copilot-cli icon indicating copy to clipboard operation
copilot-cli copied to clipboard

Is there any documentation for getting the list of Permissions that are needed for copilot to run without any permission error?

Open shain-digix opened this issue 1 year ago • 1 comments

Because everytime I run the copilot service deploy, a new permission error pops up.

Received response status [FAILED] from custom resource. Message return ed: User: arn:aws:sts::193980408680:assumed-role/cd-paas-ngpay-service -dev-ngpay-EnvControllerRole-fMcu2P8hPESe/cd-paas-ngpay-service-dev-ng -EnvControllerFunction-J7PWnRaTHdEe is not authorized to perform: iam: PassRole on resource: arn:aws:iam::193980408680:role/cd-paas-ngpay-ser vice-dev-CFNExecutionRole because no identity-based policy allows the iam:PassRole action (Log: /aws/lambda/cd-paas-ngpay-service-dev-ng-Env ControllerFunction-J7PWnRaTHdEe/2024/01/15/[$LATEST]f3847d2a4eac4849b6 c69af1fa44a629) (RequestId: 914b386d-e4a2-4286-b74f-988f61fbd787)

shain-digix avatar Jan 15 '24 01:01 shain-digix

@shain-digix I can help you with that. Just one thing that I want to make sure before jumping into the solution, I assume you have permissions boundary added to the app right? Sorry for the trouble :(!

Lou1415926 avatar Jan 16 '24 12:01 Lou1415926

This issue is stale because it has been open 60 days with no response activity. Remove the stale label, add a comment, or this will be closed in 14 days.

github-actions[bot] avatar Mar 20 '24 00:03 github-actions[bot]

This issue is closed due to inactivity. Feel free to reopen the issue if you have any further questions!

github-actions[bot] avatar Apr 04 '24 00:04 github-actions[bot]