# Error when trying exosol personal

**URL:** <https://community.exasol.com/t/error-when-trying-exosol-personal/268>\
**Category:** Help Needed\
**Tags:** exasol-personal\
**Created:** [January 17, 2026, 3:46pm UTC](https://community.exasol.com/t/error-when-trying-exosol-personal/268 "2026-01-17T15:46:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Will](https://avatars.discourse-cdn.com/v4/letter/w/90ced4/32.png) [@Will](https://community.exasol.com/u/Will)\
**Post date:** [January 17, 2026, 3:46pm UTC](https://community.exasol.com/t/error-when-trying-exosol-personal/268/1 "2026-01-17T15:46:49Z")

</div>

Hello to all!

I decided to give a try to Exasol and wanted to try with the Exasol Personal.

I have setup a user in my AWS with the permissions documented [here](https://docs.exasol.com/db/latest/get_started/exasol_personal_aws_setup.htm), but when I run `<path>\exasol.exe install` I get an error. It seems the client needs to execute the action ssm:PutParameter, but the policies of the public page aren’t enough for executing it.

What are the minimum policies required to install the Exasol personal?

> Jan 17 14:07:23.336 ERR random\_id.deployment\_id: Creating…  
> Jan 17 14:07:23.339 ERR tls\_private\_key.tls\_key: Creating…  
> Jan 17 14:07:23.339 ERR tls\_private\_key.tls\_ca\_key: Creating…  
> Jan 17 14:07:23.339 ERR tls\_private\_key.ssh\_key: Creating…  
> Jan 17 14:07:23.339 ERR time\_static.deployment\_created: Creating…  
> Jan 17 14:07:23.340 ERR random\_id.deployment\_id: Creation complete after 0s [id=YekZMw]  
> Jan 17 14:07:23.342 ERR tls\_private\_key.tls\_ca\_key: Creation complete after 0s [id=2786ef0defc9a18e03575669eed0a022ca3e3b68]  
> Jan 17 14:07:23.342 ERR tls\_private\_key.tls\_key: Creation complete after 0s [id=a86675bd94bbd8f2608e7209281128c75429af7e]  
> Jan 17 14:07:23.343 ERR time\_static.deployment\_created: Creation complete after 0s [id=2026-01-17T13:07:23Z]  
> Jan 17 14:07:23.345 ERR random\_password.adminui: Creating…  
> Jan 17 14:07:23.345 ERR random\_password.db: Creating…  
> Jan 17 14:07:23.354 ERR tls\_cert\_request.tls\_request: Creating…  
> Jan 17 14:07:23.357 ERR tls\_self\_signed\_cert.tls\_ca\_cert: Creating…  
> Jan 17 14:07:23.657 ERR tls\_cert\_request.tls\_request: Creation complete after 1s [id=f317cb898f31d758a692a0b58f8ca6d96604e433]  
> Jan 17 14:07:23.658 ERR tls\_self\_signed\_cert.tls\_ca\_cert: Creation complete after 1s [id=117707105886183849536923653068189178364]  
> Jan 17 14:07:23.666 ERR tls\_locally\_signed\_cert.tls\_cert: Creating…  
> Jan 17 14:07:23.674 ERR tls\_locally\_signed\_cert.tls\_cert: Creation complete after 0s [id=330169637866651708546962522069315544755]  
> Jan 17 14:07:23.724 ERR random\_password.db: Creation complete after 1s [id=none]  
> Jan 17 14:07:23.727 ERR random\_password.adminui: Creation complete after 1s [id=none]  
> Jan 17 14:07:23.735 ERR local\_file.deployment\_secrets: Creating…  
> Jan 17 14:07:23.740 ERR local\_file.deployment\_secrets: Creation complete after 0s [id=6dbb49ff54b9e9e23efedf6548a88deeb9f12b32]  
> Jan 17 14:07:23.957 ERR random\_shuffle.az\_selection: Creating…  
> Jan 17 14:07:23.960 ERR random\_shuffle.az\_selection: Creation complete after 0s [id=-]  
> Jan 17 14:07:23.973 ERR aws\_vpc.vpc: Creating…  
> Jan 17 14:07:23.973 ERR aws\_ebs\_volume.data\_disks[“n11”]: Creating…  
> Jan 17 14:07:24.616 ERR tls\_private\_key.ssh\_key: Creation complete after 2s [id=86d7f459eeaa9c7c128bd8155ff9c0532c658610]  
> Jan 17 14:07:24.624 ERR aws\_key\_pair.instance\_key: Creating…  
> Jan 17 14:07:24.624 ERR aws\_ssm\_parameter.ssh\_private\_key: Creating…  
> Jan 17 14:07:24.626 ERR local\_file.private\_key: Creating…  
