I have a cloudformation template that works with AWS CLI but failed in CodePipeline due to the following error:
API: iam:CreateRole User: arn:aws:sts::xxxxxxxxxx:assumed-role/xxxxxxx-role/AWSCloudFormation is not authorized to perform: iam:CreateRole on resource: arn:aws:iam::xxxxxxxxxx:role/xxxxxxxxxInstanceRole-xxxxxxx because no identity-based policy allows the iam:CreateRole action
Can anyone show me how to create identity-based policy allows the iam:CreateRole action?
Thanks in advance!