Unexpected EC2 error while attempting to Create Network Interface UnauthorizedOperation while using boto3

0

While trying to start a task of a ECS cluster using the aws API key with boto3 for my own account, the task container was created and immediately killed due to an error:

*Unexpected EC2 error while attempting to Create Network Interface in subnet 'subnet-xxxxxxxxxxxxxxxxx': UnauthorizedOperation *

However, I was able to start a task in a ECS cluster via web GUI using the same subnet. When the container was created, it is in the subnet I am expecting.

The task launch type is FARGATE, platform version is 1.4.0. Task role has been defined and used in either manual or script launch mode. Network mode shows awsvpc. In case of failed script launch, the EIN id is 'unset'.

Can someone help understand this issue? It will be nice to know how to enable the log for the launching of a container. At this moment, I only see the container logs after a container is successfully launched via web gui.

Thank you!

  • Its worth checking the CloudTrail event history to find out the request parameters and the IAM user/role being used for the operation. Search for the EventName "CreateNetworkInterface" in your CloudTrail event history and see if that helps!

JM
已提问 2 年前2186 查看次数
1 回答
0

It appears to be a security group related. The automation script used a different security group which has much more limitation. The manual process via web ui used a different security group.

However, I don't understand how security group blocks CreateNetworkInterface.

Thanks.

JM
已回答 2 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则