user " is not authorized to perform: sts:AssumeRole on resource: "

Viewed 6753

I created a EKS cluster on aws, and when I tried to access it from aws cli, I bumped into access right issue.

-- my cli user permssion:

enter image description here

-- definition of policy sts_AssumeRol,

enter image description here

-- then when I try to run

siguser@x220:~/ws/aws/eks$ ./kubectl get svc

An error occurred (AccessDenied) when calling the AssumeRole operation: User: arn:aws:iam::xxxxx:user/shichao-aws-cli is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::xxxxx:role/eks-sg-bd-role

what could be the possible cause here? i have tried to run >>aws configure a few times, but to no avail.

============================== edit 1:=======================

trust relationship for role eks-sg-bd-role: enter image description here

policy simulator:

enter image description here

============================== edit 2:======================= enter image description here

siguser@x220:~/ws/aws/eks$ ./kubectl get svc
error: You must be logged in to the server (Unauthorized)

my own solution:

i end up working around the issue with eksctl instead.

eksctl create cluster --name eks-cluster-SG-BD --version 1.16 --region us-east-2 --fargate
0 Answers
Related