![]() |
打盹的斑马 · JavaScript Date Formats· 1 月前 · |
![]() |
行走的键盘 · Delphi-使用TNetHTTPReque ...· 3 周前 · |
![]() |
深情的黄瓜 · So I m stuck on S3 ...· 1 周前 · |
![]() |
乐观的火锅 · VS 2012 TCP server ...· 1 周前 · |
![]() |
买醉的煎饼果子 · 木材科学与技术考研科目是什么-高顿教育· 7 月前 · |
![]() |
刚失恋的炒面 · 喂饭级人工智能版Photoshop(Beta ...· 7 月前 · |
![]() |
深情的韭菜 · 迪士尼收购福克斯了影响我看漫威吗?_Hulu· 9 月前 · |
![]() |
含蓄的红薯 · Pierre-Luc Arsenault ...· 9 月前 · |
![]() |
乐观的黄花菜 · 童书·专访|邓正祺:鳄鱼是我对群体生活不太行 ...· 1 年前 · |
pod try |
https://discuss.flyte.org/t/2586554/so-i-m-stuck-on-s3-access-i-created-a-service-account-called |
![]() |
深情的黄瓜
1 周前 |
sticky-angle-28419
09/16/2022, 5:33 PMflyte-executor
with the
flyte-user-role
(which has full s3 access) attached as an annotation and running Flyte executions with this service account, but it’s giving me PutObject access denied error. This service account is in the project+domain namespace. What am I doing wrong?
thankful-minister-83577
thankful-minister-83577
aws sts get-caller-identity
sticky-angle-28419
09/16/2022, 9:24 PMAmazonS3FullAccess
policy attached to it
sticky-angle-28419
09/16/2022, 9:24 PMsticky-angle-28419
09/16/2022, 9:34 PMsticky-angle-28419
09/16/2022, 9:48 PMfatal error: An error occurred (403) when calling the HeadObject operation: Forbidden
sticky-angle-28419
09/17/2022, 1:27 AMsleep infinity
to the args in the yaml and
exec
into it to run
aws sts get-caller-identity
? Let me know when you got a minute - thanks!
tall-lock-23197
thankful-minister-83577
sticky-angle-28419
09/20/2022, 7:54 PMsticky-angle-28419
09/20/2022, 7:54 PMthankful-minister-83577
thankful-minister-83577
thankful-minister-83577
sticky-angle-28419
09/20/2022, 8:03 PMsticky-angle-28419
09/20/2022, 8:03 PMthankful-minister-83577
thankful-minister-83577
thankful-minister-83577
thankful-minister-83577
sticky-angle-28419
09/20/2022, 8:05 PMsticky-angle-28419
09/20/2022, 8:06 PMapiVersion: v1
imagePullSecrets:
- name: gcr-json-key
kind: ServiceAccount
metadata:
annotations:
<http://eks.amazonaws.com/role-arn|eks.amazonaws.com/role-arn>: arn:aws:iam::xxx:role/flyte-user-role
labels:
<http://app.kubernetes.io/managed-by|app.kubernetes.io/managed-by>: pulumi
name: flyte-executor
namespace: shelly-robotics-bipedal-robot-development
resourceVersion: "57747250"
uid: 9db3e9da-cf32-4a78-8b06-81d83b66c611
secrets:
- name: flyte-executor-token-l6rkj
sticky-angle-28419
09/20/2022, 8:06 PMthankful-minister-83577
get pod <pod name> -o yaml
and grep for “iam”
thankful-minister-83577
thankful-minister-83577
sticky-angle-28419
09/20/2022, 8:35 PMget pod <pod name> -o yaml | grep 'iam'
returns this
sticky-angle-28419
09/20/2022, 8:35 PMvalue: arn:aws:iam::xxx:role/flyte-user-role
name: aws-iam-token
- name: aws-iam-token
sticky-angle-28419
09/20/2022, 8:35 PMthankful-minister-83577
