Authored FILES (not applied to AWS — provisioning gated behind the mandatory
GPT-4.1 IAM cross-review + Adam, design §7 B3) for the aws-posture checker's
read-only AWS identity. Decision D5: box stays read-only, auths via IAM Roles
Anywhere short-lived leaf certs from a new internal step-ca; NO long-lived AWS key.
- aws-posture-readonly-policy.json least-privilege read-only (ce:Get*,
cloudwatch:GetMetric*/DescribeAlarms, ec2/elb/rds:Describe*, lambda list +
GetFunctionConfiguration, s3:ListAllMyBuckets/GetBucketLocation). No write,
no iam:* mutation, no s3:GetObject/secrets/kms/logs data reads, no wildcard
actions. Resource:* only where AWS has no resource-level support.
- aws-posture-readonly-policy.rationale.md per-statement least-privilege rationale.
- aws-posture-trust-policy.json pins Roles Anywhere principal + leaf subject CN +
issuer CN + trust-anchor SourceArn (three conditions, all required).
- roles-anywhere-config.json trust anchor (pins step-ca root) + profile (1h session).
- step-ca-config-sketch.md internal CA config + systemd-timer leaf auto-renewal.
- CROSS-REVIEW-PACKET.md end-to-end trust model, blast radius, EXERCISED rollback,
reviewer scrutiny list.
Does NOT build aws-posture.sh, touch checker_coordinator.sh, or requirements.txt.
3.8 KiB
aws-posture-readonly-policy.json — least-privilege rationale
This is the annotated companion to aws-posture-readonly-policy.json. The policy JSON itself
is kept strictly valid (no inline Comment keys — IAM rejects those), so all rationale lives
here. This policy is the permission set for the aws-posture checker (design D5 / §4):
idle / anomalous-spend watch on the Sea Haven AWS account (328440206208, us-east-1).
aws-posture itself is NOT built in this change — it is hard-gated behind the mandatory GPT-4.1 IAM cross-review (design §7, B3). This file + the policy are the review inputs.
Design principle
The box stays read-only. There is no write action, no iam:* mutating action, no
Resource wildcard where AWS supports resource-level scoping. Idle-spend posture is an
account-wide, list-oriented read: most of the actions below are AWS APIs that do not support
resource-level ARNs at all (Cost Explorer, the CloudWatch metric-data calls, and the EC2/ELB/
RDS Describe* list operations). For those, least-privilege is enforced by the action
allow-list (only the specific read verbs), not by narrowing Resource.
Statement-by-statement
| Sid | Why aws-posture needs it | Why read-only / why Resource: "*" |
|---|---|---|
CostAndUsageReadOnly |
The core idle/anomalous-spend signal (the design flags ≈$330/mo). GetCostAndUsage, forecasts, dimensions, and the native CE anomaly detectors. |
Cost Explorer is an account-scoped service; its API has no resource-level ARNs, so Resource:* is the only valid form. Only Get* verbs — no ce:Update*/Create*/Delete*, no budget mutation. |
CloudWatchMetricsReadOnly |
Correlate spend with utilization (an instance billing but at ~0% CPU is idle). GetMetricData/GetMetricStatistics/ListMetrics; DescribeAlarms* to see whether an idle resource is already alarmed. |
These metric-read APIs do not support resource-level permissions. No PutMetricData, no alarm create/modify/delete. |
Ec2DescribeReadOnly |
The classic idle-spend inventory: stopped instances still paying for EBS, unattached volumes, unassociated Elastic IPs, idle NAT gateways, orphan snapshots/AMIs. | Describe* is read-only; these list calls don't take resource ARNs. No Run*/Start*/Stop*/Terminate*/Modify*/Create*/Delete*. |
ElbAndRdsDescribeReadOnly |
Idle load balancers (no healthy targets) and idle/oversized RDS are frequent waste. Describe* only. |
List APIs without resource-level ARNs. No rds:Modify*/Delete*/Reboot*, no ELB mutation. |
LambdaAndStorageInventoryReadOnly |
Inventory functions + buckets to correlate against CloudWatch idle metrics. | Deliberately excludes s3:GetObject — the role never reads object data, only ListAllMyBuckets + GetBucketLocation (existence/region). No lambda:InvokeFunction, no Lambda mutation. This is the tightest the inventory can be while still seeing what exists. |
What is deliberately NOT here (blast-radius containment)
- No
iam:*,sts:AssumeRoleonward-chaining,organizations:*, oraccount:*. - No
s3:GetObject/s3:GetObjectVersion(no data-plane read of any bucket). - No
secretsmanager:GetSecretValue/ssm:GetParameter*(no secret read). - No
kms:Decrypt, nologs:GetLogEvents(no log/data exfil path). - No write/modify/delete verb in any service.
A leaked session from this role can enumerate and price the account, and nothing more — it cannot read application data, secrets, or change a single resource.
Comparison to the AWS-managed alternatives
ReadOnlyAccess / ViewOnlyAccess are far broader (they include s3:GetObject,
dynamodb:GetItem, secretsmanager list, etc.). This custom policy is intentionally a small
fraction of those — only the cost + idle-inventory surface the checker actually queries.