How to run aws-nuke via AWS CLI using IAM role assuming

Viewed 775

I was able to run aws-nuke on one account using AWS CLI. Now I am trying to run aws-nuke to delete all the resources using IAM role assuming

I am trying to run command

 aws-nuke -c config/nuke-config.yaml 

config/nuke-config.yaml
    ---
    regions:
    - "global" # This is for all global resource types e.g. IAM
    
    
    account-blacklist:
    - "999999999999" # production
    
    
    # optional: restrict nuking to these resources
    resource-types:
      targets:
      - S3Bucket
      - S3Object
      - EC2Instance
      - CloudFormationStack
    
    accounts:
     "555133742123" #IAM alias is "test-account":

Got this Error:

Error: The specified account doesn't have an alias. For safety reasons you need to specify an account alias. Your production account should contain the term 'prod'.

You can see the Error message in the screenshot below.

enter image description here

I also ran aws-nuke on another account and it was able to identify the IAM Alias without any issue. What's missing here?

3 Answers

I was able to look at the source of the error, which is shown the error on aws-nuke code line 100.

From there I would look at the calls to ValidateAccount(). The relevant call is on line 43.

Once narrowing down the issue and error message, I would figure out why the Account.Aliases() is empty. It looks like "Account" is a resource type in AWS. So I would reproduce the call to fetch the account resource, e.g. using boto3 or the AWS CLI. Then I'd confirm that it's also empty there. Then I'd figure out how to set the alias

To check if the account aliases is empty: You can run this AWS CLI:

aws iam list-account-aliases

If it is empty list, it means that the IAM Alias is missing.

Then, you need to assign IAM Alias to the AWS account that needs to be nuked. Use you can use this AWS CLI:

aws sts get-caller-identity

This will let you know which account you are signed in into using CLI

Once you have assigned an IAM alias to the AWS account, this should resolve the aws-nuke error that you sees.

Error: The specified account doesn't have an alias. For safety reasons you need to specify an account alias. Your production account should contain the term 'prod'.

I found the author of aws-nuke in the discussion here and another post.

Disclaimer: Here's what the aws-nuke author says:

This is not a configuration problem of the YAML file, but it's a missing setting in the AWS account.

AWS IAM Alias is a globally unique name for the AWS Account. aws-nuke requires this as a safety guard, so this do not accidentally destroy the production accounts. The idea is that every production account contains at least the substring prod.

Follow the AWS docs to specify the Alias via the web console, or use the AWS CLI:

aws iam create-account-alias --profile demo --account-alias aws-nuke-test-account-8gmst3`
Related