# AWS IAM Roles getting altered

**URL:** <https://forum.serverless.com/t/aws-iam-roles-getting-altered/15854>\
**Category:** Serverless Framework\
**Tags:** aws, lambda, iam\
**Created:** [August 31, 2021, 8:41am UTC](https://forum.serverless.com/t/aws-iam-roles-getting-altered/15854 "2021-08-31T08:41:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![QAnders](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/qanders/32/3151_2.png) [@QAnders](https://forum.serverless.com/u/QAnders)\
**Post date:** [August 31, 2021, 8:41am UTC](https://forum.serverless.com/t/aws-iam-roles-getting-altered/15854/1 "2021-08-31T08:41:35Z")

</div>

We’ve recently noticed that IAM roles are getting altered when deploying to AWS using `Deploy`, e.g. `serverless deploy -s qa`.

The Roles are added in ´serverelss.yml` and have been in there (and working) in previous versions of the Lambda.

```auto
iam:
    role:
      statements:
        - Effect: Allow
          Action:
            - 'dynamodb:*'
            - 's3:*'
            - 'ec2:CreateNetworkInterface'
            - 'ec2:DescribeNetworkInterfaces'
            - 'ec2:DeleteNetworkInterface'
            - 'logs:CreateLogGroup'
            - 'logs:CreateLogStream'
            - 'logs:PutLogEvents'
            - 'lambda:*'
            - 'ssm:*'
            - 'sqs:*'
          Resource: '*'

```

What we’ve noticed is that sometimes the IAM role is altered and just now the above deploy’ed IAM role was missing the `ssm:*` permission all of a sudden.

Why could that be happening?

---

<div class="post-metadata">

**Author:** ![pgrzesik](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/pgrzesik/32/5054_2.png) [@pgrzesik](https://forum.serverless.com/u/pgrzesik)\
**Post date:** [September 8, 2021, 8:45am UTC](https://forum.serverless.com/t/aws-iam-roles-getting-altered/15854/2 "2021-09-08T08:45:33Z")

</div>

Hello @QAnders - that is quite surprising and I’ve never run into it previously. Are you using any external plugins? Do you have the ability to provide a small reproducible case?

---

<div class="post-metadata">

**Author:** ![QAnders](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/qanders/32/3151_2.png) [@QAnders](https://forum.serverless.com/u/QAnders)\
**Post date:** [September 29, 2021, 2:50pm UTC](https://forum.serverless.com/t/aws-iam-roles-getting-altered/15854/3 "2021-09-29T14:50:50Z")

</div>

Thanks @pgrzesik !

Turns out that CloudFormation had done a rollback and added the previous, previous working version which didn’t have the IAM setup…
