-
Notifications
You must be signed in to change notification settings - Fork 3.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
(amplify-alpha): The default created role is empty #28986
Comments
I'm happy to kick off a pull request adding the managed policy if that's a good fix |
Thank you for the report. I am not sure if it's a good idea but feel free to submit a PR for that. |
It's very user unfriendly, mainly for an inexperienced CDK user, that it doesn't even setup the CloudWatch log roles for Web Compute Apps. In case anyone else with as little experience as me stumbles upon this, here's a quick and dirty way to setup the CloudWatch log roles to be able to debug your deployed app. const app = new amplify.App(...)
app.grantPrincipal.addToPrincipalPolicy(
new PolicyStatement({
actions: ['logs:CreateLogStream', 'logs:CreateLogGroup', 'logs:DescribeLogGroups', 'logs:PutLogEvents'],
resources: ['*'],
}),
); |
Describe the bug
When I create an amplify app, the associated role has no policies.
Expected Behavior
If I do the same thing in the web interface it creates a role with the managed policy
AdministratorAccess-Amplify
attachedCurrent Behavior
The role has no policies
Reproduction Steps
Possible Solution
I've worked around this by manually creating and passing in a role
Additional Information/Context
No response
CDK CLI Version
2.125.0
Framework Version
No response
Node.js Version
20.11.0
OS
Linux
Language
TypeScript
Language Version
No response
Other information
No response
The text was updated successfully, but these errors were encountered: