn:aws:iam::<acct>:role/<privileged-glue-role> \
--command '{"Name":"pythonshell","ScriptLocation":"s3://you/script.py"}'
aws glue start-job-run --job-name x
The script at ScriptLocation runs as the Glue role; have it call STS or perform the privileged action and write results to a bucket you read.
Dev endpoint path#
A development endpoint is a long-lived box you can SSH into; glue:CreateDevEndpoint with a public key gives an interactive shell as the role. The update variant is covered under existing resources.
Exploitation notes#
- Glue roles are commonly over-permissioned for data access (S3, Lake Formation, catalog), so the passed role often reaches far beyond Glue itself.
- A
pythonshelljob is the lightest footprint; a Spark job also works but spins up more infrastructure.
Tools#
- AWS CLI (
glue create-job/start-job-run/create-dev-endpoint). - Pacu: Glue privesc modules.