- Le plus récent
- Le plus de votes
- La plupart des commentaires
Short Description:
Setting up an AWS pipeline and using the following AWS documentation [1] “Example Permissions Policies for AWS Data Pipeline Roles” reference policy and getting errors for invalid actions.
Resolution:
-
There is an extraneous space on L16 in the referenced documentation, meaning the policy itself is not valid JSON. To resolve this error update the account ID in the resource ARN and make sure there are no extraneous spaces. Account IDs are 12-digit integers [1].
-
The API elasticmapreduce:GetCluster does not exist but there are other supported API’s such as DescribeCluster and ListClusters that can be used as per document [2] for reference.
-
The API s3:ListMultipartUploads is a valid API but cannot be specified in a policy but s3:ListMultipartUploadParts is the equivalent as per document [3] for reference.
-
The API s3:GetObjectMetadata does not exist but you may use s3:GetObjectAttributes as the API Retrieves all the metadata from an object without returning the object itself. This action is useful if you're interested only in an object's metadata [4].
Lastly, you are correct in your assumption and I have notified the internal team of the invalid API’s in the "AWS Data Pipeline" documentation.
If further assistance is required to troubleshoot a specific error received, may I recommend opening an Internal Ticket with AWS Support for further assistance.
References:
[1] https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-reference-policy-checks.html
[2] https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazonelasticmapreduce.html
[3] https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazons3.html
[4] https://docs.aws.amazon.com/AmazonS3/latest/API/API_GetObjectAttributes.html
- Line 16: The example has a space after the account number, remove the space.
- Line 70: I would try DescribeCluster instead of GetCluster
- Line 97: Your substitution looks reasonable
- Line 111: Your substitution looks reasonable
Contenus pertinents
- demandé il y a 7 mois
- demandé il y a 6 mois
- demandé il y a 2 mois
- AWS OFFICIELA mis à jour il y a 3 ans
- AWS OFFICIELA mis à jour il y a 2 ans