The AWS CloudFormation Public Coverage Roadmap
Creative Commons Attribution Share Alike 4.0 International
1.1k
stars
53
forks
source link
AWS::IAM::Role requiring iam:UpdateRoleDescription to update role description #1923
Open
miguel-aws opened 5 months ago
Name of the resource
AWS::IAM::Role
Resource Name
AWS::IAM::Role
Issue Description
Via the IAM console, you can change a role's description with just the iam:UpdateRole permission.
However, updating the description of a role created via CloudFormation requires iam:UpdateRoleDescription.
According to the IAM documentation [1], use UpdateRole instead of UpdateRoleDescription
Why is there a difference in these behavior and does it not follow IAM documentation?
[1] https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateRoleDescription.html
Expected Behavior
CloudFormation uses UpdateRole
Observed Behavior
CloudFormation uses UpdateRoleDescription
Test Cases
Create
Update
Other Details
No response