Unable to associate IAM instance profile to mediator during CVO HA deployment in AWS
Applies to
- BlueXP
- Cloud Volumes ONTAP (CVO)
- Amazon Web Services (AWS)
- IAM
Issue
When deploying a new CVO HA pair in AWS, the actions fails with the following error seen in BlueXP timeline:
The following resource(s) failed to create: [IamHAAdminRole]. Resource handler returned message: "Encountered a permissions error performing a tagging operation, please add required tag permissions. See https://repost.aws/knowledge-center/...rmission-error for how to resolve. Resource handler returned message: "User: arn:aws:sts::XXXXXX:assumed-role/<Custom_IAM_Role_Name/<ec2_instance_iD>" is not authorized to perform: iam:TagRole on resource XXXXXX because no identity-based policy allows the iam:TagRole action (Service: Iam, Status Code: 403,HandlerErrorCode: UnauthorizedTaggingOperation)