AWS ssm:SendCommand with SNS - restrictive IAM policy

Viewed 982

I'm attempting to create a restrictive SSM role IAM policy that is able to send SNS notifications on failure of SendCommand command executions. I currently have the following policy that gives me "AccessDenied" with no other information (placeholders replaced):

{
  "Statement": {
    "Effect": "Allow",
    "Action": [ "ssm:SendCommand" ],
    "Resource": [
      "arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:instance/*",
      "arn:aws:ssm:${AWS::Region}:${AWS::AccountId}:document/${DocumentName}",
      "arn:aws:s3:::${S3BucketName}",
      "arn:aws:s3:::${S3BucketName}/*",
      "arn:aws:iam::${AWS::AccountId}:role/${RoleThatHasSNSPublishPerms}",
      "arn:aws:sns:${AWS::RegionId}:${AWS::AccountId}:${SNSTopicName}"
    ]
  }
}

I also have a iam::PassRole permissions for the ${RoleThatHasSNSPublishPerms}. I am invoking it from a lambda using python boto3 in this way:

        ssm = boto3.client('ssm')
        ssm.send_command(
            InstanceIds = [ instance_id ],
            DocumentName = ssm_document_name,
            TimeoutSeconds = 300,
            OutputS3Region = aws_region,
            OutputS3BucketName = output_bucket_name,
            OutputS3KeyPrefix = ssm_document_name,
            ServiceRoleArn = ssm_service_role_arn,
            NotificationConfig = {
                'NotificationArn': sns_arn,
                'NotificationEvents': ['TimedOut', 'Cancelled', 'Failed'],
                'NotificationType': 'Command'
            }
        )

I know that the problem lies with the "Resource" part of my IAM policy because when I change the Resource block to simply "*", the run command executes properly. Also, when I remove the NotificationConfig and ServiceRoleArn parts of my python command, the SendCommand succeeds as well.

I don't want a permissive policy for this lambda role to just execute the command anywhere and on anything. The question is, how do I restrict this policy and still send notifications on failures?

EDIT: Not sure whether this is new or I just missed it before but AWS posted some instructions on how to narrow down the permissions to only tagged EC2s: https://docs.aws.amazon.com/systems-manager/latest/userguide/sysman-rc-setting-up-cmdsec.html

This still doesn't answer the SNS/S3 part of the question, but at least it's a step in the right direction.

0 Answers
Related