> Jan 17 14:07:24.630 ERR local\_file.private\_key: Creation complete after 0s [id=c675d57da8f5086972725d8b5e6aa9e05a791b61]  
> Jan 17 14:07:24.836 ERR aws\_key\_pair.instance\_key: Creation complete after 0s [id=exasol-61e91933-key]  
> Jan 17 14:07:33.974 ERR aws\_vpc.vpc: Still creating… [10s elapsed]  
> Jan 17 14:07:33.975 ERR aws\_ebs\_volume.data\_disks[“n11”]: Still creating… [10s elapsed]  
> Jan 17 14:07:34.514 ERR aws\_ebs\_volume.data\_disks[“n11”]: Creation complete after 11s [id=vol-0c82f620ece118366]  
> Jan 17 14:07:34.550 ERR data.cloudinit\_config.cloud\_config[“n11”]: Reading…  
> Jan 17 14:07:34.558 ERR data.cloudinit\_config.cloud\_config[“n11”]: Read complete after 0s [id=2748441386]  
> Jan 17 14:07:35.661 ERR aws\_vpc.vpc: Creation complete after 12s [id=vpc-03f8f04bb86c0dd06]  
> Jan 17 14:07:35.687 ERR aws\_internet\_gateway.gateway: Creating…  
> Jan 17 14:07:35.690 ERR aws\_subnet.subnet: Creating…  
> Jan 17 14:07:35.700 ERR aws\_security\_group.exasol\_instance: Creating…  
> Jan 17 14:07:36.106 ERR aws\_internet\_gateway.gateway: Creation complete after 0s [id=igw-007a865dcef64e688]  
> Jan 17 14:07:36.123 ERR aws\_route\_table.route\_table: Creating…  
> Jan 17 14:07:37.101 ERR aws\_route\_table.route\_table: Creation complete after 1s [id=rtb-0152d89249608fd6a]  
> Jan 17 14:07:38.195 ERR aws\_security\_group.exasol\_instance: Creation complete after 2s [id=sg-06397050de022cc67]  
> Jan 17 14:07:45.690 ERR aws\_subnet.subnet: Still creating… [10s elapsed]  
> Jan 17 14:07:46.698 ERR aws\_subnet.subnet: Creation complete after 11s [id=subnet-092f1bd819849c454]  
> Jan 17 14:07:46.709 ERR aws\_route\_table\_association.route\_table\_assoc: Creating…  
> Jan 17 14:07:46.724 ERR aws\_instance.nodes[“n11”]: Creating…  
> Jan 17 14:07:47.069 ERR aws\_route\_table\_association.route\_table\_assoc: Creation complete after 0s [id=rtbassoc-0884a82d5de8501ed]  
> Jan 17 14:07:56.724 ERR aws\_instance.nodes[“n11”]: Still creating… [10s elapsed]  
> Jan 17 14:07:59.397 ERR aws\_instance.nodes[“n11”]: Creation complete after 12s [id=i-044bfc6a706aa3187]  
> Jan 17 14:07:59.407 ERR aws\_ec2\_instance\_state.node\_state[“n11”]: Creating…  
> Jan 17 14:07:59.408 ERR aws\_volume\_attachment.data\_disks[“n11”]: Creating…  
> Jan 17 14:08:09.407 ERR aws\_ec2\_instance\_state.node\_state[“n11”]: Still creating… [10s elapsed]  
> Jan 17 14:08:09.408 ERR aws\_volume\_attachment.data\_disks[“n11”]: Still creating… [10s elapsed]  
> Jan 17 14:08:09.623 ERR aws\_ec2\_instance\_state.node\_state[“n11”]: Creation complete after 11s [id=i-044bfc6a706aa3187]  
> Jan 17 14:08:09.634 ERR data.aws\_instance.nodes[“n11”]: Reading…  
> Jan 17 14:08:11.130 ERR data.aws\_instance.nodes[“n11”]: Read complete after 1s [id=i-044bfc6a706aa3187]  
> Jan 17 14:08:11.153 ERR local\_file.deployment\_info: Creating…  
> Jan 17 14:08:11.158 ERR local\_file.deployment\_info: Creation complete after 0s [id=087b741bf6b9f49c400f2e23452d2b3264c90498]  
> Jan 17 14:08:19.409 ERR aws\_volume\_attachment.data\_disks[“n11”]: Still creating… [20s elapsed]  
> Jan 17 14:08:20.468 ERR aws\_volume\_attachment.data\_disks[“n11”]: Creation complete after 21s [id=vai-2987957174]  
> Jan 17 14:08:20.481 ERR ╷  
> Jan 17 14:08:20.481 ERR │ Error: creating SSM Parameter (/exasol-61e91933/ssh\_private\_key): operation error SSM: PutParameter, https response error StatusCode: 400, RequestID: 6797b7fd-47fa-4953-a014-c740edd16e65, api error AccessDeniedException: User: _redacted_ is not authorized to perform: ssm:PutParameter on resource: arn:aws:ssm:eu-central-1:_redacted_:parameter/exasol-61e91933/ssh\_private\_key because no identity-based policy allows the ssm:PutParameter action

