Due to policies on an overarching AWS organization account and attached firewall, the create stack fails and is unable to complete the Bitbbucket with ASI AWS quickstart install. The error "client unauthorized permission." is produced when the VPC stack tries to create an internet gateway
What would be recommended best practices to overcome this issue? Temporarily modifying the AWS organization account's policies/firewall to allow the creation of the internet gateway or modify the code for the bitbucket quickstart template to prohibit the 'create internet gateway"? I am concerned that manually editing the code behind the template, could cause issues in the future for changes/upgrades etc. In addition, why is an internet gateway created during the install if the template provided for the AWS bitbucket quickstart does not ask for a value to be entered ie true/false create internet gateway?