Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add iam:GetOpenIDConnectProvider grant to docs/iam-permissions.md #728

Conversation

danielelisi
Copy link
Contributor

@danielelisi danielelisi commented Feb 5, 2020

PR o'clock

Description

The suggested policy in iam-permissions.md is missing to include the iam:GetOpenIDConnectProvider permission hence Terraform plan fails to complete with the error:

AccessDenied: User: arn:aws:sts::<redacted>:assumed-role/<iam_role>/ is not authorized to perform: iam:GetOpenIDConnectProvider on resource: arn:aws:iam::<redacted>:oidc-provider/oidc.eks.ap-southeast-2.amazonaws.com/

After including this permission Terraform completes running the plan

Checklist

Copy link
Contributor

@max-rocket-internet max-rocket-internet left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks but also please update the changelog 🙂

@danielelisi
Copy link
Contributor Author

Thanks but also please update the changelog

Sounds good! I added the change to CHANGELOG.md

Copy link
Contributor

@max-rocket-internet max-rocket-internet left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @danielelisi 💙

@max-rocket-internet max-rocket-internet merged commit 415e123 into terraform-aws-modules:master Feb 6, 2020
@danielelisi danielelisi deleted the fix_iam_permission_doc branch February 6, 2020 17:29
@github-actions
Copy link

I'm going to lock this pull request because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. If you have found a problem that seems related to this change, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Nov 20, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants