You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EC2实例使用Web Identity调用AssumeRoleWithWebIdentity权限报错排查

问题排查与修复方案

核心问题:JWT受众与角色信任策略不匹配

你生成Google身份令牌时指定的受众是example-audience.apps.googleusercontent.com,但EC2-Role的信任策略中,条件判断的accounts.google.com:aud值是googleaudienceexample,两者完全不一致。这会导致AWS验证令牌时,判定该令牌不符合角色的信任要求,直接返回未授权错误。

修复方式(二选一即可)

  • 修改生成令牌的脚本,将受众值统一为信任策略中的值:
    #! /bin/bash
    SERVICE_ACCOUNT="just-a-service-account@test-20240702122400.iam.gserviceaccount.com"
    AUDICENCES="googleaudienceexample"
    OUTPUT_FILE_PATH="/home/ubuntu/utils/web-identity-token.jwt"
    gcloud auth print-identity-token --impersonate-service-account $SERVICE_ACCOUNT --audiences=$AUDIENCES  > $OUTPUT_FILE_PATH
    
  • 或者修改EC2-Role的信任策略,将受众值统一为生成令牌时的配置:
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Principal": {
                    "Federated": "accounts.google.com"
                },
                "Action": "sts:AssumeRoleWithWebIdentity",
                "Condition": {
                    "StringEquals": {
                        "accounts.google.com:aud": "example-audience.apps.googleusercontent.com"
                    }
                }
            }
        ]
    }
    

额外验证点(统一受众后仍报错时检查)

虽然你提到Server-User拥有AdministratorAccess权限(默认包含sts:AssumeRoleWithWebIdentity),但可以执行以下命令验证当前身份的权限是否生效:

aws iam simulate-custom-policy --policy-document '{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"sts:AssumeRoleWithWebIdentity","Resource":"arn:aws:iam::123456789012:role/EC2-Role"}]}' --action-names sts:AssumeRoleWithWebIdentity --resource-arns arn:aws:iam::123456789012:role/EC2-Role

返回Allowed则权限正常,反之需检查用户权限配置。

注意:EC2实例角色的作用说明

你提到EC2实例已绑定EC2-Role,但当前执行命令时使用的是Server-User的身份(通过aws configure配置),而非实例角色。sts:AssumeRoleWithWebIdentity是通过外部身份凭证(Google JWT)获取目标角色的临时凭证,与实例当前绑定的角色无关,无需依赖实例角色权限。

内容的提问来源于stack exchange,提问作者Eloy Ruiz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 17:37:43