Coder Social home page Coder Social logo

Comments (3)

hawflau avatar hawflau commented on May 27, 2024

Hey @fade2black thanks for raising the issue.

The role is created for the pipeline to deploy resources of your application through CloudFormation. As the pipeline does not have any knowledge about your application (e.g. what resources will be created/updated), the role gives CloudFormation full access. In other words, it ensures CloudFormation to be able to deploy any change from your application template.

The risk thus lies in the application template - if an attacker adds a malicious resource in your application template (e.g. an IAM Role with admin access), the piepline will deploy it. Mitigation of this risk is to make sure only authorized persons can commit to your application template, and have a thorough review process before any change can be merged.

Alternatively, you can create your own CloudFormation Execution Role with limited scope for your application and supply that role when you create your pipeline.

Please let me know if you have any further question.

from aws-sam-cli.

fade2black avatar fade2black commented on May 27, 2024

@hawflau Clear now. Thank you for reply.

from aws-sam-cli.

github-actions avatar github-actions commented on May 27, 2024

⚠️COMMENT VISIBILITY WARNING⚠️

Comments on closed issues are hard for our team to see.
If you need more assistance, please either tag a team member or open a new issue that references this one.
If you wish to keep having a conversation with other community members under this issue feel free to do so.

from aws-sam-cli.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.