You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CloudFormation创建IAM用户及策略报错求助:策略语法错误

IAM用户策略CloudFormation模板语法错误修复

报错信息

Resource handler returned message: "Syntax errors in policy. (Service: Iam, Status Code: 400",HandlerError Code: InvalidRequest"

问题分析

模板存在三处关键问题:

  • 缩进错误:UserPolicy的UserName属性未缩进在Properties节点下,属于YAML结构错误。
  • IAM策略语法错误:最后一条权限声明中使用了单数Resource,IAM策略文档要求资源列表必须用复数Resources。
  • 条件命名逻辑矛盾:条件NoUser实际对应“创建用户”的场景(当ActivateUser为Yes时生效),命名与逻辑不符,建议修正以提升可读性。

修复后的完整模板

Parameters:
  EnterUserName:
    Description: 输入用户名
    Type: String
    AllowedPattern: ^proga.*$

  BastionName:
    Description: 输入EC2标签名称
    Type: String    

  ActivateUser:
    Description: 是否激活用户?
    Type: String
    Default: No
    AllowedValues:
      - No
      - Yes
    ConstraintDescription: 无效选择!   

Conditions:
  CreateUser: !Equals [!Ref ActivateUser, Yes]    

Resources:
  SSMSessionUser:
    Condition: CreateUser
    Type: AWS::IAM::User
    Properties:
      UserName: !Ref EnterUserName

  UserPolicy:
    Condition: CreateUser
    Type: AWS::IAM::UserPolicy
    Properties:
      PolicyName: !Sub ${AWS::StackName}-policyName
      PolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Action: ssm:StartSession
            Resources:
              - !Sub arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:document/SSM-SessionManagerRunShell
          - Effect: Allow
            Action: ssm:StartSession
            Resources: 
              - !Sub arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:instance/*
            Condition:
              StringEquals:
                'aws:ResourceTag/Bastion': !Ref BastionName
          - Effect: Allow
            Action:
              - ssm:TerminateSession
              - ssm:ResumeSession
            Resources: 
              - 'arn:aws:ssm:*:*:session/${aws:userid}-*'
      UserName: !Ref SSMSessionUser

修复说明

  1. 修正UserPolicy中UserName的缩进,将其放入Properties节点内。
  2. 把最后一条Statement里的Resource改为复数Resources,符合IAM策略语法规范。
  3. 将条件NoUser重命名为CreateUser,匹配其“当ActivateUser为Yes时创建资源”的逻辑,提升模板可读性。

内容的提问来源于stack exchange,提问作者D' go

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 12:07:18