aws-cloudformation / aws-cloudformation/cloudformation-cli

CloudFormationManagedUploadInfrastructure setup issues

Offen
#720 0 Kommentare 2 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Python
Sterne
336
Forks
172
Ø Merge
3 T. 5 Min.
Gemergte PRs (30 T.)
3

Beschreibung

A customer attempted to register modules using CodeBuild and reported this to us:

- The registration failed with "internal failure". It was not clear what the error was. In the end it turned out that the CodeBuild service role was missing `kms:decrypt` permissions against the KMS key used by the S3 bucket (the same KMS Key generated by the CloudFormationManagedUploadInfrastructure stack). CFN CLI should give more descriptive error messages.
- When `CloudFormationManagedUploadInfrastructure` generates, the stack should provide a "AWS::KMS::Alias" to simplify KMS key management, KMS permissions, and with making templates across many accounts.
- We should provide guidance on what the `CloudFormationManagedUploadInfrastructure` stack is and what it does. (For this point, i'm not sure if this should be explained in this repo, or in the CloudFormation user guide).

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne damit, den Registrierungsablauf der CFN CLI und den im Bericht erwähnten Stack CloudFormationManagedUploadInfrastructure nachzuverfolgen. Prüfe, wie interne Fehler nach außen gegeben werden und wie der KMS-Schlüssel generiert wird, und sieh dir anschließend die Frage im CloudFormation-Benutzerhandbuch an. Als erledigt gilt die Aufgabe, wenn die angeforderten Hinweise zu Fehlern, der KMS-Alias und die Stack-Erklärung klare Verantwortliche sowie entsprechende Änderungen an Implementierung oder Dokumentation haben.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
aws
Bereich
cloud, infrastructure, security
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
30/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.