Skip to content

IAM role ARN value is invalid or does not include the required permissions for: S3_SNAPSHOT_INGESTION

0

We are trying to restore an RDS MySQL database from a backfile on an S3 instance. However, our request to create DB Instance fails with the following error message: "IAM role ARN value is invalid or does not include the required permissions for: S3_SNAPSHOT_INGESTION"

Any help would be greatly appreciated.

Thanks!

  • Please accept the answer if it was useful for you

2 Answers
2
EXPERT
answered 2 years ago
EXPERT
reviewed 2 years ago
EXPERT
reviewed 2 years ago
  • I am also seeing the error message IAM role ARN value is invalid or does not include the required permissions for: S3_SNAPSHOT_INGESTION.

    I have ensured that the Role ARN provided does have:

    s3:ListBucket s3:GetBucketLocation s3:GetObject

    permissions on the correct bucket. (It is the same role ID that was used to export the snapshot), as mentioned in the first article linked above, and also the kms:Decrypt. What other permissions might be required? Is a more specific error message available in logs somewhere?

    EDIT: Same error message is seen even if choosing the Create a New Role option.

0

The error message you're encountering suggests that the IAM role associated with your RDS instance does not have the necessary permissions to access the S3 bucket containing the database snapshot. To resolve this issue, you need to update the IAM role's policy to include the required permissions for S3 snapshot ingestion.

answered 2 years ago
EXPERT
reviewed 2 years ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.