How to solve this? AWS updateAutoScalingGroup - error: AccessDenied: You are not authorized to use launch template

Viewed 9488

(Solved)

I missed this mention on the aws user guide You can use the AmazonEC2FullAccess policy to give users complete access to work with Amazon EC2 Auto Scaling resources, launch templates, and other EC2 resources in their AWS account

Now I added permissions as same as on the AmazonEC2FullAccess policy on my custom policy, and the lambda is working well.

The AmazonEC2FullAccess has full permissions of CloudWatch, EC2, EC2 Auto Scaling, ELB, ELB v2, and limited IAM write permission.

@Marcin _ Thanks! your comment made me check this part.

I'm trying to update the ASG with 'updateAutoScalingGroup' API on lambda.

But this error "AccessDenied: You are not authorized to use launch template" is blocking me...

At the first time, I applied only related permissions on the IAM policy depend on the document, but now I allowed full permissions of EC2 and Autoscaling on the policy to solve this issue. But no lucks.

On google, I saw some posts that saying this is just an error, or issue from AMI existence. But my AMI for the launch template is in the same account, same region...

Could you give me some hint or reference to solve this?

Thanks

const AWS = require('aws-sdk')

exports.handler = (event) => {
    const autoscaling = new AWS.AutoScaling()
    
    const { asgName, templateName, version } = event
    
    const params = {
        AutoScalingGroupName: asgName,
        LaunchTemplate: {
            LaunchTemplateName: templateName, 
            Version: version
        },
        MaxSize: 4,
        MinSize: 1,
        DesiredCapacity: 1
    }

    autoscaling.updateAutoScalingGroup(params, async (err, data)=> {
        if(err) console.log("err---", err)
        else console.log("data---", data)
    })
};

Below was added after the comments from Marcin, John Rotenstein, samtoddler

  1. Now the policy has full permission for EC2, EC2 Auto Scaling, EC2 Image Builder, Auto Scaling, and some permissions on CloudWatch Logs. But no lucks yet.
  2. The AMI is in the same account, same region. And I added the account number on the 'Modify Image Permissions' on it. (I don't know well on this but just tried.)
  3. describeLaunchTemplates() shows the launchTemplate which I want to use.
  4. CloudTrail shows 'RunInstances' and 'UpdateAutoScalingGroup' events. 'RunInstances' returned "errorCode": "Client.UnauthorizedOperation", and 'UpdateAutoScalingGroup' returned "errorCode": "AccessDenied", "errorMessage": "An unknown error occurred"
  5. Without LaunchTemplate part, API is working well. (I tried update the min and max count only, and it succeed.)
  6. Even I changed AMI as public, it's not working for this.

Now I'm trying to search about launch template and AMI related configuration..

2 Answers

Unfortunately, the errors provided by AWS in some cases are very unclear and could mislead.

Besides checking that you have the proper rights, this error is also returned when you are trying to create an autoscaling group with an invalid AMI or one that doesn't exist.

Actually, problem is your EC2 instance is having an IAM Role which you are not authorised to use it. Add below policy to lambda or whatever role or IAM user you using to pass the role that is attached to EC2 instance. Once that is done it will start working.

{
    "Version": "2012-10-17",
    "Statement": [{
        "Effect": "Allow",
        "Action": [
            "iam:GetRole",
            "iam:PassRole"
        ],
        "Resource": "arn:aws:iam::account-id:role/EC2-roles-for-XYZ-*"
    }]
}

Related