awslabs / awslabs/aws-deployment-framework
[Bug]: adf-glabal-base-deployment cloudformation stack Update failed
- Dominant language
- Python
- Stars
- 699
- Forks
- 235
- Avg merge
- 20h 53m
- Merged PRs (30d)
- 7
Description
### Is there an existing issue for this?
- [x] I have searched the existing issues
### Describe the bug
When adf-glabal-base-deployment stack run it get stuck due to s3:PutBucketPolicy missing permission.
ADF 4.0.0
### Expected Behavior
The adf-glabal-base-deployment cloudformation stack should run without error.
### Current Behavior
Resource handler returned message: "User: arn:aws:sts:::assumed-role/adf-bootstrap-update-deployment-role/management is not authorized to perform: s3:PutBucketPolicy on resource: "arn:aws:s3:::adf-global-base-deployment-pipelinebucket-xxxxxxxx" because no identity-based policy allows the s3:PutBucketPolicy action
### Steps To Reproduce
_No response_
### Possible Solution
_No response_
### Additional Information/Context
_No response_
### ADF Version
4.0.0
### Contributing a fix?
- [x] Yes, I am working on a fix to resolve this issue
Contributor guide
Research direction
Start by inspecting the adf-glabal-base-deployment CloudFormation stack and the adf-bootstrap-update-deployment-role policy. Verify why s3:PutBucketPolicy is missing, then confirm that the stack update completes successfully on ADF 4.0.0 without the authorization error.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, devops, infrastructure
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100