Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

What's New @ Cloudera

Find the latest Cloudera product news
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!

Addition of new features will require an update to any custom AWS policies for cross account roles

avatar
Contributor

A number of new features (Endpoint Access Gateway, Medium Duty SDX) have resulted in CDP exercising a set of AWS APIs that were not used earlier. The default cross account role (available via the CDP Documentation) already includes these APIs and no action is required.  However, customers who are running a custom cross account role policy may need to update their policy to ensure they have added the following actions.  Failure to do so will result in environment creation operations failing.

 

cloudformation:UpdateStack
cloudformation:ListStackResources
elasticloadbalancing:DescribeLoadBalancers
elasticloadbalancing:DescribeTargetHealth
elasticloadbalancing:RegisterTargets
elasticloadbalancing:DeregisterTargets

 

For details on how to find the AWS Cross Account role for your environment, please see the documentation on how to change an environment's credential.  For details on finding the Amazon Resource Name of the AWS IAM Role, please see the documentation on modifying a provisioning credential.