aws-samples / aws-samples/sample-developer-tutorials
059-amazon-datazone-gs: requires Identity Center + DataZone integration
- Ngôn ngữ chính
- Shell
- Star
- 175
- Fork
- 42
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
## Problem
CreateEnvironmentProfile requires the calling principal to be a DataZone project member via Identity Center. DataZone uses its own authorization model separate from IAM.
## Current state
- Script creates domain and projects successfully
- Fails at CreateEnvironmentProfile with AccessDeniedException
- `--managed` flag fix applied for blueprint listing
## Steps to resolve
1. Configure DataZone domain to use Identity Center for user management
2. Map an IC user as a DataZone project owner
3. Run the script as that IC user
4. Test end-to-end
5. Add back to the non-interactive PR
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu với script 059-amazon-datazone-gs và kiểm tra lệnh gọi CreateEnvironmentProfile cùng các giả định hiện tại của nó về Identity Center. Cấu hình miền DataZone để quản lý người dùng Identity Center, ánh xạ một người dùng Identity Center làm chủ sở hữu dự án và chạy script với tư cách người dùng đó. Hoàn tất khi quy trình thành công từ đầu đến cuối và thay đổi này có thể được thêm lại vào PR không tương tác.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- aws, shell
- Lĩnh vực
- authorization, cloud
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 45/100