Skip to content

059-amazon-datazone-gs: requires Identity Center + DataZone integration #76

@mwunderl

Description

@mwunderl

Problem

CreateEnvironmentProfile requires the calling principal to be a DataZone project member via Identity Center. DataZone uses its own authorization model separate from IAM.

Current state

  • Script creates domain and projects successfully
  • Fails at CreateEnvironmentProfile with AccessDeniedException
  • --managed flag fix applied for blueprint listing

Steps to resolve

  1. Configure DataZone domain to use Identity Center for user management
  2. Map an IC user as a DataZone project owner
  3. Run the script as that IC user
  4. Test end-to-end
  5. Add back to the non-interactive PR

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions