Action: sts:AssumeRole (aws iam role)
(Redirected from Sts:AssumeRole)
Jump to navigation
Jump to search
sts:AssumeRole sts:AssumeRoleWithWebIdentity
Contents
Official example[edit]
https://aws.amazon.com/blogs/security/how-to-use-trust-policies-with-iam-roles/
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::111122223333:root"
},
"Action": "sts:AssumeRole"
}
]
}
Examples[edit]
Access to s3:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": "s3.amazonaws.com"
},
"Action": "sts:AssumeRole"
}
]
}
Access to s3 and one more cross-account role:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": "s3.amazonaws.com"
},
"Action": "sts:AssumeRole"
},
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::01234567890:role/your-role",
"AWS": "arn:aws:iam::11111111111:role/your-other-role"
},
"Action": "sts:AssumeRole"
}
]
}
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "",
"Effect": "Allow",
"Principal": {
"Service": "ecs-tasks.amazonaws.com"
},
"Action": "sts:AssumeRole"
}
]
}
resource "aws_iam_role" "ecs_task_role" { name = "your-ecs-task-role" assume_role_policy = <<-EOF { "Version": "2012-10-17", "Statement": [ { "Sid": "", "Effect": "Allow", "Principal": { "Service": "ecs-tasks.amazonaws.com" }, "Action": [ "sts:AssumeRole" ] } ] } EOF }
resource "aws_iam_role" "test_role" { name = "test_role" # Terraform's "jsonencode" function converts a # Terraform expression result to valid JSON syntax. assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Action = "sts:AssumeRole" Effect = "Allow" Sid = "" Principal = { Service = "ec2.amazonaws.com" } }, ] }) tags = { tag-key = "tag-value" } }
Related[edit]
aws sts assume-roleaws iam add-role-to-instance-profile- Amazon Cloudformation EKS cluster role
An error occurred (ValidationError) when calling the AssumeRole operation:aws sts get-caller-identitysts:aws ssm put-parameteraws iam list-instance-profiles- Terraform resource:
aws_iam_role sts:AssumeRoleWithWebIdentity- monitoring.rds.amazonaws.com
- iam:PassRole
See also[edit]
sts:, sts:TagSession, sts:AssumeRole, sts:AssumeRoleWithWebIdentity, sts:AssumeRoleWithSAMLamazonaws.com, clientvpn.REGION.amazonaws.com, efs.REGION.amazonaws.com, quicksight.amazonaws.com, metrics.eks.amazonaws.com, cognito-identity.amazonaws.com, sns.amazonaws.com, ecs.amazonaws.com, ecs-tasks.amazonaws.com,codeartifact.amazonaws.com, autoscaling.amazonaws.com- AWS STS
(sts:),aws sts[get-session-token|get-caller-identity|assume-role | assume-role-with-web-identity | assume-role-with-saml | get-access-key-info ] - AWS IAM role, ServiceRoleARN,
iam:GetRole, assumed-role, sts:AssumeRole, Trusted entities
Advertising: