awslabs / awslabs/aws-deployment-framework

[Bug]: adf-glabal-base-deployment cloudformation stack Update failed

Open
#780 0 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Python
Stars
699
Forks
235
Avg merge
20h 53m
Merged PRs (30d)
7

Description

### Is there an existing issue for this?

- [x] I have searched the existing issues

### Describe the bug

When adf-glabal-base-deployment stack run it get stuck due to s3:PutBucketPolicy missing permission.
ADF 4.0.0

### Expected Behavior

The adf-glabal-base-deployment cloudformation stack should run without error.

### Current Behavior

Resource handler returned message: "User: arn:aws:sts:::assumed-role/adf-bootstrap-update-deployment-role/management is not authorized to perform: s3:PutBucketPolicy on resource: "arn:aws:s3:::adf-global-base-deployment-pipelinebucket-xxxxxxxx" because no identity-based policy allows the s3:PutBucketPolicy action

### Steps To Reproduce

_No response_

### Possible Solution

_No response_

### Additional Information/Context

_No response_

### ADF Version

4.0.0

### Contributing a fix?

- [x] Yes, I am working on a fix to resolve this issue

Contributor guide

Open the contributing guide

Research direction

Start by inspecting the adf-glabal-base-deployment CloudFormation stack and the adf-bootstrap-update-deployment-role policy. Verify why s3:PutBucketPolicy is missing, then confirm that the stack update completes successfully on ADF 4.0.0 without the authorization error.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, devops, infrastructure
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.