You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署AWS EventBridge Schedule角色权限错误修复咨询

问题

尝试部署AWS EventBridge Schedule并关联相关策略,使用的Terraform配置如下:

resource "aws_iam_role" "eventbridge_role" {
  name = "EventBridgeRoleForStepFunctions"

  assume_role_policy = jsonencode({
    "Version" = "2012-10-17",
    "Statement" = [
      {
        "Effect"    = "Allow",
        "Principal" = {
          "Service" = "scheduler.amazonaws.com"
        },
        "Action"    = "sts:AssumeRole"
      }
    ]
  })
}

resource "aws_iam_policy" "eventbridge_invoke_stepfunctions_policy" {
  name        = "EventBridgeInvokeStepFunctionsPolicy"
  path        = "/"
  description = "Allow EventBridge to invoke Step Functions"

  policy = jsonencode({
    Version = "2012-10-17",
    Statement = [
      {
        Effect   = "Allow",
        Action   = "states:StartExecution",
        Resource = aws_sfn_state_machine.MySandboxStateMachine.arn
      }
    ]
  })
}

resource "aws_iam_policy_attachment" "eventbridge_role_policy_attachment" {
  name = "StepFunctionPolicyAttachment"
  policy_arn = aws_iam_policy.eventbridge_invoke_stepfunctions_policy.arn
  roles = [aws_iam_role.eventbridge_role.name]
}

resource "aws_scheduler_schedule" "every_five_minutes" {
  name       = "every-five-minutes"
  group_name = "default"

  flexible_time_window {
    mode = "OFF"
  }

  schedule_expression = "cron(0/5 * * * ? *)"

  target {
    arn      = aws_sfn_state_machine.MySandboxStateMachine.arn
    role_arn = aws_iam_role.eventbridge_role.arn
  }
}

执行时出现错误:

Creating Amazon EventBridge Scheduler Schedule (every-five-minutes): operation error Scheduler: CreateSchedule, https response error StatusCode: 400, RequestID: a3a7f4fa-b96e-4107-a041-2cd339e266c7, ValidationException: The execution role you provide must allow AWS EventBridge Scheduler to assume the role.

请问如何正确关联策略解决该问题?

解决方案

错误核心原因是IAM角色信任策略的服务主体格式不正确,EventBridge Scheduler要求使用区域化的服务主体(格式为<region>.scheduler.amazonaws.com),而非全局的scheduler.amazonaws.com。此外,需确保IAM角色的权限策略完全生效后再创建调度器,避免时序问题。

修正后的完整配置

# 动态获取当前部署的AWS区域
data "aws_region" "current" {}

resource "aws_iam_role" "eventbridge_role" {
  name = "EventBridgeRoleForStepFunctions"

  assume_role_policy = jsonencode({
    "Version" = "2012-10-17",
    "Statement" = [
      {
        "Effect"    = "Allow",
        "Principal" = {
          "Service" = "${data.aws_region.current.name}.scheduler.amazonaws.com"
        },
        "Action"    = "sts:AssumeRole"
      }
    ]
  })
}

resource "aws_iam_policy" "eventbridge_invoke_stepfunctions_policy" {
  name        = "EventBridgeInvokeStepFunctionsPolicy"
  path        = "/"
  description = "Allow EventBridge to invoke Step Functions"

  policy = jsonencode({
    Version = "2012-10-17",
    Statement = [
      {
        Effect   = "Allow",
        Action   = "states:StartExecution",
        Resource = aws_sfn_state_machine.MySandboxStateMachine.arn
      }
    ]
  })
}

resource "aws_iam_policy_attachment" "eventbridge_role_policy_attachment" {
  name       = "StepFunctionPolicyAttachment"
  policy_arn = aws_iam_policy.eventbridge_invoke_stepfunctions_policy.arn
  roles      = [aws_iam_role.eventbridge_role.name]
}

resource "aws_scheduler_schedule" "every_five_minutes" {
  name       = "every-five-minutes"
  group_name = "default"

  # 显式依赖策略附件,确保角色权限已完全生效
  depends_on = [aws_iam_policy_attachment.eventbridge_role_policy_attachment]

  flexible_time_window {
    mode = "OFF"
  }

  schedule_expression = "cron(0/5 * * * ? *)"

  target {
    arn      = aws_sfn_state_machine.MySandboxStateMachine.arn
    role_arn = aws_iam_role.eventbridge_role.arn
  }
}

关键修改说明

  • 添加data "aws_region" "current"数据源,动态获取当前AWS区域,避免硬编码区域信息
  • 将信任策略中的服务主体改为区域化格式${data.aws_region.current.name}.scheduler.amazonaws.com,满足EventBridge Scheduler的角色信任要求
  • 在aws_scheduler_schedule中添加depends_on依赖,确保IAM角色的权限策略完全附着后再创建调度器,避免因资源创建时序问题导致权限未生效

内容的提问来源于stack exchange,提问作者Aleksandrs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 21:05:16