Terraform配置S3通知至SNS报错:无法验证目标配置
S3通知配置验证失败问题分析与修复
我有一个名为image_bucket的S3存储桶和image_changes_topic的SNS主题,想要在S3桶创建对象时触发SNS通知,编写了如下Terraform配置:
resource "aws_s3_bucket" "image_bucket" { bucket = var.image_bucket_name } resource "aws_s3_bucket" "reduced_image_bucket" { bucket = var.reduced_image_bucket_name } data "aws_iam_policy_document" "image_changes_topic_policy" { statement { effect = "Allow" principals { type = "Service" identifiers = ["s3.amazonaws.com"] } actions = ["SNS:Publish"] resources = [aws_sns_topic.image_changes_topic.arn] condition { test = "ArnLike" variable = "aws:SourceArn" values = [aws_s3_bucket.image_bucket.arn] } } } resource "aws_sns_topic" "image_changes_topic" { name = var.image_changes_topic_name } resource "aws_s3_bucket_notification" "bucket_notification" { bucket = aws_s3_bucket.image_bucket.id topic { topic_arn = aws_sns_topic.image_changes_topic.arn events = ["s3:ObjectCreated:*"] } }
执行terraform apply时出现如下错误:
module.dark_room_app_infra.aws_iam_policy.image_bucket_to_image_changes_sns_policy: Destruction complete after 0s ╷ │ Error: creating S3 Bucket (dr-original-images) Notification: operation error S3: PutBucketNotificationConfiguration, https response error StatusCode: 400, RequestID: efg, HostID: abc/O4=, api error InvalidArgument: Unable to validate the following destination configurations │ │ with module.dark_room_app_infra.aws_s3_bucket_notification.bucket_notification, │ on modules/dark-room-app/s3.tf line 78, in resource "aws_s3_bucket_notification" "bucket_notification": │ 78: resource "aws_s3_bucket_notification" "bucket_notification" { │
问题
- 该
InvalidArgument: Unable to validate the following destination configurations错误是什么含义? - 我已配置
image_changes_topic_policy策略授权S3向SNS发消息,为何仍出现此验证错误? - 该如何修复?
错误含义解释
这个错误的意思是:S3在配置桶通知时,无法确认你指定的目标(这里是SNS主题)是否允许S3向它发送消息。本质就是S3没有合法权限访问该SNS主题,或者权限配置还未生效。
问题原因分析
你只定义了image_changes_topic_policy这个IAM策略文档,但没有把这个策略实际绑定到SNS主题上。这个策略文档只是个权限模板,不绑定到主题的话,相当于没给SNS设置对应的访问权限,S3自然没法向它发消息,验证就会失败。另外,就算后续绑定了策略,如果Terraform先创建S3通知、再绑定策略,也会因为权限未及时生效导致验证不通过。
修复方案
步骤1:添加SNS主题策略绑定资源
新增aws_sns_topic_policy资源,把你定义的策略文档绑定到image_changes_topic主题上,让权限真正生效。
步骤2:明确资源依赖关系
让S3通知资源依赖于SNS主题策略,确保策略先创建完成并生效,再创建S3通知。
修改后的完整配置如下:
resource "aws_s3_bucket" "image_bucket" { bucket = var.image_bucket_name } resource "aws_s3_bucket" "reduced_image_bucket" { bucket = var.reduced_image_bucket_name } data "aws_iam_policy_document" "image_changes_topic_policy" { statement { effect = "Allow" principals { type = "Service" identifiers = ["s3.amazonaws.com"] } actions = ["SNS:Publish"] resources = [aws_sns_topic.image_changes_topic.arn] condition { test = "ArnLike" variable = "aws:SourceArn" values = ["${aws_s3_bucket.image_bucket.arn}/*"] # 加上/*,精准匹配桶内对象的事件源ARN } } } resource "aws_sns_topic" "image_changes_topic" { name = var.image_changes_topic_name } # 新增:将策略绑定到SNS主题,让权限生效 resource "aws_sns_topic_policy" "image_changes_topic_policy" { arn = aws_sns_topic.image_changes_topic.arn policy = data.aws_iam_policy_document.image_changes_topic_policy.json } resource "aws_s3_bucket_notification" "bucket_notification" { bucket = aws_s3_bucket.image_bucket.id # 明确依赖,确保策略先创建完成 depends_on = [aws_sns_topic_policy.image_changes_topic_policy] topic { topic_arn = aws_sns_topic.image_changes_topic.arn events = ["s3:ObjectCreated:*"] } }
另外,策略里的aws:SourceArn加上/*,能更精准匹配S3桶内对象的事件源ARN,避免权限范围过大。
内容的提问来源于stack exchange,提问作者robskrob
相关产品推荐
相关产品推荐

