You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform升级至0.12.31时出现Route53 GetHostedZone 403权限拒绝错误

Terraform 0.11.15升级至0.12.31时Route53 403权限错误问题

升级Terraform从0.11.15版本到0.12.31版本时,遇到如下权限拒绝错误导致升级暂停:

Error: AccessDenied: User: arn:aws:sts::121212121212:assumed-role/AWSReservedSSO_AdministratorAccess_e9ff994d3fa76329/user is not authorized to access this resource
status code: 403, request id: 37fc48e4-3b89-41fd-a1cf-da8418a18d67

通过执行TF_LOG=DEBUG terraform plan启用调试模式后,定位到错误来自调用Route53的GetHostedZone接口时返回的403响应。

已进行的排查动作:

  • 怀疑AWS Provider版本问题,先后更换为v2.50.0、v2.70.0、v2.70.4版本测试,问题未解决
  • 确认该403错误在原Terraform 0.11.15版本下不会出现

相关配置信息:
Route53记录使用独立的AWS配置文件,对应的Provider配置如下:

provider "aws" {
  profile = "testing"
  region  = "ap-southeast-2"
  version = "v2.70.0"
}

provider "aws" {
  alias   = "us-east-1"
  profile = "testing"
  region  = "us-east-1"
  version = "v2.70.0"
}

provider "aws" {
  profile = "test"
  region  = "ap-southeast-2"
  alias   = "route53_company_net"
  version = "v2.70.0"
}

dns.tf文件中Route53资源定义:

resource "aws_route53_record" "countryconnect" {
  zone_id = data.aws_route53_zone.primary.zone_id
  name    = "au01-connect-testing.${var.domain}"
  type    = "A"
  alias {
    name                   = module.cloudfront_api.domain_name
    zone_id                = module.cloudfront_api.hosted_zone_id
    evaluate_target_health = false
  }
  provider = aws.route53_company_net
}

注:Route53 DNS记录使用aws.route53_company_net Provider。

内容的提问来源于stack exchange,提问作者erlchamp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 12:02:18