Skip to content

v0.19.2

Latest

Choose a tag to compare

@btassone btassone released this 04 Sep 22:40
9faf65e

Bug Fixes

Fixed Database Deletion with Snapshots

Issue: Database deletion operations with snapshot=true were failing with 403 AccessDenied errors when AWS RDS attempted to copy tags to final snapshots.

Root Cause: AWS RDS automatically copies tags from the source database/cluster to final snapshots during deletion, which requires the rds:AddTagsToResource permission that was missing from the IAM policy.

Error Fixed:

User: arn:aws:sts::846761448161:assumed-role/SpinupXAManagementRoleTst/... is not authorized to perform: rds:AddTagsToResource on resource: arn:aws:rds:us-east-1:846761448161:cluster-snapshot:final-spinbt2l-db00000a

Changes:

  • Enhanced database deletion permission logic to conditionally include snapshot creation permissions (rds:CreateDBClusterSnapshot, rds:CreateDBSnapshot) when snapshot=true
  • Added rds:AddTagsToResource permission for tag copying during final snapshot creation
  • Maintains security by only granting additional permissions when snapshots are actually being created

Impact:

  • ✅ Database deletion with final snapshots now works without permission errors
  • ✅ No breaking changes to existing API functionality
  • ✅ Maintains principle of least privilege - permissions only granted when needed

Commits

  • 4e20884 Add required cluster snapshot permissions
  • 5b9f449 Fix AddTagsToResource error