You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform跨账号SNS-SQS订阅因无法自动确认超时失败

跨账号SQS订阅SNS Topic失败:无法自动确认订阅

尝试将账号A(392607711111)中的SQS队列订阅到账号B(473655411111)中的SNS Topic,执行terraform apply时2分钟后订阅失败,报错无法自动确认订阅。

执行日志

aws_sns_topic_subscription.storetime_offset_sqs_queue: Still creating... [2m0s elapsed]
╷
│ Error: waiting for SNS Topic Subscription (arn:aws:sns:eu-west-1:473655411111:store-eta-published:9b9de7b2-c240-46f2-a345-45431a123994) confirmation: timeout while waiting for state to become 'false' (last state: 'true', timeout: 2m0s)
│ 
│   with aws_sns_topic_subscription.store_eta_published_sqs_queue,
│   on store-eta-published-sqs.tf line 92, in resource "aws_sns_topic_subscription" "store_eta_published_sqs_queue":
│   92: resource "aws_sns_topic_subscription" "store_eta_published_sqs_queue" {
│ 
╵
╷
│ Error: waiting for SNS Topic Subscription (arn:aws:sns:eu-west-1:473655411111:store-time-offset-changed:ba4e0185-9697-499b-9710-c154c2e22545) confirmation: timeout while waiting for state to become 'false' (last state: 'true', timeout: 2m0s)
│ 
│   with aws_sns_topic_subscription.storetime_offset_sqs_queue,
│   on storetime-offset-sqs.tf line 92, in resource "aws_sns_topic_subscription" "storetime_offset_sqs_queue":
│   92: resource "aws_sns_topic_subscription" "storetime_offset_sqs_queue" {
│ 
╵

Exited with code exit status 1

相关配置

SNS策略

resource "aws_sns_topic_policy" "cross_account_policy" {
  count = length(local.topic_names)
  arn   = aws_sns_topic.sns_topics.*.arn[count.index]
  policy = <<EOF
{
  "Version": "2008-10-17",
  "Id": "maverick_cross_account_subscription_policy",
  "Statement": [
    {
       "Effect":"Allow",
       "Principal":{
          "AWS":"392607711111"
       },
       "Action":"sns:subscribe",
       "Resource":"${aws_sns_topic.sns_topics.*.arn[count.index]}"
    }
  ]
}
EOF
}

SQS策略

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "topic-subscription-arn:arn:aws:sns:eu-west-1:473655411111:store-time-offset-changed",
      "Effect": "Allow",
      "Principal": "*",
      "Action": "sqs:SendMessage",
      "Resource": "dplus-storetime-offset-queue",
      "Condition": {
        "ArnLike": {
          "aws:SourceArn": "arn:aws:sns:eu-west-1:473655411111:store-time-offset-changed"
        }
      }
    }
  ]
}

SNS订阅配置

resource "aws_sns_topic_subscription" "store_eta_published_sqs_queue" {
  provider  = aws.reactor-eu-west-1
  topic_arn = local.store_eta_published_topic_arn
  protocol  = "sqs"
  endpoint  = aws_sqs_queue.store_eta_published_sqs_queue.arn
}

SQS资源配置

resource "aws_sqs_queue" "store_eta_published_sqs_queue" {
  name                        = local.store_eta_published_queue_name
  delay_seconds               = 0
  fifo_queue                  = false
  content_based_deduplication = false
  visibility_timeout_seconds  = 60
  receive_wait_time_seconds   = 0
  redrive_policy              = "{\"deadLetterTargetArn\":\"${aws_sqs_queue.store_eta_published_sqs_queue_dead_letter.arn}\",\"maxReceiveCount\":${local.queue_retry_count}}"
  depends_on                  = [aws_sqs_queue.store_eta_published_sqs_queue_dead_letter]
  message_retention_seconds   = 345600 # SQS default
}

resource "aws_sqs_queue" "store_eta_published_sqs_queue_dead_letter" {
  name       = "${local.store_eta_published_queue_name}-dead-letter"
  fifo_queue = false
  policy     = ""
}
data "aws_iam_policy_document" "store_eta_published_sqs_queue" {
  statement {
    sid    = "topic-subscription-arn:${local.store_eta_published_topic_arn}"
    effect = "Allow"

    principals {
      type        = "AWS"
      identifiers = ["473655411111"]
    }

    actions   = ["sqs:SendMessage"]
    resources = [aws_sqs_queue.store_eta_published_sqs_queue.name]
  }
}

resource "aws_sqs_queue_policy" "store_eta_published_sqs_queue" {
  queue_url = aws_sqs_queue.store_eta_published_sqs_queue.id
  policy    = data.aws_iam_policy_document.store_eta_published_sqs_queue.json
}

AWS Provider配置

provider "aws" {
  alias   = "reactor-eu-west-1"
  region  = "eu-west-1"
  access_key = data.aws_secretsmanager_secret_version.current-reactor-access-key.secret_string
  secret_key = data.aws_secretsmanager_secret_version.current-reactor-secret-key.secret_string
}

修复方案

1. 修正SQS策略的Resource字段

AWS IAM策略中资源必须使用ARN标识,不能用队列名称。修改后的SQS策略:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "topic-subscription-arn:arn:aws:sns:eu-west-1:473655411111:store-time-offset-changed",
      "Effect": "Allow",
      "Principal": "*",
      "Action": "sqs:SendMessage",
      "Resource": "arn:aws:sqs:eu-west-1:392607711111:dplus-storetime-offset-queue",
      "Condition": {
        "ArnLike": {
          "aws:SourceArn": "arn:aws:sns:eu-west-1:473655411111:store-time-offset-changed"
        }
      }
    }
  ]
}

2. 修正SQS IAM策略文档的资源引用

同样将资源从队列名称改为ARN,确保权限生效:

data "aws_iam_policy_document" "store_eta_published_sqs_queue" {
  statement {
    sid    = "topic-subscription-arn:${local.store_eta_published_topic_arn}"
    effect = "Allow"

    principals {
      type        = "AWS"
      identifiers = ["473655411111"]
    }

    actions   = ["sqs:SendMessage"]
    resources = [aws_sqs_queue.store_eta_published_sqs_queue.arn]
  }
}

3. 延长订阅确认超时时间(可选)

如果权限配置生效较慢,可延长Terraform的订阅确认超时时间:

resource "aws_sns_topic_subscription" "store_eta_published_sqs_queue" {
  provider                      = aws.reactor-eu-west-1
  topic_arn                     = local.store_eta_published_topic_arn
  protocol                      = "sqs"
  endpoint                      = aws_sqs_queue.store_eta_published_sqs_queue.arn
  confirmation_timeout_in_minutes = 5 # 延长至5分钟
}

内容的提问来源于stack exchange,提问作者Farhad-Taran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 23:17:33