# Aws node template IAM profile

**URL:** <https://forums.suse.com/t/aws-node-template-iam-profile/10397>\
**Category:** SUSE Rancher Prime\
**Created:** [May 13, 2018, 4:40pm UTC](https://forums.suse.com/t/aws-node-template-iam-profile/10397 "2018-05-13T16:40:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nbannister](https://avatars.discourse-cdn.com/v4/letter/n/9fc348/32.png) [@nbannister](https://forums.suse.com/u/nbannister)\
**Post date:** [May 13, 2018, 4:40pm UTC](https://forums.suse.com/t/aws-node-template-iam-profile/10397/1 "2018-05-13T16:40:35Z")

</div>

When specifying the IAM profile for node template do you specify the full ARN or just the template name?

---

<div class="post-metadata">

**Author:** ![nidheeshdas](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/nidheeshdas/32/4071_2.png) [@nidheeshdas](https://forums.suse.com/u/nidheeshdas)\
**Post date:** [May 17, 2018, 5:34am UTC](https://forums.suse.com/t/aws-node-template-iam-profile/10397/2 "2018-05-17T05:34:16Z")

</div>

Do you have a IAM profile? Can you share the policy JSON?

---

<div class="post-metadata">

**Author:** ![pjpritch](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/pjpritch/32/4060_2.png) [@pjpritch](https://forums.suse.com/u/pjpritch)\
**Post date:** [May 17, 2018, 6:52am UTC](https://forums.suse.com/t/aws-node-template-iam-profile/10397/3 "2018-05-17T06:52:09Z")

</div>

you need to use the name of the IAM role, not the arn. it should have this policy:  
{  
“Version”: “2012-10-17”,  
“Statement”: [  
{  
“Effect”: “Allow”,  
“Action”: “ec2:Describe\*”,  
“Resource”: “_"  
},  
{  
“Effect”: “Allow”,  
“Action”: “ec2:AttachVolume”,  
“Resource”: "_”  
},  
{  
“Effect”: “Allow”,  
“Action”: “ec2:DetachVolume”,  
“Resource”: “_"  
},  
{  
“Effect”: “Allow”,  
“Action”: [  
"ec2:_”  
],  
“Resource”: [  
“_"  
]  
},  
{  
“Effect”: “Allow”,  
“Action”: [  
"elasticloadbalancing:_”  
],  
“Resource”: [  
“\*”  
]  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![superseb](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/superseb/32/2424_2.png) [@superseb](https://forums.suse.com/u/superseb)\
**Post date:** [May 17, 2018, 10:30am UTC](https://forums.suse.com/t/aws-node-template-iam-profile/10397/4 "2018-05-17T10:30:43Z")

</div>

[https://rancher.com/docs/rancher/v2.x/en/concepts/clusters/cloud-providers/#aws](https://rancher.com/docs/rancher/v2.x/en/concepts/clusters/cloud-providers/#aws)

> <https://github.com/rancher/rancher/issues/13553>
>
> Users get confused what to put in \`IAM Profile\` when creating EC2 node. (name vs… ARN)
> 
> This can be made more clear by changing it to \`IAM Instance Profile Name\` and a placeholder.

---

<div class="post-metadata">

**Author:** ![Julien\_Dubois](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@Julien\_Dubois](https://forums.suse.com/u/Julien_Dubois)\
**Post date:** [May 26, 2018, 7:10am UTC](https://forums.suse.com/t/aws-node-template-iam-profile/10397/5 "2018-05-26T07:10:51Z")

</div>

I created a role and specified this one in the node template but I’ve got an error like I wrote un this topic below. Do you have an Idea?

> [@Unable to create instances with IAM role specified](http://forums.suse.com/t/unable-to-create-instances-with-iam-role-specified/10573):
>
> I’m unable to create instances with IAM role specified, I created a role, associated with the strategy below: { “Version”: “2012-10-17”, “Statement”: [{ “Effect”: “Allow”, “Action”: “ec2:Describe\*”, “Resource”: “" }, { “Effect”: “Allow”, “Action”: “ec2:AttachVolume”, “Resource”: "” }, { “Effect”: “Allow”, “Action”: “ec2:DetachVolume”, “Resource”: “" }, { “Effect”: “Allow”, “Action”: ["ec2:”], “Resource”: [“"] }, { “Effect”: “Allow”, “Action”: [ "elasticloadbal…
