Saturday, 1 July 2017

Access Denied - Route53 - AWS - Create IAM policy

Error: User: arn:aws:iam::502616337927:user/example is not authorized to perform: route53:ChangeResourceRecordSets on resource: arn:aws:route53:::hostedzone/W3MS19SVPW6HSSFGDHFGSHDF at Request.ext

To create a dns record, you need an IAM policy attached to the IAM user.

Create  IAM Policy

   "Version": "2012-10-17",
   "Statement": [
         "Sid" : "AllowPublicHostedZonePermissions",
         "Effect": "Allow",
         "Action": [
         "Resource": "*"
       "Sid" : "AllowHealthCheckPermissions",
         "Effect": "Allow",
         "Action": [
         "Resource": "*"

