fix: create assume role policy inline#439
Conversation
comcalvi
left a comment
There was a problem hiding this comment.
Looks good, just please add or modify an integ test for this one.
I think the existing integration tests are sufficient but the snapshot needs to be updated because this PR removes the duplicate policy that gets added to the admin role. Unfortunately I'm a bit stumped on how to make this change on my end. I tried to run For context, this is the snapshot change that's causing the integration test to fail: Please advise, thanks! |
|
I'm running into this issue as well. I want to have a pre-provisioned Admin role (due to the race condition) for the StackSet, but it tries to attach a duplicate inline permission to the pre-provisioned Admin role. This occurs when deploying multiple self managed stacksets with this same Admin role. Please fix the issue. |
|
+1 I too hope this issue is resolved. |
|
#678 is the right thing to do here so im going to close this in favor of that. |
Fixes #438
This PR moves the assume role policy inline to avoid a race condition of the stack set resource deployment before the policy is attached. As a consequence, an existing admin role won't be modified with a potentially duplicate policy.