BlueXP AWS CVO create-subtask AWS S3の「Create Cloud Formation Stack」が失敗し、「No identity-based policy allows the IAM:TagRole」というエラーが表示される
環境
- Amazon Web Service(AWS)
- Cloud Volumes ONTAP(CVO)の導入
- 高可用性(HA)とシングルノード
- FabricPoolまたはCBSに使用されるSimple Storage Service(S3)
- Cloud Backup Service(CBS)
問題
BlueXP AWS CVO create with AWS S3 for FabricPool or CBS or both - AWS S3 - subtask「
Create Cloud Formation Stack
」for AWS S3がエラーで失敗する "no identity-based policy allows the iam:TagRole"
エラー:
BlueXP タイムライン:
Create VSA Environment:
Aug 26 2024, 5:23:38 pm Create Cloud Formation Stack failed cvo-instance-profile-version10-f21de2f5-63be-11ef-a3f3-7ba0fb45a1c4 Aug 26 2024, 5:23:18 pm Error: The following resource(s) failed to create: [IamInstanceRole]. Resource handler returned message: "Encountered a permissions error performing a tagging operation, please add required tag permissions. See https://repost.aws/knowledge-center/cloudformation-tagging-permission-error for how to resolve. Resource handler returned message: "User: arn:aws:sts::69199abcdef6:assumed-role/bluexpCloud-Manager-Operator-Gk0aQL0/i-0b4049d89620868d3 is not authorized to perform: iam:TagRole on resource: arn:aws:iam::69199abcdef6:role/cvo-instance-profile-version10-f21d-IamInstanceRole-OiiFvLfNQ15W because no identity-based policy allows the iam:TagRole action (Service: Iam, Status Code: 403, Request ID: a0c04413-78a4-456e-ab9a-xxxx)"" (RequestToken: 216aae93-5668-d1ae-1c33-yyy, HandlerErrorCode: UnauthorizedTaggingOperation ... Aug 26 2024, 5:23:18 pm Create Cloud Formation Stack success { "name": "cvo-instance-profile-version10-f21de2f5-63be-11ef-a3f3-7ba0fb45a1c4", "_result": "arn:aws:cloudformation:us-east-1:691999302746: stack/cvo-instance-profile-version10-f21de2f5-63be-11ef-a3f3-7ba0fb45a1c4/1f15a3f0-63bf-11ef-8ed9-0affc143be6f", "disableRollback": true, "tags": { "InstanceProfileResourcesStackName": "cvo-instance-profile-version10-f21de2f5-63be-11ef-a3f3-7ba0fb45a1c4" }, "_region": "us-east-1", "templateIsUrl": false, "templateName": null, "timeout": "15 minutes", "parameters": { "EC2Endpoint": "ec2.amazonaws.com", "FabricPoolBucketName": "fabric-pool-f21de2f5-63be-11ef-a3f3-xxxyyyyyyy", "S3ARN": "arn:aws:s3" } }
影響:
- CVOの作成は成功するが、AWS S3への階層化(FabricPool)やCBSは不可
AWS S3 buckets
コネクターcanvas
->には表示されません。storage