Clearer errors when Bref Cloud cannot access the AWS account - #55
Merged
Merged
Conversation
Every 403 was replaced with "Do you need to login to a different team?", including those that explain their cause. For example when Bref Cloud cannot access the AWS account, `bref deploy` hid the message saying so. The generic message is kept for failed authorizations, whose message says nothing about the cause.
- When AWS denies the deployment of the connection stack with a service control policy, explain that AWS accounts created with "Sign up for AWS (new)" (AWS projects) cannot be connected to Bref Cloud. - When no AWS credentials are found, say so instead of reporting the error of the EC2 instance metadata service, and mention that `aws login` sessions expire after 12 hours. - Use the AWS_PROFILE environment variable when `--profile` is not set, instead of always using the "default" profile.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found while connecting an AWS account created with the new AWS sign-up ("Sign up for AWS (new)"). These accounts are "AWS projects" with AWS-managed policies: they deny CloudFormation outside of the project's region, and deny Bref Cloud's access altogether (see brefphp/bref#2187). The CLI made both hard to understand.
bref deploy: when Bref Cloud cannot assume its role in the AWS account, the API answers 403 with the reason:The CLI replaced every 403 with "Forbidden. You do not have the required permissions. Do you need to login to a different team?". It now shows the API message, and keeps the generic one for failed authorizations (Laravel's "This action is unauthorized." or an empty message), which say nothing about the cause. Other 403 messages that were hidden: "Your current plan does not allow creating more AWS accounts.", "A valid plan is required to create secrets".
bref connect:The connection stack is deployed in
us-east-1, which AWS projects deny. The user got the raw AWS error (... with an explicit deny in a service control policy: ...). On such a denial, the error now says that AWS accounts created with "Sign up for AWS (new)" cannot be connected, and links to the docs.AWS projects give credentials with
aws login, whose sessions expire after 12 hours. With an expired session (or no credentials at all), the AWS SDK only reports the error of its last credential provider:Error retrieving credentials from the instance profile metadata service. (cURL error 7: Failed to connect to 169.254.169.254 ...). It now reads:Without
--profile, the command always used thedefaultprofile and ignoredAWS_PROFILE. It now usesAWS_PROFILEwhen it is set, like the AWS CLI (the docs tellaws loginusers toexport AWS_PROFILE=...).Tested with the new AWS account: the credentials message and
AWS_PROFILEhandling with a real expiredaws loginsession. The two other messages are covered by tests built from the real AWS and API errors.