You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过AWS CLI创建OpenSearch域时访问策略正则验证失败求助

问题:AWS CLI创建OpenSearch域时访问策略正则验证失败

命令配置

ACCESS_POLICY_JSON=$(cat <<EOF
{
  &quot;Version&quot;: &quot;2012-10-17&quot;,
  &quot;Statement": [
    {
      &quot;Sid&quot;: &quot;AllowElasticsearchAccess&quot;,
      &quot;Effect&quot;: &quot;Allow&quot;,
      &quot;Principal&quot;: {
        &quot;AWS&quot;: &quot;*&quot;
      },
      &quot;Action&quot;: &quot;es:*&quot;,
      &quot;Resource&quot;: &quot;arn:aws:es:${AWS_REGION}:${AWS_ACCOUNT}:domain/es-dev-tenant/*&quot;
    }
  ]
}
EOF
)

aws opensearch create-domain --domain-name es-dev-tenant \
    --engine-version ${ES_VERSION} --region ${AWS_REGION} \
    --cluster-config InstanceType=${ES_INSTANCE_SIZE},InstanceCount=${ES_INSTANCE_COUNT},DedicatedMasterEnabled=false,ZoneAwarenessEnabled=false,MultiAZWithStandbyEnabled=false \
    --vpc-options $ES_VPC_OPTIONS --ebs-options EBSEnabled=true,VolumeType=gp2,VolumeSize=${ES_VOLUME_SIZE} \
    --access-policies "$ACCESS_POLICY_JSON"

错误信息

An error occurred (ValidationException) when calling the CreateDomain operation: 1 validation error detected: Value '{
  &quot;Version&quot;: &quot;2012-10-17&quot;,
  &quot;Statement": [
    {
      &quot;Sid&quot;: &quot;Allow elasticsearch access.&quot;,
      &quot;Effect&quot;: &quot;Allow&quot;,
      &quot;Principal": {
        &quot;AWS&quot;: &quot;*&quot;
      },
      &quot;Action&quot;: &quot;es:*&quot;,
      &quot;Resource&quot;: &quot;arn:aws:es:ap-southeast-2:6xxxx:domain/es-dev-tenant/*&quot;
    }
  ]
}' at 'accessPolicies' failed to satisfy constraint: Member must satisfy regular expression pattern: .*

原因分析

错误核心是访问策略JSON中的HTML转义双引号(&quot;),AWS CLI期望接收标准JSON格式字符串,&quot;会被当作普通字符处理,导致整个JSON结构不合法,触发验证失败(错误提示里的正则.*是兜底表述,实际为JSON格式无效)。

解决方法

将HEREDOC中的&quot;替换为普通双引号即可,HEREDOC内部可直接使用双引号,无需转义:

ACCESS_POLICY_JSON=$(cat <<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowElasticsearchAccess",
      "Effect": "Allow",
      "Principal": {
        "AWS": "*"
      },
      "Action": "es:*",
      "Resource": "arn:aws:es:${AWS_REGION}:${AWS_ACCOUNT}:domain/es-dev-tenant/*"
    }
  ]
}
EOF
)

aws opensearch create-domain --domain-name es-dev-tenant \
    --engine-version ${ES_VERSION} --region ${AWS_REGION} \
    --cluster-config InstanceType=${ES_INSTANCE_SIZE},InstanceCount=${ES_INSTANCE_COUNT},DedicatedMasterEnabled=false,ZoneAwarenessEnabled=false,MultiAZWithStandbyEnabled=false \
    --vpc-options $ES_VPC_OPTIONS --ebs-options EBSEnabled=true,VolumeType=gp2,VolumeSize=${ES_VOLUME_SIZE} \
    --access-policies "$ACCESS_POLICY_JSON"

额外注意事项

  • 若需在shell中对双引号转义,使用shell原生的\"而非HTML转义符
  • 确保${AWS_REGION}、${AWS_ACCOUNT}等环境变量已正确赋值,避免替换后生成无效ARN
  • 若仍有问题,可尝试将JSON压缩为单行格式传递,减少换行可能带来的解析问题:
    ACCESS_POLICY_JSON='{"Version":"2012-10-17","Statement":[{"Sid":"AllowElasticsearchAccess","Effect":"Allow","Principal":{"AWS":"*"},"Action":"es:*","Resource":"arn:aws:es:'${AWS_REGION}':'${AWS_ACCOUNT}':domain/es-dev-tenant/*"}]}'
    

内容的提问来源于stack exchange,提问作者Nigel Sheridan-Smith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 02:47:21