aws-cloudformation / aws-cloudformation/cloudformation-cli

Execution role is missing `cloudformation:ListExports`

Open
#941 0 comments 0 reactions 1 assignee Claimed by @ericzbeard View on GitHub
bug p1
Dominant language
Python
Stars
336
Forks
172
Avg merge
3d 5m
Merged PRs (30d)
3

Description

When running `cfn generate`, `resource-role.yaml` is created based on the roles required in the resource schema. If the user provides `inputs` for testing and includes a template variable in the inputs, `test-type` fails.

```
botocore.exceptions.ClientError: An error occurred (AccessDenied) when calling the ListExports operation:
User: arn:aws:sts::755952356119:assumed-role/awscommunity-s3-deletebucketcontents-ExecutionRole-AJU1L19ZAMNZ/CloudFormationContractTest-20221112002935
is not authorized to perform: cloudformation:ListExports because no identity-based policy allows the cloudformation:ListExports action
```

The workaround is to manually edit `resource-role.yaml` to add the missing action.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.