3 ms·
Policy simulator is indeed a great option except I didn't have access to it at the time because it was disabled via SCP :D Kidding around though I'll try that
by dopylitty 3y ago
Policy simulator is indeed a great option except I didn't have access to it at the time because it was disabled via SCP :D
Kidding around though I'll try that if I face a similar issue in the future. It has been improving quite a bit lately.
> Well EC2 would process these requests by first verifying subnet-related permissions before moving on to security group permissions. Variations in the error messages could reflect the point at which the request encounters a permission issue?
I would think the context would be deterministic in that case but I verified calling the API with the same parameters using the same role twice in a row ended up with different 'resource' values in the context. It was almost like under the hood boto3 or something else was changing the order of the parameters in the API call which was changing the way the context was created. I could've put in a support case but had bigger fish to fry.