Error: Couldn't find specified instance profile (Packer iam_instance_profile)
Fixes Packer rejecting an IAM instance profile whose name contains a path. For engineers passing a profile ARN path as iam_instance_profile, the fix is using the bare profile name.
Error: Couldn't find specified instance profile: ... failed to satisfy constraint (Packer)
TL;DR
iam_instance_profile must be the bare profile name, not a path or ARN. Use test-profile, not /foo/bar/test-profile or the full ARN.
The error
Build 'amazon-ebs' errored after 20 seconds 62 milliseconds: Couldn't find specified instance profile: ValidationError: 1 validation error detected: Value '/foo/bar/test-profile' at 'instanceProfileName' failed to satisfy constraint: Member must satisfy regular expression pattern: [\w+=,.@-]+
status code: 400Fix it
- Take your instance profile ARN and keep only the last segment:
arn:aws:iam::[account]:instance-profile/foo/bar/test-profilebecomestest-profile.
- Success check: the value contains no
/.
- Set
"iam_instance_profile": "test-profile"in the builder.
- Success check: the value matches
[\w+=,.@-]+.
- If your profile genuinely has a path and Packer will not accept it, duplicate the profile without a path as a workaround.
- Success check: the build finds the profile.
- Re-run
packer build.
- Success check: the instance launches with the profile attached.
When to use this
You hit this when the build fails looking up the instance profile, and your value contains /.
When NOT to use this
Do not use this for UnauthorizedOperation on iam:PassRole (that is a permissions gap on your build identity, not the name format).
Compatibility
Packer 1.x, amazon-ebs. The constraint comes from the EC2 API.
Variants
- The same
ValidationErrorwhen passing a full ARN instead of the name Couldn't find specified instance profilewhen the profile genuinely does not exist (check the name)
Root cause
EC2's instanceProfileName parameter accepts only the name pattern [\w+=,.@-]+, which excludes /. Packer passes the value straight through, so paths fail at the AWS API.
Edge cases
- Profiles with paths in their names are valid in IAM but unusable here. The duplicate-without-path workaround is the escape hatch.
- The error surfaces ~20s in, at instance launch, not at validate time.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.