Terraform部署AWS EventBridge Schedule角色权限错误修复咨询
问题
尝试部署AWS EventBridge Schedule并关联相关策略,使用的Terraform配置如下:
resource "aws_iam_role" "eventbridge_role" { name = "EventBridgeRoleForStepFunctions" assume_role_policy = jsonencode({ "Version" = "2012-10-17", "Statement" = [ { "Effect" = "Allow", "Principal" = { "Service" = "scheduler.amazonaws.com" }, "Action" = "sts:AssumeRole" } ] }) } resource "aws_iam_policy" "eventbridge_invoke_stepfunctions_policy" { name = "EventBridgeInvokeStepFunctionsPolicy" path = "/" description = "Allow EventBridge to invoke Step Functions" policy = jsonencode({ Version = "2012-10-17", Statement = [ { Effect = "Allow", Action = "states:StartExecution", Resource = aws_sfn_state_machine.MySandboxStateMachine.arn } ] }) } resource "aws_iam_policy_attachment" "eventbridge_role_policy_attachment" { name = "StepFunctionPolicyAttachment" policy_arn = aws_iam_policy.eventbridge_invoke_stepfunctions_policy.arn roles = [aws_iam_role.eventbridge_role.name] } resource "aws_scheduler_schedule" "every_five_minutes" { name = "every-five-minutes" group_name = "default" flexible_time_window { mode = "OFF" } schedule_expression = "cron(0/5 * * * ? *)" target { arn = aws_sfn_state_machine.MySandboxStateMachine.arn role_arn = aws_iam_role.eventbridge_role.arn } }
执行时出现错误:
Creating Amazon EventBridge Scheduler Schedule (every-five-minutes): operation error Scheduler: CreateSchedule, https response error StatusCode: 400, RequestID: a3a7f4fa-b96e-4107-a041-2cd339e266c7, ValidationException: The execution role you provide must allow AWS EventBridge Scheduler to assume the role.
请问如何正确关联策略解决该问题?
解决方案
错误核心原因是IAM角色信任策略的服务主体格式不正确,EventBridge Scheduler要求使用区域化的服务主体(格式为<region>.scheduler.amazonaws.com),而非全局的scheduler.amazonaws.com。此外,需确保IAM角色的权限策略完全生效后再创建调度器,避免时序问题。
修正后的完整配置
# 动态获取当前部署的AWS区域 data "aws_region" "current" {} resource "aws_iam_role" "eventbridge_role" { name = "EventBridgeRoleForStepFunctions" assume_role_policy = jsonencode({ "Version" = "2012-10-17", "Statement" = [ { "Effect" = "Allow", "Principal" = { "Service" = "${data.aws_region.current.name}.scheduler.amazonaws.com" }, "Action" = "sts:AssumeRole" } ] }) } resource "aws_iam_policy" "eventbridge_invoke_stepfunctions_policy" { name = "EventBridgeInvokeStepFunctionsPolicy" path = "/" description = "Allow EventBridge to invoke Step Functions" policy = jsonencode({ Version = "2012-10-17", Statement = [ { Effect = "Allow", Action = "states:StartExecution", Resource = aws_sfn_state_machine.MySandboxStateMachine.arn } ] }) } resource "aws_iam_policy_attachment" "eventbridge_role_policy_attachment" { name = "StepFunctionPolicyAttachment" policy_arn = aws_iam_policy.eventbridge_invoke_stepfunctions_policy.arn roles = [aws_iam_role.eventbridge_role.name] } resource "aws_scheduler_schedule" "every_five_minutes" { name = "every-five-minutes" group_name = "default" # 显式依赖策略附件,确保角色权限已完全生效 depends_on = [aws_iam_policy_attachment.eventbridge_role_policy_attachment] flexible_time_window { mode = "OFF" } schedule_expression = "cron(0/5 * * * ? *)" target { arn = aws_sfn_state_machine.MySandboxStateMachine.arn role_arn = aws_iam_role.eventbridge_role.arn } }
关键修改说明
- 添加
data "aws_region" "current"数据源,动态获取当前AWS区域,避免硬编码区域信息 - 将信任策略中的服务主体改为区域化格式
${data.aws_region.current.name}.scheduler.amazonaws.com,满足EventBridge Scheduler的角色信任要求 - 在
aws_scheduler_schedule中添加depends_on依赖,确保IAM角色的权限策略完全附着后再创建调度器,避免因资源创建时序问题导致权限未生效
内容的提问来源于stack exchange,提问作者Aleksandrs
相关产品推荐
相关产品推荐

