Unable to associate IAM instance profile to mediator during CVO HA deployment in AWS
- Views:
- 125
- Visibility:
- Public
- Votes:
- 0
- Category:
- cloud-manager
- Specialty:
- cloud
- Last Updated:
- 6/28/2024, 3:32:53 PM
Applies to
- BlueXP
- Cloud Volumes ONTAP (CVO)
- Amazon Web Services (AWS)
- IAM
Issue
When deploying a new CVO HA pair in AWS, the actions fails with the following error seen in BlueXP timeline:
The following resource(s) failed to create: [IamHAAdminRole]. Resource handler returned message: "Encountered a permissions error performing a tagging operation, please add required tag permissions. See https://repost.aws/knowledge-center/...rmission-error for how to resolve. Resource handler returned message: "User: arn:aws:sts::XXXXXX:assumed-role/<Custom_IAM_Role_Name/<ec2_instance_iD>" is not authorized to perform: iam:TagRole on resource XXXXXX because no identity-based policy allows the iam:TagRole action (Service: Iam, Status Code: 403,HandlerErrorCode: UnauthorizedTaggingOperation)