IAM Roles
Explore the concept of IAM roles in AWS to understand how they grant temporary access permissions to users, AWS services, and external entities. Learn about trust and permission policies, principal entities, and how roles use temporary security credentials to enhance secure access management within and across AWS accounts.
We'll cover the following...
An IAM role is an AWS identity similar to IAM users with an identity-based policy specifying its access. However, unlike the IAM users, IAM roles can be used to provide access to any entity within or outside the AWS account. A role is not attached to a specific entity and can be used by multiple entities at the same time to get the required access.
IAM roles provide this access for a limited amount of time in the form of sessions. The maximum time for this session can be 12 hours. By default, the value for this session is one hour. Temporary security credentials are associated with each of these sessions, which expire when the session ends.
Policies associated with an IAM role
There are mutiple policies associated with an IAM role that dictate the scope of permissions of the role and the entities that are allowed ...