Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Does this CFT template works for AWS China #18

Open
skaas-cloudsec opened this issue Jun 30, 2022 · 4 comments
Open

Does this CFT template works for AWS China #18

skaas-cloudsec opened this issue Jun 30, 2022 · 4 comments
Assignees
Labels
question Further information is requested

Comments

@skaas-cloudsec
Copy link

Hi All,

We are facing issues while deploying this CFT template in AWS China region. Please suggest

2 Errors:

[ERROR] 2022-06-28T12:32:26.256Z 74510861-6c86-41a1-8a82-cc4b037ce51b <--!! Exception: An error occurred (AccessDenied) when calling the PutObject operation: User: arn:aws-cn:sts::xxxxxxxxx:assumed-role/ec2cnbfortigate-LambdaRole-SU3TB0KACIDM/ec2cnbfortigate-InitFunction-k0ups0YllBeU is not authorized to perform: kms:GenerateDataKey on resource: arn:aws-cn:kms:cn-north-1:xxxxxxxx:key/acbcd-c6cb-4a90-8798-asdasdasf123 because no identity-based policy allows the kms:GenerateDataKey action

[ERROR] 2022-06-28T12:32:01.679Z c2a620ae-d73f-45bf-ba08-06e8ef98b6ec !!--> Unable to find AMI in response! {'Images': [], 'ResponseMetadata': {'RequestId': 'ab5f7568-dd5d-460e-98a5-9d643d3c46a8', 'HTTPStatusCode': 200, 'HTTPHeaders': {'x-amzn-requestid': 'ab5f7568-dd5d-460e-98a5-9d643d3c46a8', 'cache-control': 'no-cache, no-store', 'strict-transport-security': 'max-age=31536000; includeSubDomains', 'content-type': 'text/xml;charset=UTF-8', 'content-length': '219', 'date': 'Tue, 28 Jun 2022 12:32:01 GMT', 'server': 'AmazonEC2'}, 'RetryAttempts': 0}}

@skaas-cloudsec
Copy link
Author

Please help with a response

@Joel-Cripps Joel-Cripps added the question Further information is requested label Jul 13, 2022
@Joel-Cripps
Copy link
Member

It doesn't sound like it will. The Chinese regions don't have the same AMI format, so the functions to grab those would have to change.

@Joel-Cripps Joel-Cripps self-assigned this Jul 14, 2022
@aaa815
Copy link

aaa815 commented Oct 5, 2022

I have same issue.. any solution seen in coming days?

@aaa815
Copy link

aaa815 commented Jul 3, 2023

It works as i have deployed the same in AWS China

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

3 participants