Creating AWS CVO-HA failed with error due to AccessDenied
Applies to
- NetApp BlueXP (BXP)
- NetApp Cloud Volume ONTAP (CVO)
- Amazon Web Service (AWS)
Issue
When creating an AWS CVO HA instance, it failed due to the below error from the Timeline:
Create Aws Ha Working Environment BlueXP Failed
Error:The following resource(s) failed to create: [IamHAAdminRole]. Resource handler returned message: "User: arn:aws:sts::xxxxxxxxxx:assumed-role/PROD-Connector-xxxxxxxxx-OCCMIAMRole-xxxxxxxxx/i-0784fxxxxxxx is not authorized to perform: iam:CreateRole on resource: arn:aws:iam::xxxxxxxxxx:role/xxxx-mediator-IamHAAdminRole-xxxxx because no permissions boundary allows the iam:CreateRole action (Service: Iam, Status Code: 403, Request ID: 9847a8dd-4816-463d-a11d-xxxxxx)" (RequestToken: be5a24d2-e455-8381-b290-xxxxxx, HandlerErrorCode: AccessDenied)