---

<div class="post-metadata">

**Author:** ![realtdegen](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@realtdegen](https://community.exasol.com/u/realtdegen)\
**Post date:** [January 17, 2026, 6:40pm UTC](https://community.exasol.com/t/error-when-trying-exosol-personal/268/2 "2026-01-17T18:40:10Z")

</div>

Hi Will

The error is caused by missing IAM permission for `ssm:PutParameter` on the SSM Parameter Store path where the SSH private key should be written, so the deployment user is not allowed to store `/exasol-61e91933/ssh_private_key` in SSM.

## What the error means

- The failing resource is `aws_ssm_parameter.ssh_private_key` that tries to create `/exasol-61e91933/ssh_private_key` in Parameter Store as a (secure) parameter.
- AWS returns `AccessDeniedException: User ... is not authorized to perform: ssm:PutParameter on resource: arn:aws:ssm:eu-central-1:...:parameter/exasol-61e91933/ssh_private_key because no identity-based policy allows the ssm:PutParameter action`, which means the IAM identity Terraform uses has no Allow (or is explicitly Denied) for this action.

## Likely root cause in your setup

The most probable causes are:

- An identity-based policy (user, group, or permissions boundary) that does **not** include `ssm:PutParameter` and possibly has a broader `Deny` for SSM or `ssm:*`.
- The Exasol PE Terraform code assumes it can create SSM parameters to store the generated SSH private key, but your IAM role for the `exasol` profile is restricted and does not allow writing to SSM Parameter Store.

## How to fix it (for Exasol PE)

Ask your AWS admin (or update your own policies, if allowed) to add an IAM statement similar to:

```json
{
  "Effect": "Allow",
  "Action": [
    "ssm:PutParameter",
    "ssm:AddTagsToResource"
  ],
  "Resource": "arn:aws:ssm:eu-central-1:<account-id>:parameter/exasol-61e91933/*"
}

```

- Attach this to the IAM user/role used by Terraform (your `exasol` profile).
- Ensure there is **no** conflicting explicit `Deny` that covers `ssm:PutParameter` on that path or on `arn:aws:ssm:eu-central-1:<account-id>:parameter/*`, because a Deny will override any Allow.

Once that permission is granted (and any Deny removed), re-run the Exasol Personal Edition deployment; the SSM parameter creation step should succeed and the rest of the stack can complete.

Let me know if you can move on with your Exasol Personal Edition following the advice above.

Best - Thomas D.

---

<div class="post-metadata">

**Author:** ![Will](https://avatars.discourse-cdn.com/v4/letter/w/90ced4/32.png) [@Will](https://community.exasol.com/u/Will)\
**Post date:** [January 17, 2026, 9:49pm UTC](https://community.exasol.com/t/error-when-trying-exosol-personal/268/3 "2026-01-17T21:49:35Z")

</div>

Hi Thomas,

Thanks for your tips, I managed to make it work.

