fortinet / aws-cloudformation-templates

Cloud Formation Templates for getting you started in AWS with Fortinet.
MIT License
34 stars 67 forks source link

Does this CFT template works for AWS China #18

Open skaas-cloudsec opened 2 years ago

skaas-cloudsec commented 2 years ago

Hi All,

We are facing issues while deploying this CFT template in AWS China region. Please suggest

2 Errors:

[ERROR] 2022-06-28T12:32:26.256Z 74510861-6c86-41a1-8a82-cc4b037ce51b <--!! Exception: An error occurred (AccessDenied) when calling the PutObject operation: User: arn:aws-cn:sts::xxxxxxxxx:assumed-role/ec2cnbfortigate-LambdaRole-SU3TB0KACIDM/ec2cnbfortigate-InitFunction-k0ups0YllBeU is not authorized to perform: kms:GenerateDataKey on resource: arn:aws-cn:kms:cn-north-1:xxxxxxxx:key/acbcd-c6cb-4a90-8798-asdasdasf123 because no identity-based policy allows the kms:GenerateDataKey action

[ERROR] 2022-06-28T12:32:01.679Z c2a620ae-d73f-45bf-ba08-06e8ef98b6ec !!--> Unable to find AMI in response! {'Images': [], 'ResponseMetadata': {'RequestId': 'ab5f7568-dd5d-460e-98a5-9d643d3c46a8', 'HTTPStatusCode': 200, 'HTTPHeaders': {'x-amzn-requestid': 'ab5f7568-dd5d-460e-98a5-9d643d3c46a8', 'cache-control': 'no-cache, no-store', 'strict-transport-security': 'max-age=31536000; includeSubDomains', 'content-type': 'text/xml;charset=UTF-8', 'content-length': '219', 'date': 'Tue, 28 Jun 2022 12:32:01 GMT', 'server': 'AmazonEC2'}, 'RetryAttempts': 0}}

skaas-cloudsec commented 2 years ago

Please help with a response

Joel-Cripps commented 2 years ago

It doesn't sound like it will. The Chinese regions don't have the same AMI format, so the functions to grab those would have to change.

aaa815 commented 1 year ago

I have same issue.. any solution seen in coming days?

aaa815 commented 1 year ago

It works as i have deployed the same in AWS China