This question has been edited to indicate that I (a) went ahead and started using Cloud9 as the root user, and then (b) granted console access to the IAM user and switched to using that. Then, based on that, I modified the question that I'm asking. See the end of this question for those edits.
===================================
The documentation for Individual user setup for AWS Cloud9 is confusing. It tells me to sign in as a root user and "you can now start using AWS Cloud9." But right after that, it tells me not to use it as a root user, but as an IAM user. So I created a new IAM user for Cloud9. But I don't see how to sign in with the credentials for that.
The new IAM user has the following four permission policies applied:
- AWSCloud9EnvironmentMember
- AWSCloud9Administrator
- AWSCloud9User
- AWSCloud9SSM
I applied those four because when I was offered a list of 757 policies to choose from, those were all the ones that included "Cloud9" in their names.
The documentation mentioned above says, "Open the AWS Cloud9 console, at https://console.aws.amazon.com/cloud9/." When I click on that, I get the regular sign-in page for the AWS console:
If I sign in as the root user, I get taken to the Cloud9 homepage, which has a button for "Create environment". When I click on that, the page that comes up starts with the warning box:
AWS root account login detected
We do not recommend using your AWS root account to create or work with environments. Use an IAM user instead. This is an AWS security best practice.
Okay, so I logged out and went back to that link for the Cloud 9 console. This time, I clicked on "IAM user". Then it asked for my account ID.
I entered that, and then it asked for my IAM user name and password.
I entered the user name, but this IAM user doesn't have a password. I tried entering the access key ID, and then the secret access key, but with either of those as the password, AWS responded that "Your authentication information is incorrect."
So what do I need to do to access the Cloud9 system as this IAM user?
There's an SO question, Sign in to AWS console without password, which describes the exact same situation. But the accepted answer says to either (a) use the CLI and API, giving a link to the CLI, but the linked page has nothing about signing in, or (b) get a password from the administrator "if you think you require web console access as well." This IAM user was created without console access on purpose because the whole point of this user is just for using Cloud9 without any access to the rest of AWS.
Amazon has a page on Troubleshooting AWS sign-in or account issues, but it doesn't say anything about the issue described here.
So I'm stuck. How do I log in as this IAM user to create an environment in Cloud9?
===================================
EDIT Issue 1
While I waited for an answer here, I went ahead and signed back in as root user and started using Cloud9 to get familiar with it. When the Cloud9 Python tutorial told me to install the Python SDK:
sudo python3.7 -m pip install boto3(Typo of "python36" corrected.)
I got the warning:
WARNING: Running pip install with root privileges is generally not a good idea. Try
python3.7 -m pip install --userinstead.
This suggested alternative command makes no sense because it doesn't include specifying the module to be installed. But worse than that, after issuing the warning, it did not allow me to abort the command, but went ahead and did the installation. So I wonder if I've caused any security problem in my AWS account by doing that.
EDIT Issue 2
After not getting an answer here, I thought that maybe what I'm supposed to do is give console access to the IAM user, which would generate a password for it. So I went and edited the user to do that. I then was able to sign in as that user. When I did that, I went to several services: IAM, SES, and even Support, and found that they were all disabled for lack of permissions. Then I went to Cloud9 and seemed to have full access there. So signed out, signed back in as root user, deleted the Cloud9 environment I'd created there, signed out, signed back in as the IAM user, and created a new environment there.
The reason I did not give this new user console access before is because I have two other IAM users from previous work in SES, and neither of them have console access. So I figured IAM users aren't supposed to have that. If Cloud9 is a special case in which an IAM user is supposed to have console access, whereas SES IAM users are not, then the Cloud9 User Guide should say so.
EDIT Summary
My original question of how to sign in without console access has now changed to two questions:
Have I done the right thing to solve the problem (not being able to sign in as the IAM user) by granting console access to the IAM user?
Regarding any security problem caused by the root user creating and using a Cloud9 environment, have I healed any such problem by deleting that environment, or could there be any lingering effect of that problem that deserves further attention?


