Description of problem:
Under the heading "Additional IAM and S3 permissions that are required to create manifests" we request the s3:HeadBucket IAM permission which does not exist, I think this needs to be changed to s3:ListBucket because when I add that permission in the AWS policy console it has an error: "Invalid Action: The action s3:HeadBucket does not exist. Did you mean s3:ListBucket? The API called HeadBucket authorizes against the IAM action s3:ListBucket." Additionally we can remove s3:GetBucketReplication since it does not exist and is covered by s3:GetReplicationConfiguration
- is cloned by
-
OCPBUGS-31819 Document an RN known issue that requests a non-existent AWS s3:HeadBucket perm
- Closed
- is related to
-
OCPBUGS-31813 AWS: Installer requires nonexistent s3:HeadBucket permission
- Closed
- relates to
-
OCPBUGS-33661 aws: rename `preserverBootstrapIgnition` install-config option
- Closed
-
OCPBUGS-33662 aws: do not require s3:Delete* perms if `preserveBootstrapIgnition` is set
- Closed
- links to
(3 links to)