thankful-minister-83577
sticky-angle-28419
09/20/2022, 8:38 PMaws sts assume-role …
locally, I get this error:
An error occurred (AccessDenied) when calling the AssumeRole operation
thankful-minister-83577
thankful-minister-83577
thankful-minister-83577
sticky-angle-28419
09/20/2022, 8:47 PMsticky-angle-28419
09/20/2022, 8:47 PM{
"Version": "2012-10-17",
"Statement": [
"Sid": "",
"Effect": "Allow",
"Principal": {
"Federated": "arn:aws:iam::xxx:oidc-provider/oidc.eks.us-west-1.amazonaws.com/id/2A6739B7813451087E3258C60BC37CF4"
"Action": "sts:AssumeRoleWithWebIdentity",
"Condition": {
"StringEquals": {
"<http://oidc.eks.us-west-1.amazonaws.com/id/2A6739B7813451087E3258C60BC37CF4:aud|oidc.eks.us-west-1.amazonaws.com/id/2A6739B7813451087E3258C60BC37CF4:aud>": "<http://sts.amazonaws.com|sts.amazonaws.com>"
"Sid": "",
"Effect": "Allow",
"Principal": {
"Service": "<http://ec2.amazonaws.com|ec2.amazonaws.com>"
"Action": "sts:AssumeRole"
}
sticky-angle-28419
09/20/2022, 8:47 PMthankful-minister-83577
sticky-angle-28419
09/20/2022, 8:51 PMsticky-angle-28419
09/20/2022, 8:52 PMthankful-minister-83577
thankful-minister-83577
sticky-angle-28419
09/20/2022, 8:54 PMsleep infinity
?
sticky-angle-28419
09/20/2022, 9:00 PMaws sts get-caller-identity
and here’s the response:
sticky-angle-28419
09/20/2022, 9:00 PM{
"UserId": "xxx:botocore-session-1663707573",
"Account": "xxx",
"Arn": "arn:aws:sts::xxx:assumed-role/flyte-user-role/botocore-session-1663707573"
}
thankful-minister-83577
sticky-angle-28419
09/20/2022, 9:01 PMsticky-angle-28419
09/20/2022, 9:01 PMthankful-minister-83577
thankful-minister-83577
thankful-minister-83577
cat > abc
hello
^C
thankful-minister-83577
sticky-angle-28419
09/20/2022, 9:02 PMsticky-angle-28419
09/20/2022, 9:04 PMsticky-angle-28419
09/20/2022, 9:04 PMaws s3 cp abc <s3://sidetrek-flyte-cluster-flyte-bucket/metadata/propeller/shelly-robotics-bipedal-robot-development-an6gvhl5dn8vr44nn9ds/n0/data/0/abc.txt>
thankful-minister-83577
sticky-angle-28419
09/20/2022, 9:05 PMsticky-angle-28419
09/20/2022, 9:05 PMsticky-angle-28419
09/20/2022, 9:05 PMsticky-angle-28419
09/20/2022, 9:06 PMSecurity Context
section - leaving IAM Role field empty
sticky-angle-28419
09/20/2022, 9:06 PMsticky-angle-28419
09/20/2022, 9:06 PMthankful-minister-83577
sticky-angle-28419
09/20/2022, 9:24 PMthankful-minister-83577
sticky-angle-28419
09/20/2022, 9:24 PMthankful-minister-83577
sticky-angle-28419
09/20/2022, 9:25 PMsticky-angle-28419
09/20/2022, 9:25 PM>>> import boto3
![]() |
打盹的斑马 · JavaScript Date Formats 1 月前 |
![]() |
乐观的火锅 · VS 2012 TCP server side diconnected by accident, how reconnect that after server run again?-VBForums 1 周前 |
![]() |
买醉的煎饼果子 · 木材科学与技术考研科目是什么-高顿教育 7 月前 |
![]() |
深情的韭菜 · 迪士尼收购福克斯了影响我看漫威吗?_Hulu 9 月前 |