📣 Send us your press release
Site updates every 15 minutes
Technology

Amazon EMR introduces runtime roles for step access control

Amazon Web Services has launched a new feature for its Amazon EMR service. The "runtime roles" functionality allows for the use of distinct IAM roles for EMR steps, enhancing access management.

28 September 2026
Amazon EMR introduces runtime roles for step access control

Amazon Web Services (AWS) has released a new capability for its Amazon Elastic MapReduce (EMR) service called runtime roles. This new functionality allows customers to assign distinct IAM (Identity and Access Management) roles to individual EMR steps, significantly improving access control and security.

Previously, job steps running on an Amazon EMR cluster, such as Apache Spark or Apache Hive jobs, utilized a shared EC2 instance profile with a unified IAM role. This meant the role had to encompass all potential permissions for any AWS resources that any step might require. This approach could lead to overly broad permissions and complicate access management, particularly in shared cluster environments.

The runtime roles feature enables each EMR step to be assigned its own, specifically defined IAM role. This allows, for instance, a Spark job to access only its designated resources, and a Hive job its own, without needing extensive general permissions. This is particularly beneficial in scenarios where the same EMR cluster is used by multiple different users or teams (tenants), as each tenant's or application's access to AWS resources can be precisely isolated.

The new feature also supports AWS Lake Formation, which provides a centralized method for managing access permissions to data sources within data lakes. By combining runtime roles with Lake Formation, customers can implement even more precise and granular access control for their data in AWS EMR.

AWS EMR is a managed Hadoop framework service that simplifies the processing and analysis of large datasets in the cloud. The new runtime roles feature adds flexibility and security for users employing EMR for complex data analysis tasks and application execution.

Original source: aws.amazon.com