Empresas
Empleos
  • Sobre nosotros
  • Soluciones
    • Publicación de vacantes
      Publica tu vacante y recibe candidatos calificados en 48h.
    • Evaluación de candidatos
      500+ pruebas técnicas y psicológicas, más anti-fraude.
    • Headhunting
      Búsqueda ejecutiva a la medida de principio a fin.
    • Nómina + EOR
      Dispersión de nómina y EOR en más de 15 países de LATAM.
  • Precios
  • Empleos

0

425
Vistas
Need to make an identical copy of AWS IAM role (including policies and trust relationship it has)

I have a IAM role (with many policies and a trust relationship in it). I used this in building a AWS Cognito User Pool. However, this IAM role will be deleted soon.

Making a copy manually will be a chore and also not repeatable. I would like to make a copy either via CLI or script of some other repeatable way.

So far, I have searched through stackoverflow and google, but failed to find anything relevant.

Any help is appreciated.

over 4 years ago · Santiago Trujillo
3 Respuestas
Responde la pregunta

0

It looks like you will need to use:

  • list_role_policies() to obtain the names of inline policies attached to the role
  • get_role_policy() to retrieve inline policies
  • list_attached_role_policies() to list managed policies that are attached to the role

Then create a new role and use:

  • put_role_policy() to attach an inline policy
  • attach_role_policy() to attach a managed policy
over 4 years ago · Santiago Trujillo Denunciar

0

Thanks to @JohnRotenstein for pointing in the right direction. I came up with a Node.js script to automate the IAM role copy procedure.

Steps it performs along with AWS SDK APIs used:

  1. Fetch the source role along with its trust relationship policy: getRole()
  2. Fetch inline policies of the source role: listRolePolicies(), getRolePolicy()
  3. Fetch managed policies of the source role (both AWS- and customer-created): listAttachedRolePolicies()
  4. Create a new role copying over all relevant properties (including trust policy): createRole()
  5. Add all inline policies found in the source role to the new role: putRolePolicy()
  6. Attach all managed policies from the source role: attachRolePolicy()

The process is quite straightforward... The only interesting detail is steps 2 and 3 require recursive fetch to accommodate the fact that policies response can be paginated.

How to make a copy of AWS IAM role.

over 4 years ago · Santiago Trujillo Denunciar

0

If Python is an option, perhaps boto3 can be helpful (AWS's SDK for Python)

Creating a role: https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/iam.html#IAM.Client.create_role

Creating a policy: https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/iam.html#IAM.Client.create_policy

More: https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/iam.html#client https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/iam.html

over 4 years ago · Santiago Trujillo Denunciar
Responde la pregunta
Encuentra empleos remotos

¡Descubre la nueva forma de encontrar empleo!

Top de empleos
Top categorías de empleo
Empresas
Publicar vacante Precios Comercial
Legal
Términos y condiciones Política de privacidad
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomiéndame algunas ofertas
Necesito ayuda