#7665 Permission to CreateTags in the fedimg production keys
Closed: Fixed 5 years ago by sayanchowdhury. Opened 5 years ago by sayanchowdhury.

  • Describe what you need us to do:

I am using clean-amis.py to clean the older AMIs, which also adds some tags to add the information regarding the operation and a timestamp.

So please give CreateTags permission to the keys that fedimg production uses to upload the images.

  • When do you need this? (YYYY/MM/DD)
    ASAP

  • When is this no longer needed or useful? (YYYY/MM/DD)
    No expiry

  • If we cannot complete your request, what is the impact?
    AMIs will keep on accumulating


the image-upload user already seems to have this permission. Let me know if it's another user or another permission.

So, one thing I see is that the CreateTags permission is specific to type = snapshot

Could that be the issue? what are you trying to tag?

So, lets do this:

  • I am going to open permissions to let image-upload tag any image.
  • You run the script and confirm that it is working
  • I'll then setup autotagging, so we tag any image image-upload uploads as being from it.
  • After a while we set the policy to only allow it to tag images that it uploaded.

Sound acceptable?

Sounds good to me. Let us collaborate on this tomorrow. I don't need to run the script, i can just run a aws create tags command to check if it's working or not

ok, I already made the change to allow image tagging. So, run at your leasure...

I tried using the euca-create-tags command and I'm able to create the tags now. I will run the script.

Metadata Update from @sayanchowdhury:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

5 years ago

Login to comment on this ticket.

Metadata