AWS SAM deployed Error under hello world template

Viewed 3051

I'm currently working on AWS serverless lambda function deployment and try to distribute and test with AWS SAM. However, when I followed the AWS SAM hello world template tutorial on official website, I can't really deploy my code to AWS.

I've already

  1. Assigned a working IAM account
  2. Install every package we need for AWS SAM (brew, aws-sam-cli...etc)
  3. Set up AWS configuration
  4. Using a function template provided by AWS

Yet, I got error message

Error: Stack aws-sam-cli-managed-default is missing Tags and/or Outputs information and therefore not in a healthy state (Current state:aws-sam-cli-managed-default). Failing as the stack was likely not created by the AWS SAM CLI

3 Answers

Took me a minute to figure out too.

Open up CloudFormation in AWS and delete the aws-sam-cli-managed-default stack then try to redeploy.

Every time your deploy fails you'll likely have to do this again.

It's aws credentials error - because you not configure it right or not config at all.

If you didn't have aws cli installed on your computer, find aws cli installer for your filesystem, for mac it's https://docs.aws.amazon.com/cli/latest/userguide/install-cliv2-mac.html.

Go to https://console.aws.amazon.com/iam and create new user with AdministratorAccess permission and get aws_access_key_id and aws_secret_access_key.

Go to your terminal and type aws configure.

Enter your credentials.

Try to run sum build && sum deploy --guided

Now it's need to work.

Like @Eli Meiler says, it may well be a credential issue. If you need to see more details here try

$ aws cloudformation describe-change-set --change-set-name InitialCreation --stack-name aws-sam-cli-managed-default

...FAILED  User: arn:aws:iam::123:user/<human user> is not authorized to perform:
cloudformation:CreateChangeSet
on resource: arn:aws:cloudformation:eu-central-1:aws:transform/Serverless-2016-10-31
with an explicit deny in an identity-based policy

EDIT

Even though I had full permissions in that AWS account, what I was not aware was that MFA / 2-factor auth is kinda troublesome here.

The advice that worked for me was this github comment to

  • generate an sts token
  • set the env vars and
  • then try sam deploy --guided again
$ aws sts get-session-token --serial-number arn:aws:iam::<account_id>:mfa/<human.user>  --duration-seconds 15000 --token-code 123456
Related