When i am trying to create eks using cli its showing:
2025-11-06 11:11:38 [
] AWS::EC2::NatGateway/NATGateway: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EC2::SubnetRouteTableAssociation/RouteTableAssociationPublicUSEAST1A: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EC2::SubnetRouteTableAssociation/RouteTableAssociationPrivateUSEAST1D: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EC2::SubnetRouteTableAssociation/RouteTableAssociationPublicUSEAST1D: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EC2::SecurityGroup/ClusterSharedNodeSecurityGroup: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EC2::RouteTable/PrivateRouteTableUSEAST1A: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EC2::RouteTable/PublicRouteTable: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EC2::VPCGatewayAttachment/VPCGatewayAttachment: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EC2::SecurityGroup/ControlPlaneSecurityGroup: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EC2::RouteTable/PrivateRouteTableUSEAST1D: CREATE_FAILED – “Resource creation cancelled”
2025-11-06 11:11:38 [
] AWS::EKS::Cluster/ControlPlane: CREATE_FAILED – “Resource handler returned message: “User: arn:aws:iam::295533237186:user/kk_labs_user_593392 is not authorized to perform: iam:PassRole on resource: arn:aws:iam::295533237186:role/eksctl-demo-cluster3-cluster-ServiceRole-Tucb9kK58rll because no identity-based policy allows the iam:PassRole action (Service: Eks, Status Code: 403, Request ID: cb4445b6-a2cd-46c5-ae77-b76699c1b15a) (SDK Attempt Count: 1)” (RequestToken: 2728ed50-6ce8-48a0-d02e-ee73733165cb, HandlerErrorCode: AccessDenied)”
When i try to give access it’s showes:
Access denied to iam:ListAttachedUserPolicies
You don’t have permission to iam:ListAttachedUserPolicies. To request access, copy the following text and send it to your AWS administrator. Learn more about troubleshooting access denied errors.
User: arn:aws:iam::295533237186:user/kk_labs_user_593392Action: iam:ListAttachedUserPoliciesContext: an identity-based policy explicitly denies the action