You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置S3通知至SNS报错:无法验证目标配置

S3通知配置验证失败问题分析与修复

我有一个名为image_bucket的S3存储桶和image_changes_topic的SNS主题,想要在S3桶创建对象时触发SNS通知,编写了如下Terraform配置:

resource "aws_s3_bucket" "image_bucket" {
  bucket = var.image_bucket_name
}

resource "aws_s3_bucket" "reduced_image_bucket" {
  bucket = var.reduced_image_bucket_name
}

data "aws_iam_policy_document" "image_changes_topic_policy" {
  statement {
    effect = "Allow"

    principals {
      type        = "Service"
      identifiers = ["s3.amazonaws.com"]
    }

    actions   = ["SNS:Publish"]
    resources = [aws_sns_topic.image_changes_topic.arn]

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = [aws_s3_bucket.image_bucket.arn]
    }
  }
}

resource "aws_sns_topic" "image_changes_topic" {
  name = var.image_changes_topic_name
}

resource "aws_s3_bucket_notification" "bucket_notification" {
  bucket = aws_s3_bucket.image_bucket.id
  topic {
    topic_arn     = aws_sns_topic.image_changes_topic.arn
    events        = ["s3:ObjectCreated:*"]
  }
}

执行terraform apply时出现如下错误:

module.dark_room_app_infra.aws_iam_policy.image_bucket_to_image_changes_sns_policy: Destruction complete after 0s
╷
│ Error: creating S3 Bucket (dr-original-images) Notification: operation error S3: PutBucketNotificationConfiguration, https response error StatusCode: 400, RequestID: efg, HostID: abc/O4=, api error InvalidArgument: Unable to validate the following destination configurations
│
│   with module.dark_room_app_infra.aws_s3_bucket_notification.bucket_notification,
│   on modules/dark-room-app/s3.tf line 78, in resource "aws_s3_bucket_notification" "bucket_notification":
│   78: resource "aws_s3_bucket_notification" "bucket_notification" {
│

问题

  1. 该InvalidArgument: Unable to validate the following destination configurations错误是什么含义?
  2. 我已配置image_changes_topic_policy策略授权S3向SNS发消息,为何仍出现此验证错误?
  3. 该如何修复?

错误含义解释

这个错误的意思是:S3在配置桶通知时,无法确认你指定的目标(这里是SNS主题)是否允许S3向它发送消息。本质就是S3没有合法权限访问该SNS主题,或者权限配置还未生效。

问题原因分析

你只定义了image_changes_topic_policy这个IAM策略文档,但没有把这个策略实际绑定到SNS主题上。这个策略文档只是个权限模板,不绑定到主题的话,相当于没给SNS设置对应的访问权限,S3自然没法向它发消息,验证就会失败。另外,就算后续绑定了策略,如果Terraform先创建S3通知、再绑定策略,也会因为权限未及时生效导致验证不通过。

修复方案

步骤1:添加SNS主题策略绑定资源

新增aws_sns_topic_policy资源,把你定义的策略文档绑定到image_changes_topic主题上,让权限真正生效。

步骤2:明确资源依赖关系

让S3通知资源依赖于SNS主题策略,确保策略先创建完成并生效,再创建S3通知。

修改后的完整配置如下:

resource "aws_s3_bucket" "image_bucket" {
  bucket = var.image_bucket_name
}

resource "aws_s3_bucket" "reduced_image_bucket" {
  bucket = var.reduced_image_bucket_name
}

data "aws_iam_policy_document" "image_changes_topic_policy" {
  statement {
    effect = "Allow"

    principals {
      type        = "Service"
      identifiers = ["s3.amazonaws.com"]
    }

    actions   = ["SNS:Publish"]
    resources = [aws_sns_topic.image_changes_topic.arn]

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["${aws_s3_bucket.image_bucket.arn}/*"] # 加上/*,精准匹配桶内对象的事件源ARN
    }
  }
}

resource "aws_sns_topic" "image_changes_topic" {
  name = var.image_changes_topic_name
}

# 新增:将策略绑定到SNS主题,让权限生效
resource "aws_sns_topic_policy" "image_changes_topic_policy" {
  arn    = aws_sns_topic.image_changes_topic.arn
  policy = data.aws_iam_policy_document.image_changes_topic_policy.json
}

resource "aws_s3_bucket_notification" "bucket_notification" {
  bucket = aws_s3_bucket.image_bucket.id
  
  # 明确依赖,确保策略先创建完成
  depends_on = [aws_sns_topic_policy.image_changes_topic_policy]

  topic {
    topic_arn     = aws_sns_topic.image_changes_topic.arn
    events        = ["s3:ObjectCreated:*"]
  }
}

另外,策略里的aws:SourceArn加上/*,能更精准匹配S3桶内对象的事件源ARN,避免权限范围过大。

内容的提问来源于stack exchange,提问作者robskrob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 13:55:58