docs icon indicating copy to clipboard operation
docs copied to clipboard

Clarify amplify-admin local AWS setup profile

Open carlschroedl opened this issue 6 months ago • 1 comments

Describe the content issue: Currently the amplify-admin local AWS setup profile documentation (step 4) includes the following CLI session:

CLI profile name [amplify-policy-<your-aws-account-id>]: default
To use this profile, specify the profile name using --profile, as shown:

aws s3 ls --profile default

When I ran the suggested command, I got an error:

$ aws s3 ls --profile default

An error occurred (AccessDenied) when calling the ListBuckets operation: Access Denied

I suspected something went wrong during the previous steps, but after troubleshooting I discovered that the role associated with the profile intentionally lacks permissions to list S3 buckets, and that this is expected. To prevent others from spending time troubleshooting this, I suggest that a note be added after the output aws s3 ls --profile default clarifying that running that generic example command will fail because the amplify admin user's least privilege role intentionally does not include this permission, and that you should proceed to the next step to verify your amplify setup.

URL page where content issue is: https://docs.amplify.aws/vue/start/account-setup/#4-set-up-local-aws-profile

carlschroedl avatar Jul 27 '24 13:07 carlschroedl