Policy Simulator failed for AmazonECSTaskExecutionRolePolicy

0

Why did the Policy Simulator fail for AmazonECSTaskExecutionRolePolicy ?

Please, see the screenshot in attachment.

Enter image description here

질문됨 일 년 전202회 조회
2개 답변
2
수락된 답변

Hi,

It's because, there is no allow statement for ECS. In the first simulation, I replicated as you did and in the second one I added "ecs:RunTask" in the same policy and then tested, policy simulator showed me as allowed for RunTask.

Simulation1

Simulation2

Feel free to comment here, if you see any further challenge, I'm happy to help. If that answers your question, please accept the answer.

PS: If you look at description of AmazonECSTaskExecutionRolePolicy, it says that it "Provides access to other AWS service resources that are required to run Amazon ECS tasks". Hope that helps.

profile pictureAWS
전문가
답변함 일 년 전
profile picture
전문가
검토됨 일 년 전
0

Thanks. I am new to AWS and I created a new user group with minimal rights to run ECS tasks.

According to your answer, that means that I have to add the permission ecs:RunTask additionally to the AmazonECSTaskExecutionRolePolicy that comes pre defined with AWS. This role or at least its name or description is really confusing.

I will adjust the permissions for the group. Thanks !

  • Absolutely. Yes, permission should be there. Role name may be misinterpreted but description explains it well. Feel free to post your questions here on repost. This community would always be ready to help along with your your learning journey.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