Create an EBS CSI driver IAM role with the required permissions and attach it to the CSI driver add-on

Answer Correct answer: B — create an EBS CSI driver IAM role with the required permissions and attach it to the CSI driver add-on.

A DevOps engineer provisioned an Amazon Elastic Kubernetes Service (Amazon EKS) cluster with managed node groups. The DevOps engineer associated an OpenID Connect (OIDC) issuer with the cluster. The DevOps engineer is configuring Amazon Elastic Block Store (Amazon EBS) General Purpose SSD (gp3) volumes for the cluster. The DevOps engineer attempts to initiate a PersistentVolumeClaim (PVC) request but is unable to provision a volume. To troubleshoot the issue, the DevOps engineer runs the kubectl describe pyc command. The DevOps engineer receives a failed to provision volume with StorageClass error and a could not create volume in EC2:UnauthorizedOperation error. Which solution will resolve these errors?

  1. Create a Kubernetes cluster role that allows the persistent volumes to perform get, list, watch, create, and delete operations. Configure the cluster role to allow get, list, and watch operations for storage in the cluster.
  2. Create an Amazon EBS Container Storage Interface (CSI) driver IAM role that has the required permissions and trust relationships. Attach the IAM role to the Amazon EBS CSI driver add-on in the cluster. Correct Answer
  3. Add the ebs.csi.aws.com/volumeType:gp3 annotation to the PersistentVolumeClaim object in the cluster.
  4. Create a Kubernetes storage class object. Set the provisioner value to ebs.csi.aws.com. Set the volumeBindingMode value to WaitForFirstConsumer in the luster.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The error string identifies the root cause directly: UnauthorizedOperation on volume creation means the CSI driver's own IAM identity lacks permission, not that the PVC, storage class, or volume type is misconfigured (B). The remedy is therefore to create the EBS CSI driver IAM role with the required permissions and trust relationship and attach it to the add-on, which is the documented prerequisite for the driver to provision volumes (B). Options A, C, and D do not grant any permission to the driver, so none of them can resolve an authorization failure.

The PVC fails with could not create volume in EC2: UnauthorizedOperation, which is an authorization failure raised when the EBS CSI driver calls the EC2 API to create the volume because the driver has no IAM role permitting it. The cluster already has an OIDC issuer associated, so the fix is to create an EBS CSI driver IAM role holding the required permissions and trust relationships and attach that role to the Amazon EBS CSI driver add-on, giving the driver the authorization it needs to provision gp3 volumes.

Creating a Kubernetes cluster role allowing persistent volumes to perform get, list, watch, create, and delete operations (A) — a Kubernetes RBAC cluster role grants permissions within the Kubernetes API and cannot authorize the driver's EC2 CreateVolume call, so the UnauthorizedOperation error would persist. Adding the ebs.csi.aws.com/volumeType:gp3 annotation to the PVC (C) — an annotation affects how the volume is provisioned, not who is authorized to provision it, so it does not address an authorization failure. Creating a storage class with the ebs.csi.com provisioner and WaitForFirstConsumer binding mode (D) — this controls volume binding timing and which provisioner is used, but supplies no IAM authorization to the driver, so it likewise cannot resolve the error.

Community Discussion (4 comments)

Srikantha 👍 1 Selected: B
The key error is: "could not create volume in EC2: UnauthorizedOperation" This indicates that the EBS CSI driver does not have the required IAM permissions to provision EBS volumes via the EC2 API. Since the cluster is using IAM roles for service accounts (IRSA) with OIDC, the EBS CSI driver must assume an IAM role with the right permissions. Here's what's likely missing: The IAM role for the EBS CSI driver. Proper trust relationship with the OIDC provider. Necessary permissions like ec2:CreateVolume, ec2:AttachVolume, etc. 🛠 What to do: Create an IAM policy with the required permissions. Create an IAM role for the EBS CSI driver. Update the trust relationship to allow assumption via the cluster’s OIDC provider. Patch the EBS CSI driver deployment to use this IAM role (via Kubernetes service account).
jojewi8143 👍 1 Selected: B
B seems correct.
teo2157 👍 2 Selected: B
It's B based on this: https://docs.aws.amazon.com/eks/latest/userguide/ebs-csi.html
uncledana 👍 2
The root cause of the error is that the EBS CSI driver does not have the necessary IAM permissions to create EBS volumes in EC2. Solution B resolves the issue by creating an appropriate IAM role and attaching it to the EBS CSI driver, giving it the required permissions.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The reported error, could not create volume in EC2: UnauthorizedOperation, is returned by the EC2 API when the caller is not authorized to create the volume, and the caller in this case is the Amazon EBS CSI driver running in the cluster. Because the cluster already has an OpenID Connect issuer associated, the driver has an identity with which an IAM role can be associated, so the correct fix is to create an EBS CSI driver IAM role that contains the required permissions for provisioning and deleting volumes along with the appropriate trust relationships, and then attach that role to the Amazon EBS CSI driver add-on in the cluster (B). Srikantha identified exactly this reading of the error, that the EBS CSI driver lacks the IAM permissions to provision EBS volumes through the EC2 API, and teo2157 and uncledana both cited the AWS EBS CSI documentation as the basis. Once the role is attached, the driver is authorized and the PVC provisions normally. B is the correct answer.

Why the Other Options Are Wrong

A creates a Kubernetes cluster role allowing persistent volumes to perform get, list, watch, create, and delete operations and allows get, list, and watch for storage in the cluster. A Kubernetes RBAC cluster role grants permissions on Kubernetes API objects to Kubernetes identities; it cannot authorize the CSI driver's call to the EC2 CreateVolume API, which is an AWS API call made using an IAM role. The UnauthorizedOperation error would therefore persist unchanged. C adds the ebs.csi.aws.com/volumeType:gp3 annotation to the PersistentVolumeClaim object. This annotation only influences how the volume is provisioned, for example which volume type is requested; it grants no IAM permissions to the driver and so cannot resolve an authorization failure. D creates a Kubernetes storage class object with the provisioner set to ebs.csi.com and volumeBindingMode set to WaitForFirstConsumer. This controls which provisioner handles the volume and when binding occurs, but it supplies no IAM authorization to the driver, so it too leaves the UnauthorizedOperation error in place. B is correct.

Community Comment Notes

Community voted B unanimously. Srikantha gave the decisive diagnosis, that the key error is could not create volume in EC2: UnauthorizedOperation, indicating the EBS CSI driver does not have the required IAM permissions to provision EBS volumes via the EC2 API. teo2157 cited the AWS EKS documentation page on the EBS CSI driver as confirmation. uncledana agreed that the root cause is the missing IAM permissions and that creating the appropriate role with the correct trust relationship resolves it. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide