Skip to content

Assume Role does not work for NetApp connector & CVO deployment #122

@bryanheo

Description

@bryanheo

Hello

We are trying to deploy Connector and CVO via assume role as shown below but it returns an error 'UnauthorizedOperation'.
When we deploy the connector and CVO with IAM user, the deployment works fine. Both IAM user and Assume role use the same policy.
AWS resources are also created with the assume role but only netapp-cloudmanager_connector_aws and netapp-cloudmanager_cvo_aws are not created

Can NetApp resources be deployed by Assume role rather than IAM user?

provider "aws" {
  region = var.region

  assume_role {
    role_arn     = "arn:aws:iam::${var.account_id}:role/tfe-netapp-deploy"
    session_name = "tfe-netapp"
  }

}

Error
Screenshot 2022-08-17 at 21 41 06

Regards
Moon

Metadata

Metadata

Assignees

No one assigned

    Labels

    JiraHas an Internal Jira StoryenhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions