Skip to content
This repository was archived by the owner on Feb 10, 2026. It is now read-only.

v1.250.2

Choose a tag to compare

@cloudpossebot cloudpossebot released this 14 Jul 23:34
· 373 commits to refs/heads/main since this release
ca80ce2

馃殌 Enhancements

[aws-teams] Remove obsolete restriction on assuming roles in identity account Nuru (@Nuru) (#761)

what

  • [aws-teams] Remove obsolete restriction on assuming roles in the identity account

why

Some time ago, there was an implied permission for any IAM role to assume any other IAM role in the same account if the originating role had sufficient permissions to perform sts:AssumeRole. For this reason, we had an explicit policy against assuming roles in the identity account.

AWS has removed that implied permission and now requires all roles to have explicit trust policies. Our current Team structure requires Teams (e.g. spacelift) to be able to assume roles in identity (e.g. planner). Therefore, the previous restriction is both not needed and actually hinders desired operation.

馃悰 Bug Fixes

[aws-teams] Remove obsolete restriction on assuming roles in identity account Nuru (@Nuru) (#761)

what

  • [aws-teams] Remove obsolete restriction on assuming roles in the identity account

why

Some time ago, there was an implied permission for any IAM role to assume any other IAM role in the same account if the originating role had sufficient permissions to perform sts:AssumeRole. For this reason, we had an explicit policy against assuming roles in the identity account.

AWS has removed that implied permission and now requires all roles to have explicit trust policies. Our current Team structure requires Teams (e.g. spacelift) to be able to assume roles in identity (e.g. planner). Therefore, the previous restriction is both not needed and actually hinders desired operation.