I had to add another couple of permissions, this is the final policy JSON I used.

I think Exasol should update the [documentation](https://docs.exasol.com/db/latest/get_started/exasol_personal_aws_setup.htm) though, it was frustrating finding out missing permissions error by error.

```auto
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "ssm:PutParameter",
                "ssm:DeleteParameter",
                "ssm:AddTagsToResource",
                "ssm:ListTagsForResource",
                "ssm:GetParameters",
                "ssm:GetParameter"
            ],
            "Resource": "arn:aws:ssm:eu-central-1:account_id:parameter/exasol-*/*"
        },
        {
            "Sid": "VisualEditor1",
            "Effect": "Allow",
            "Action": "ssm:DescribeParameters",
            "Resource": "*"
        }
    ]
}

```

---

<div class="post-metadata">

**Author:** ![realtdegen](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@realtdegen](https://community.exasol.com/u/realtdegen)\
**Post date:** [January 18, 2026, 12:42am UTC](https://community.exasol.com/t/error-when-trying-exosol-personal/268/4 "2026-01-18T00:42:12Z")

</div>

Will, glad you’ve managed to move forward .

Indeed, as AWS IAM policies can be tricky, the current Exasol Personal Edition deployment pre-requisites instructions could be more precise in this respect.

Especially as this is known and documented however for general Exasol on AWS at:

> **[IAM Policy - AWS | Exasol DB Documentation](https://docs.exasol.com/db/7.1/administration/aws/installation/aws_iam_policy.htm)**
>
> Learn how to set up IAM policies before you start installation of Exasol on AWS.

Here it’s pointed to this [JSON policy](https://s3.eu-central-1.amazonaws.com/cloudtools.exasol.com/iam_policy.json) which covers the AWS IAM user requirements for the Personal Edition Terraform deployment in it as well.

As Exasol Personal Edition has just launched, please bear with us while we are constantly improving Personal Edition documentation for smoother user experience.

Now finally enjoy your Exasol Personal Edition trials, thank you for your feedback.

Best - Thomas D.

---

<div class="post-metadata">

**Author:** ![juergen\_albertsen](https://avatars.discourse-cdn.com/v4/letter/j/3bc359/32.png) [@juergen\_albertsen](https://community.exasol.com/u/juergen_albertsen)\
**Post date:** [January 19, 2026, 5:03pm UTC](https://community.exasol.com/t/error-when-trying-exosol-personal/268/5 "2026-01-19T17:03:09Z")

</div>

Hi Will, product manager of Exasol Personal here. Terribly sorry that you ran into issues and thanks for the feedback. Indeed a permission was missing from our instructions. We have now updated our [documentation](https://docs.exasol.com/db/latest/get_started/exasol_personal_aws_setup.htm).

---

<div class="post-metadata">

**Author:** ![Will](https://avatars.discourse-cdn.com/v4/letter/w/90ced4/32.png) [@Will](https://community.exasol.com/u/Will)\
**Post date:** [January 20, 2026, 8:47am UTC](https://community.exasol.com/t/error-when-trying-exosol-personal/268/6 "2026-01-20T08:47:48Z")

</div>

No problem at all, I understand Personal has just been launched. Thank you, the platform looks great!

---

<div class="post-metadata">

**Author:** ![juergen\_albertsen](https://avatars.discourse-cdn.com/v4/letter/j/3bc359/32.png) [@juergen\_albertsen](https://community.exasol.com/u/juergen_albertsen)\
**Post date:** [January 20, 2026, 9:30am UTC](https://community.exasol.com/t/error-when-trying-exosol-personal/268/7 "2026-01-20T09:30:47Z")

</div>

Glad to hear! I would be interested to learn what you are going to use it for. Can I reach out to you directly and perhaps we can even have a quick one-on-one chat?

---

<div class="post-metadata">

**Author:** ![Will](https://avatars.discourse-cdn.com/v4/letter/w/90ced4/32.png) [@Will](https://community.exasol.com/u/Will)\
**Post date:** [January 20, 2026, 9:53pm UTC](https://community.exasol.com/t/error-when-trying-exosol-personal/268/8 "2026-01-20T21:53:27Z")

</div>

I don’t think to have a very interesting story, but it’s always enriching to have a talk with fellow data technologists 🙂
