awslabs / landing-zone-accelerator-on-aws

Deploy a multi-account cloud foundation to support highly-regulated workloads and complex compliance requirements.
https://aws.amazon.com/solutions/implementations/landing-zone-accelerator-on-aws/
Apache License 2.0
564 stars 449 forks source link

fix(constructs): service linked role missing permissions #631

Open richardkeit opened 3 weeks ago

richardkeit commented 3 weeks ago

Issue #, if available:

https://github.com/awslabs/landing-zone-accelerator-on-aws/issues/629

Description of changes:

Adds permission that was required.

Note: Still issues with snapshots raised in https://github.com/awslabs/landing-zone-accelerator-on-aws/issues/624 & attempted to be fixed https://github.com/awslabs/landing-zone-accelerator-on-aws/pull/611

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

hickeydh-aws commented 1 week ago

Hello @richardkeit,

Thank you for taking the time to create this MR. Our team is reviewing this change and we will get back to you if we have any questions!

richardkeit commented 1 week ago

Hi @hickeydh-aws,

I raised AWS Support case (173084606300187), attaching Cloudtrail logs for evidence of the missing permission. Raised another case (173101637500383) in a different Organization as it occurred there also.

Also hoping for https://github.com/awslabs/landing-zone-accelerator-on-aws/pull/611 that I raised to be merged in (first), given there is duplicate of the update snapshots due to issue https://github.com/awslabs/landing-zone-accelerator-on-aws/issues/624

hickeydh-aws commented 1 week ago

Thank you for the extra context. We will evaluate the above PRs as well.