Business
Jobs
  • About Us
  • Solutions
    • Job Postings
      Post your job and receive qualified candidates in 48h.
    • Candidate Assessments
      500+ technical and psychological tests, plus anti-fraud.
    • Headhunting
      Tailor-made executive search from start to finish.
    • Payroll + EOR
      Payroll dispersal and EOR across 15+ LATAM countries.
  • Pricing
  • Jobs

0

421
Views
Need to make an identical copy of AWS IAM role (including policies and trust relationship it has)

I have a IAM role (with many policies and a trust relationship in it). I used this in building a AWS Cognito User Pool. However, this IAM role will be deleted soon.

Making a copy manually will be a chore and also not repeatable. I would like to make a copy either via CLI or script of some other repeatable way.

So far, I have searched through stackoverflow and google, but failed to find anything relevant.

Any help is appreciated.

over 4 years ago · Santiago Trujillo
3 answers
Answer question

0

It looks like you will need to use:

  • list_role_policies() to obtain the names of inline policies attached to the role
  • get_role_policy() to retrieve inline policies
  • list_attached_role_policies() to list managed policies that are attached to the role

Then create a new role and use:

  • put_role_policy() to attach an inline policy
  • attach_role_policy() to attach a managed policy
over 4 years ago · Santiago Trujillo Report

0

Thanks to @JohnRotenstein for pointing in the right direction. I came up with a Node.js script to automate the IAM role copy procedure.

Steps it performs along with AWS SDK APIs used:

  1. Fetch the source role along with its trust relationship policy: getRole()
  2. Fetch inline policies of the source role: listRolePolicies(), getRolePolicy()
  3. Fetch managed policies of the source role (both AWS- and customer-created): listAttachedRolePolicies()
  4. Create a new role copying over all relevant properties (including trust policy): createRole()
  5. Add all inline policies found in the source role to the new role: putRolePolicy()
  6. Attach all managed policies from the source role: attachRolePolicy()

The process is quite straightforward... The only interesting detail is steps 2 and 3 require recursive fetch to accommodate the fact that policies response can be paginated.

How to make a copy of AWS IAM role.

over 4 years ago · Santiago Trujillo Report

0

If Python is an option, perhaps boto3 can be helpful (AWS's SDK for Python)

Creating a role: https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/iam.html#IAM.Client.create_role

Creating a policy: https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/iam.html#IAM.Client.create_policy

More: https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/iam.html#client https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/iam.html

over 4 years ago · Santiago Trujillo Report
Answer question
Find remote jobs

Discover the new way to find a job!

Top jobs
Top job categories
Business
Post vacancy Pricing Sales
Legal
Terms and conditions Privacy policy
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Show me some job opportunities
There's an error!