You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置S3事件通知至SQS时遇InvalidArgument错误求助

问题排查:Terraform配置S3事件通知到SQS失败

问题描述

尝试通过Terraform为SQS配置S3事件通知,参考Terraform Registry代码修改命名规范后执行,除事件通知外其他资源均创建成功,现附上模块代码及报错信息请求排查。

模块代码

data "aws_iam_policy_document" "create-applicant-policy" {
  statement {
    effect = "Allow"

    principals {
      type        = "*"
      identifiers = ["*"]
    }

    actions   = ["sqs:SendMessage"]
    resources = ["arn:aws:sqs:*:*:s3-event-notification-queue"]

    condition {
      test     = "ArnEquals"
      variable = "aws:SourceArn"
      values   = [aws_s3_bucket.vardo-assets-bucket.arn]
    }
  }
}

resource "aws_s3_bucket" "vardo-assets-bucket" {
  bucket = var.assets-bucket
}

resource "aws_sqs_queue" "create-applicant-queue" {
  name   = var.create-applicant-queue
  policy = data.aws_iam_policy_document.create-applicant-policy.json
}

resource "aws_s3_bucket_notification" "vardo-assets-bucket-event-notification" {
  bucket = aws_s3_bucket.vardo-assets-bucket.id

  queue {
    queue_arn     = aws_sqs_queue.create-applicant-queue.arn
    events        = ["s3:ObjectCreated:Put"]
    filter_prefix = "Prospects/"
    filter_suffix = ".pdf"
  }
}

报错信息

Error: creating S3 Bucket (vardo-assets-dev) Notification: operation error S3: PutBucketNotificationConfiguration, https response error StatusCode: 400, RequestID: P23KKT6S8M2T1RZG, HostID: AJhzSoWnHWR/TvUDvoCeDWS3Idb83EhQIDt7QsNhqA90bWu/GXwjnXMJ/s/ty3kGsWQInKbOYvwtee5Z3fhYwg==, api error InvalidArgument: Unable to validate the following destination configurations with module.create-applicant-module.aws_s3_bucket_notification.vardo-assets-bucket-event-notification, on modules/createApplicant/main.tf line 30, in resource "aws_s3_bucket_notification" "vardo-assets-bucket-event-notification": 30: resource "aws_s3_bucket_notification" "vardo-assets-bucket-event-notification" {

问题原因及修复方案

核心问题

SQS队列的IAM策略中,resources字段硬编码了固定队列ARN,但实际创建的队列名称由变量var.create-applicant-queue指定(比如报错中的桶为vardo-assets-dev,对应的队列名大概率不是s3-event-notification-queue),导致策略中的资源ARN与实际队列ARN不匹配。S3验证事件通知目标权限时,发现队列策略未正确授权当前桶发送消息,因此返回InvalidArgument错误。

修复步骤

修改data "aws_iam_policy_document" "create-applicant-policy"中的resources字段,引用实际创建的SQS队列ARN,替换硬编码值:

data "aws_iam_policy_document" "create-applicant-policy" {
  statement {
    effect = "Allow"

    principals {
      type        = "*"
      identifiers = ["*"]
    }

    actions   = ["sqs:SendMessage"]
    # 改为引用实际队列的ARN
    resources = [aws_sqs_queue.create-applicant-queue.arn]

    condition {
      test     = "ArnEquals"
      variable = "aws:SourceArn"
      values   = [aws_s3_bucket.vardo-assets-bucket.arn]
    }
  }
}

额外检查点

  • 确认S3桶与SQS队列处于同一AWS区域(跨区域事件通知需额外配置)
  • 验证变量var.create-applicant-queue的取值是否符合SQS队列命名规范,无特殊字符或格式错误

内容的提问来源于stack exchange,提问作者Ozey5540

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 18:23:09