amazon-web-servicesamazon-ec2amazon-iamautoscalingaws-code-deploy

Simple IAM Issue with CodeDeploy


I'm having an issue with a seemingly trivial task of getting CodeDeploy to deploy Github code to an AutoScaling Group in a Blue/Green Deployment.

I have a Pipeline setup, a Deployment Group setup, and the AutoScaling Group, but it fails when it gets to the actual deployment:

enter image description here


I went to my role and it seems like it has sufficient policies for it to go through with the blue/green deployment:

enter image description here


Is there a policy that I'm not considering that needs to be attached to this role?


Solution

  • I was also getting the error:

    "The IAM role does not give you permission to perform operations in the following AWS service: AmazonAutoScaling. Contact your AWS administrator if you need help. If you are an AWS administrator, you can grant permissions to your users or groups by creating IAM policies."

    I figured out the 2 permissions needed to get past this error, I created the policy below and attached it to the Code Deploy role:

    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": [
                    "iam:PassRole",
                    "ec2:RunInstances",
                    "ec2:CreateTags"
                ],
                "Resource": "*"
            }
        ]
    }