Create an EBS CSI driver IAM role with the required permissions and attach it to the CSI driver add-on
A DevOps engineer provisioned an Amazon Elastic Kubernetes Service (Amazon EKS) cluster with managed node groups. The DevOps engineer associated an OpenID Connect (OIDC) issuer with the cluster. The DevOps engineer is configuring Amazon Elastic Block Store (Amazon EBS) General Purpose SSD (gp3) volumes for the cluster. The DevOps engineer attempts to initiate a PersistentVolumeClaim (PVC) request but is unable to provision a volume. To troubleshoot the issue, the DevOps engineer runs the kubectl describe pyc command. The DevOps engineer receives a failed to provision volume with StorageClass error and a could not create volume in EC2:UnauthorizedOperation error. Which solution will resolve these errors?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The error string identifies the root cause directly: UnauthorizedOperation on volume creation means the CSI driver's own IAM identity lacks permission, not that the PVC, storage class, or volume type is misconfigured (B). The remedy is therefore to create the EBS CSI driver IAM role with the required permissions and trust relationship and attach it to the add-on, which is the documented prerequisite for the driver to provision volumes (B). Options A, C, and D do not grant any permission to the driver, so none of them can resolve an authorization failure.
The PVC fails with could not create volume in EC2: UnauthorizedOperation, which is an authorization failure raised when the EBS CSI driver calls the EC2 API to create the volume because the driver has no IAM role permitting it. The cluster already has an OIDC issuer associated, so the fix is to create an EBS CSI driver IAM role holding the required permissions and trust relationships and attach that role to the Amazon EBS CSI driver add-on, giving the driver the authorization it needs to provision gp3 volumes.
Creating a Kubernetes cluster role allowing persistent volumes to perform get, list, watch, create, and delete operations (A) — a Kubernetes RBAC cluster role grants permissions within the Kubernetes API and cannot authorize the driver's EC2 CreateVolume call, so the UnauthorizedOperation error would persist. Adding the ebs.csi.aws.com/volumeType:gp3 annotation to the PVC (C) — an annotation affects how the volume is provisioned, not who is authorized to provision it, so it does not address an authorization failure. Creating a storage class with the ebs.csi.com provisioner and WaitForFirstConsumer binding mode (D) — this controls volume binding timing and which provisioner is used, but supplies no IAM authorization to the driver, so it likewise cannot resolve the error.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The reported error, could not create volume in EC2: UnauthorizedOperation, is returned by the EC2 API when the caller is not authorized to create the volume, and the caller in this case is the Amazon EBS CSI driver running in the cluster. Because the cluster already has an OpenID Connect issuer associated, the driver has an identity with which an IAM role can be associated, so the correct fix is to create an EBS CSI driver IAM role that contains the required permissions for provisioning and deleting volumes along with the appropriate trust relationships, and then attach that role to the Amazon EBS CSI driver add-on in the cluster (B). Srikantha identified exactly this reading of the error, that the EBS CSI driver lacks the IAM permissions to provision EBS volumes through the EC2 API, and teo2157 and uncledana both cited the AWS EBS CSI documentation as the basis. Once the role is attached, the driver is authorized and the PVC provisions normally. B is the correct answer.Why the Other Options Are Wrong
A creates a Kubernetes cluster role allowing persistent volumes to perform get, list, watch, create, and delete operations and allows get, list, and watch for storage in the cluster. A Kubernetes RBAC cluster role grants permissions on Kubernetes API objects to Kubernetes identities; it cannot authorize the CSI driver's call to the EC2 CreateVolume API, which is an AWS API call made using an IAM role. The UnauthorizedOperation error would therefore persist unchanged. C adds the ebs.csi.aws.com/volumeType:gp3 annotation to the PersistentVolumeClaim object. This annotation only influences how the volume is provisioned, for example which volume type is requested; it grants no IAM permissions to the driver and so cannot resolve an authorization failure. D creates a Kubernetes storage class object with the provisioner set to ebs.csi.com and volumeBindingMode set to WaitForFirstConsumer. This controls which provisioner handles the volume and when binding occurs, but it supplies no IAM authorization to the driver, so it too leaves the UnauthorizedOperation error in place. B is correct.Community Comment Notes
Community voted B unanimously. Srikantha gave the decisive diagnosis, that the key error is could not create volume in EC2: UnauthorizedOperation, indicating the EBS CSI driver does not have the required IAM permissions to provision EBS volumes via the EC2 API. teo2157 cited the AWS EKS documentation page on the EBS CSI driver as confirmation. uncledana agreed that the root cause is the missing IAM permissions and that creating the appropriate role with the correct trust relationship resolves it. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →