cyberark / pas-on-cloud

CyberArk Privileged Access Security on Cloud

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

stack deploy failed at CopyRecupToBucket

YouareGitHub opened this issue · comments

Hi Please can you assist.

I have tried to deploy the stack for both PAS-AIO-Deployment.json and PAS-AIO-dr-Deployment.json
The Role I am using to deploy the stack has Admin privileges
The licence and recpub files use the default name in the root of the new bucket (Vault Files Bucket)
I set the bucket to full global access to check there was no privilege issue with access to the bucket.
During the stack setup I have tried using the bucket ARN, NAme, URL.

any advise greatly appreciated

first error in the deployment

08 May 2019 22:48:40 CopyRecpubToBucket CREATE_FAILED Failed to create resource. See the details in CloudWatch Log Stream: 2019/05/08/[$LATEST]fbddd337df934230a6d20c665750bd3a

### Full text from the log CloudWatchLog Groups/aws/lambda/CyberArkDR-CopyfileFromBucketLambda-1AMK26XVRUOZK2019/05/08/[$LATEST]0934d9a49d40435193668f7b6b23739a

2019-05-08 16:54:59
No older events found at the moment. Retry.
START RequestId: a7d659df-8a2f-43c3-b1c5-290441762995 Version: $LATEST
An error occurred (InvalidArgument) when calling the CopyObject operation: Invalid copy source URI.
https://cloudformation-custom-resource-response-useast1.s3.amazonaws.com/arn%3Aaws%3Acloudformation%3Aus-east-1%3A737331083610%3Astack/CyberArkDR/e276b010-71b1-11e9-a36b-0e194fb09f5c%7CCopyRecpubToBucket%7C451ed0a5-4fee-47df-9c04-81e5935031fe?AWSAccessKeyId=AKIA6L7Q4OWT7XTLUBXY&Expires=1557341699&Signature=G8m1CANTMSDlYzlvgJwR9Wlvcck%3D
Response body:
{
"Status": "FAILED",
"StackId": "arn:aws:cloudformation:us-east-1:737331083610:stack/CyberArkDR/e276b010-71b1-11e9-a36b-0e194fb09f5c",
"PhysicalResourceId": "50696e01-3ea0-4941-9e96-4f57248f2ba5",
"Reason": "See the details in CloudWatch Log Stream: 2019/05/08/[$LATEST]0934d9a49d40435193668f7b6b23739a",
"NoEcho": false,
"RequestId": "451ed0a5-4fee-47df-9c04-81e5935031fe",
"Data": {},
"LogicalResourceId": "CopyRecpubToBucket"
}
Status code: OK
END RequestId: a7d659df-8a2f-43c3-b1c5-290441762995
REPORT RequestId: a7d659df-8a2f-43c3-b1c5-290441762995 Duration: 2067.00 ms Billed Duration: 2100 ms Memory Size: 128 MB Max Memory Used: 67 MB
START RequestId: 5430ee1a-ace4-49d6-accf-863893bda097 Version: $LATEST
Object Deleted Successfully
https://cloudformation-custom-resource-response-useast1.s3.amazonaws.com/arn%3Aaws%3Acloudformation%3Aus-east-1%3A737331083610%3Astack/CyberArkDR/e276b010-71b1-11e9-a36b-0e194fb09f5c%7CCopyLicenseToBucket%7C3c11db60-86a6-43fc-a495-6867ea02a669?AWSAccessKeyId=AKIA6L7Q4OWT7XTLUBXY&Expires=1557341736&Signature=KokCS4QRqs722aWWknhvAbSaeWs%3D
Response body:
{
"Status": "SUCCESS",
"StackId": "arn:aws:cloudformation:us-east-1:737331083610:stack/CyberArkDR/e276b010-71b1-11e9-a36b-0e194fb09f5c",
"PhysicalResourceId": "CyberArkDR-CopyLicenseToBucket-DIT9C9H7RO3V",
"Reason": "See the details in CloudWatch Log Stream: 2019/05/08/[$LATEST]0934d9a49d40435193668f7b6b23739a",
"NoEcho": false,
"RequestId": "3c11db60-86a6-43fc-a495-6867ea02a669",
"Data": {},
"LogicalResourceId": "CopyLicenseToBucket"
}
Status code: OK
END RequestId: 5430ee1a-ace4-49d6-accf-863893bda097
REPORT RequestId: 5430ee1a-ace4-49d6-accf-863893bda097 Duration: 514.80 ms Billed Duration: 600 ms Memory Size: 128 MB Max Memory Used: 68 MB

! sorry user error
Fix was to use the Bucket name ONLY. not ARN or url