ancient-wolf-19325
09/09/2024, 12:42 PMdetails = "failed to create a signed url. Error: WebIdentityErr: failed to retrieve credentials
caused by: AccessDenied: Not authorized to perform sts:AssumeRoleWithWebIdentity
# Answer
The error you're encountering, AccessDenied: Not authorized to perform sts:AssumeRoleWithWebIdentity, indicates an issue with the IAM Role for Service Account (IRSA) setup. This typically happens when the trust relationship or permissions for the IAM role associated with your Flyte service account are not correctly configured.
1. Check Trust Relationship: Ensure that the trust relationship for the IAM role allows the EKS service to assume the role. The trust policy should look something like this:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Federated": "arn:aws:iam::<account-id>:oidc-provider/<oidc-provider>"
},
"Action": "sts:AssumeRoleWithWebIdentity",
"Condition": {
"StringEquals": {
"<oidc-provider>:sub": "system:serviceaccount:<namespace>:<service-account>"
}
}
}
]
}
2. Verify Role Annotations: Ensure that the Kubernetes service account used by Flyte has the correct IAM role annotation. You can check this using:
kubectl describe sa <service-account> -n <namespace>
3. IAM Policy: Ensure that the IAM role has the necessary permissions to access the required AWS resources, such as S3.
For more details, you can refer to the discussions on similar issues here and here.
Would you like more detailed steps or a specific example?
Sources:
- Flyte Community Discussion 1
- Flyte Community Discussion 2
Slack Link
https://flyte-org.slack.com/archives/CP2HDHKE1/p1725885745.954279 👍 0 button 👎 0 button 💡 Hint: Mention @runllm in the thread for followups.