The deploy role that can do anything SEC-322

Open2 versionsCloud · Hard · Fix · about 35 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Priya Raman opened SEC-322 at 11:00SEV-2

The access review found that the CI role every Waybill deploy assumes can do far more than deploy Waybill. Its policy was "temporary, for the migration", and then "narrowed" once. Nobody has compared it with what the pipeline calls.

Every Waybill deploy assumes role/waybill-deploy through the CI's identity provider. Anyone who gets a workflow merged to main gets that role.

"It was temporary, for the migration. We narrowed it later, I think." (Sasha)

"What does the pipeline actually call? Give it that and nothing else." (Priya)

The lab runs an offline simulated AWS account. The aws CLI in your terminal is already pointed at it.

Your task

Replace the role's permissions with exactly what the deploy job needs: the actions it calls, on the resources it touches. Leave the trust policy alone.

On the machine

  • pipeline/deploy.yml: every AWS call the deploy job makes
  • aws iam list-role-policies --role-name waybill-deploy, aws iam get-role-policy ...
  • policies/waybill-deploy.json, policies/trust.json

Timeline

2026-03-12Sasha gives the deploy role "*" for the registry migration.
10:30The quarterly access review flags role/waybill-deploy.
10:50"What does the pipeline actually call? Give it that and nothing else." (Priya)
11:00SEC-322 lands with you.

Done when

  1. The deploy job can still make every call in pipeline/deploy.yml.
  2. The role can do nothing else, including other repositories, other bucket paths, other services, and IAM.
  3. The role's trust policy is unchanged.

Hints

Hint 1

Start from the comments in `pipeline/deploy.yml`. They list each action and the resource it acts on.

Hint 2

One action in the list has no resource to scope to. That one needs `"Resource": "*"`.

Hint 3

`ecr:*` on `*` is still a wildcard: it can delete every repository. And `iam:PassRole` on any role lets the pipeline hand itself an admin role.

Hint 4

Replace the inline policy with `aws iam put-role-policy`; the same name overwrites it.

Show the solution

Read the attached policy (`aws iam get-role-policy --role-name waybill-deploy --policy-name deploy`): `"*"` on everything, or whole services (`ecr:*`, `s3:*`, `ecs:*`) on every resource plus `iam:PassRole` on any role. Replace it with four statements from the comments in `pipeline/deploy.yml`: ecr:GetAuthorizationToken on "*", the six push actions on `arn:aws:ecr:eu-central-1:123456789012:repository/waybill`, s3:PutObject on `arn:aws:s3:::northstar-releases/waybill/*`, and ecs:UpdateService plus ecs:DescribeServices on `arn:aws:ecs:eu-central-1:123456789012:service/depot-cluster/waybill`. Apply it with `aws iam put-role-policy --role-name waybill-deploy --policy-name deploy --policy-document file://...`. The pipeline passes no role, so it needs no iam:PassRole.