aws-samples / aws-samples/eks-workshop-v2

[Bug]: deletion fails - no permissions to remove termination protection in stack : eksctl-eks-workshop-nodegroup-default

Open
#1,853 0 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
HCL
Stars
626
Forks
613
Avg merge
2d 7h
Merged PRs (30d)
9

Description

### Installation method

Own AWS account

### What happened?

#### Summary :
- The de-installation script running in the IDE does not have IAM permissions to deactivate termination protection for three CloudFormation stacks:
- `eksctl-eks-workshop-nodegroup-default`
- `eksctl-eks-workshop-addon-vpc-cni`
- `eksctl-eks-workshop-cluster`.
- After removing manually (AWS Console, CloudFormation service) the termination protection for the three stacks, the de-installation script runs smoothly:
```
ec2-user:~/environment:$ eksctl delete cluster $EKS_CLUSTER_NAME --wait
2026-05-29 17:40:56 [ℹ] deleting EKS cluster "eks-workshop"
2026-05-29 17:40:56 [ℹ] deleted 0 Fargate profile(s)
2026-05-29 17:40:57 [ℹ] cleaning up AWS load balancers created by Kubernetes objects of Kind Service or Ingress
2026-05-29 17:40:57 [ℹ] 1 task: { delete cluster control plane "eks-workshop" }
2026-05-29 17:40:57 [ℹ] will delete stack "eksctl-eks-workshop-cluster"
2026-05-29 17:40:57 [ℹ] waiting for stack "eksctl-eks-workshop-cluster" to get deleted
2026-05-29 17:40:57 [ℹ] waiting for CloudFormation stack "eksctl-eks-workshop-cluster"
2026-05-29 17:41:27 [ℹ] waiting for CloudFormation stack "eksctl-eks-workshop-cluster"
2026-05-29 17:42:09 [ℹ] waiting for CloudFormation stack "eksctl-eks-workshop-cluster"
2026-05-29 17:44:07 [ℹ] waiting for CloudFormation stack "eksctl-eks-workshop-cluster"
2026-05-29 17:44:07 [✔] all cluster resources were deleted
```

#### More details

- Note: running in eu-west-1 region, not one of the officially supported regions.

- Followed clean up instructions from: https://www.eksworkshop.com/docs/introduction/setup/your-account/cleanup
- In IDE, first ran `delete-environment` - all OK
- then ran `eksctl delete cluster $EKS_CLUSTER_NAME --wait`
- Got the following output and IAM permissions error:
```
ec2-user:~/environment:$ eksctl delete cluster $EKS_CLUSTER_NAME --wait
2026-05-29 17:16:11 [ℹ] deleting EKS cluster "eks-workshop"
2026-05-29 17:16:11 [ℹ] will drain 0 unmanaged nodegroup(s) in cluster "eks-workshop"
2026-05-29 17:16:11 [ℹ] starting parallel draining, max in-flight of 1
2026-05-29 17:16:11 [ℹ] deleted 0 Fargate profile(s)
2026-05-29 17:16:11 [ℹ] cleaning up AWS load balancers created by Kubernetes objects of Kind Service or Ingress
2026-05-29 17:16:12 [ℹ]
4 sequential tasks: { delete nodegroup "default", delete IAM OIDC provider, delete addon IAM "eksctl-eks-workshop-addon-vpc-cni", delete cluster control plane "eks-workshop"
}
2026-05-29 17:16:12 [ℹ] 1 error(s) occurred while deleting cluster with nodegroup(s)
2026-05-29 17:16:12 [✖] disabling termination protection on stack "eksctl-eks-workshop-nodegroup-default": operation error CloudFormation: UpdateTerminationProtection, https response error StatusCode: 403, RequestID: bae116de-f2a1-41fc-be81-a4e051eecc68, api error AccessDenied: User: arn:aws:sts::659916668326:assumed-role/eks-workshop-ide-EksWorkshopIdeRole-3z6cj7u4F6br/i-0d7454adf4e0de595 is not authorized to perform: cloudformation:UpdateTerminationProtection on resource: arn:aws:cloudformation:eu-west-1:659916668326:stack/eksctl-eks-workshop-nodegroup-default/9cd4b2c0-5a73-11f1-9eb6-0a5f3c0af2cd because no identity-based policy allows the cloudformation:UpdateTerminationProtection action
Error: failed to delete cluster with nodegroup(s)
```

Once I deactivated termination protection for CFN stack `eksctl-eks-workshop-nodegroup-default` and retried the deletion, a similar error popped up for stack `eksctl-eks-workshop-addon-vpc-cni`.

Repeated the workaround and retried the deletion. This time the same error for stack `eksctl-eks-workshop-cluster` - did the same. after this the de-installation script ran smoothly.

### What did you expect to happen?

Deletion of cluster and related resources with CloudFormation called by eksctl

### How can we reproduce it?

Follow instructions from: https://www.eksworkshop.com/docs/introduction/setup/your-account/cleanup

### Anything else we need to know?
- Note: running in eu-west-1 region, not one of the officially supported regions.
- Workaround:
- in the AWS Console, navigate to CloudFormation
- search for stack `eksctl-eks-workshop-nodegroup-default` (or other stack that produces the same error)
- under `actions` dropdown, select `Edit Termination Protection`
- deactivate termination protection
- then, in the IDE, repeat the eksctl command to delete.
### EKS version

1.33

Contributor guide

Open the contributing guide

Research direction

Start with the cleanup instructions and the IDE de-installation flow, including delete-environment and the eksctl delete cluster command. Trace where the IAM policy for eks-workshop-ide-EksWorkshopIdeRole is defined and verify the CloudFormation termination-protection operation. Done means cleanup completes without manually disabling termination protection in the AWS Console.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes
Domain
cloud, infrastructure, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.