AWS Policy: Allow update specific record in route53 hosted zone

Viewed 5549

Assume the documentation, I should use policy, like this:

{
   "Version": "2017-11-27",
   "Statement":[
      {   
         "Effect":"Allow",
         "Action": [
           "route53:ChangeResourceRecordSets"
         ],  
         "Resource": [
          "arn:aws:route53:::hostedzone/<ZONE_ID>"
         ]
   ]   
}

I need a very safe policy.

I cannot add specific resource record set (one record in zone) in arn. I can use Condition to check what record should be changed with ChangeResourceRecordSets API call. If I'm not mistaken.

This is necessary for automatic update only one record in public domain zone. Updates _acme-challenge.ldap.example.com. record for automatically update let's encrypt certificates. I know that acme.sh is available to achive my goal. But I want to write my own custom and simple script to do this.

2 Answers

In the scenario of allowing starting EC2 instances with a script to add/remove record set of a domain programmatically, but limit the access to specific record safely without harming example.com.

Create another public hosted zone (without purchasing another domain from anyone), just use a subdomain like delegate.example.com. Copy the name server assigned to delegate.example.com by AWS like:

ns-1143.awsdns-14.org. 
ns-1686.awsdns-18.co.uk. 
ns-133.awsdns-16.com. 
ns-965.awsdns-56.net.

And for example, the created zone is ZONEABCD

The goal of created domain will be instance-xxx.delegate.example.com without harming example.com

Create a record set of NS Type in the hosted zone under your root example.com. Create a record set of type NS and paste the 4 name servers copied from delegate.example.com.

The you can create a IAM user (copy the accesskey/secretkey for script) with the following policy attached. Limit resource to the created arn:aws:route53:::hostedzone/{ZONEABCD}.

{
"Version": "2012-10-17",
"Statement": [
    {
        "Effect": "Allow",
        "Action": [
            "route53:ChangeResourceRecordSets"
        ],
        "Resource": [
            "arn:aws:route53:::hostedzone/{ZONEABCD}"
        ]
    },
    {
        "Effect": "Allow",
        "Action": [
            "route53:ListHostedZonesByName"
        ],
        "Resource": [
            "*"
        ]
    }
]}

Launch a VM with name instance-xxx and run script with aws-cli

$aws route53 change-resource-record-sets --cli-input-json '{
"HostedZoneId": "ZONEABCD",
"ChangeBatch": {
    "Comment": "This is a test and may be deleted.",
    "Changes": [
        {
            "Action": "CREATE",
            "ResourceRecordSet": {
                "Name": "instance-xxx.delegate.example.com",
                "Type": "A",
                "TTL": 600,
              "ResourceRecords": [
                {
                  "Value": "some.ip.v4.address"
                }
              ]
            }
        }
    ]
}}'

$nslookup instance-xxx.delegate.example.com 

Returning {some.ip.v4.address} for instance-xxx.delegate.example.com proves the above is working.

Related