aws / aws/aws-cdk

aws-iot: How to attach an IoT Policy to a Thing Group

Open
#26,166 10 comments 0 reactions 0 assignees View on GitHub
@aws-cdk/aws-iot effort/medium feature-request needs-cfn p2
Dominant language
TypeScript
Stars
12.9k
Forks
4.6k
Avg merge
2d 3h
Merged PRs (30d)
83

Description

### Describe the feature

IoT Core allows to attach an IoT Policy to a Thing Group, but 'CfnPolicyPrincipalAttachment' fails at deploy time if we the pass principal as CfnThingGroup..attrArn.
The error message is:
12:12:40 PM | CREATE_FAILED | AWS::IoT::PolicyPrincipalAttachment | quarPolicyAttachment
The given ARN does not represent a cert (Service: AWSIot; Status Code: 400; Error Code: InvalidRequestException; Request ID: 8018ecbf-38ff-4493-93c8-6e3a183abb0b; Proxy: null)****

### Use Case

User wants to attach an IoT Policy to a Thing Group.
One common case is to create a Quarantine group used to isolate Things with unexpected behaviour.

### Proposed Solution

CfnPolicyPrincipalAttachment to accept a Thing Group ARN for a Static Group.

### Other Information

_No response_

### Acknowledgements

- [ ] I may be able to implement this feature request
- [ ] This feature might incur a breaking change

### CDK version used

aws-cdk@2.85.0

### Environment details (OS name and version, etc.)

Clou9 on Linux

Contributor guide

Open the contributing guide

Research direction

Start with the CfnPolicyPrincipalAttachment and CfnThingGroup entry points, focusing on how attrArn is passed as the principal. Reproduce the deployment failure described for a static Thing Group, then verify that a Thing Group ARN is accepted while existing certificate attachment behavior remains intact.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, typescript
Domain
cloud, infrastructure
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.