Skip to content

Clearer errors when Bref Cloud cannot access the AWS account - #55

Merged
mnapoli merged 2 commits into
mainfrom
clearer-errors
Sep 26, 2026
Merged

mnapoli merged 2 commits into
mainfrom
clearer-errors

Conversation

@mnapoli

@mnapoli mnapoli commented Sep 26, 2026

Copy link
Copy Markdown
Member

Found while connecting an AWS account created with the new AWS sign-up ("Sign up for AWS (new)"). These accounts are "AWS projects" with AWS-managed policies: they deny CloudFormation outside of the project's region, and deny Bref Cloud's access altogether (see brefphp/bref#2187). The CLI made both hard to understand.

bref deploy: when Bref Cloud cannot assume its role in the AWS account, the API answers 403 with the reason:

Bref Cloud is not authorized to access the AWS account "production": it could not assume the role arn:aws:iam::123456789012:role/BrefCloudAccess. See https://bref.cloud/aws-accounts

The CLI replaced every 403 with "Forbidden. You do not have the required permissions. Do you need to login to a different team?". It now shows the API message, and keeps the generic one for failed authorizations (Laravel's "This action is unauthorized." or an empty message), which say nothing about the cause. Other 403 messages that were hidden: "Your current plan does not allow creating more AWS accounts.", "A valid plan is required to create secrets".

bref connect:

  • The connection stack is deployed in us-east-1, which AWS projects deny. The user got the raw AWS error (... with an explicit deny in a service control policy: ...). On such a denial, the error now says that AWS accounts created with "Sign up for AWS (new)" cannot be connected, and links to the docs.

  • AWS projects give credentials with aws login, whose sessions expire after 12 hours. With an expired session (or no credentials at all), the AWS SDK only reports the error of its last credential provider: Error retrieving credentials from the instance profile metadata service. (cURL error 7: Failed to connect to 169.254.169.254 ...). It now reads:

    No valid AWS credentials found for the AWS profile 'my-project'. If you log in with `aws login`, run `aws login --profile my-project` again: its sessions expire after 12 hours. Use the `--profile` option to select another AWS profile.
    
  • Without --profile, the command always used the default profile and ignored AWS_PROFILE. It now uses AWS_PROFILE when it is set, like the AWS CLI (the docs tell aws login users to export AWS_PROFILE=...).

Tested with the new AWS account: the credentials message and AWS_PROFILE handling with a real expired aws login session. The two other messages are covered by tests built from the real AWS and API errors.

Every 403 was replaced with "Do you need to login to a different team?", including those that explain their cause. For example when Bref Cloud cannot access the AWS account, `bref deploy` hid the message saying so.

The generic message is kept for failed authorizations, whose message says nothing about the cause.
- When AWS denies the deployment of the connection stack with a service control policy, explain that AWS accounts created with "Sign up for AWS (new)" (AWS projects) cannot be connected to Bref Cloud.
- When no AWS credentials are found, say so instead of reporting the error of the EC2 instance metadata service, and mention that `aws login` sessions expire after 12 hours.
- Use the AWS_PROFILE environment variable when `--profile` is not set, instead of always using the "default" profile.
@mnapoli
mnapoli merged commit 4d36ba1 into main Sep 26, 2026
4 checks passed
@mnapoli
mnapoli deleted the clearer-errors branch September 26, 2026 13:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant