Bug Fixes
Fixed Database Deletion with Snapshots
Issue: Database deletion operations with snapshot=true were failing with 403 AccessDenied errors when AWS RDS attempted to copy tags to final snapshots.
Root Cause: AWS RDS automatically copies tags from the source database/cluster to final snapshots during deletion, which requires the rds:AddTagsToResource permission that was missing from the IAM policy.
Error Fixed:
User: arn:aws:sts::846761448161:assumed-role/SpinupXAManagementRoleTst/... is not authorized to perform: rds:AddTagsToResource on resource: arn:aws:rds:us-east-1:846761448161:cluster-snapshot:final-spinbt2l-db00000a
Changes:
- Enhanced database deletion permission logic to conditionally include snapshot creation permissions (
rds:CreateDBClusterSnapshot,rds:CreateDBSnapshot) whensnapshot=true - Added
rds:AddTagsToResourcepermission for tag copying during final snapshot creation - Maintains security by only granting additional permissions when snapshots are actually being created
Impact:
- ✅ Database deletion with final snapshots now works without permission errors
- ✅ No breaking changes to existing API functionality
- ✅ Maintains principle of least privilege - permissions only granted when needed
Commits
4e20884Add required cluster snapshot permissions5b9f449Fix AddTagsToResource error