EMR Studio笔记本对接EMR Serverless内核选择报错排查
EMR Studio搭配EMR Serverless选择内核报错排查
问题详情
尝试用EMR Studio工作区(笔记本)对接EMR Serverless应用,选择python3等内核时触发报错。以root用户身份查阅了所有官方文档中的策略和信任策略说明,仍未找到问题根源。
报错截图

角色信任策略
{"Version": "2012-10-17","Statement": [{"Effect": "Allow","Principal": {"Service": "elasticmapreduce.amazonaws.com"},"Action": "sts:AssumeRole","Condition": {"StringEquals": {"aws:SourceAccount": "123"},"ArnLike": {"aws:SourceArn": "arn:aws:elasticmapreduce:us-east-2:123:*"}}},{"Effect": "Allow","Principal": {"Service": "emr-serverless.amazonaws.com"},"Action": ["sts:AssumeRole","sts:SetContext"]}]}
角色关联策略
{"Version": "2012-10-17","Statement": [{"Sid": "EMRServerlessInteractiveAccess","Effect": "Allow","Action": "emr-serverless:AccessInteractiveEndpoints","Resource": "arn:aws:emr-serverless:us-east-2:123:/applications/*"},{"Sid": "ReadAccessForEMRSamples","Effect": "Allow","Action": ["s3:GetObject","s3:ListBucket"],"Resource": ["arn:aws:s3:::*.elasticmapreduce","arn:aws:s3:::*.elasticmapreduce/*"]},{"Sid": "EMRServerlessRuntimeRoleAccess","Effect": "Allow","Action": "iam:PassRole","Resource": "*"},{"Sid": "FullAccessToOutputBucket","Effect": "Allow","Action": ["s3:PutObject","s3:GetObject","s3:GetEncryptionConfiguration","s3:ListBucket","s3:DeleteObject"],"Resource": ["arn:aws:s3:::s3bu","arn:aws:s3:::s3bu/*"]},{"Sid": "GlueCreateAndReadDataCatalog","Effect": "Allow","Action": ["glue:GetDatabase","glue:CreateDatabase","glue:GetDataBases","glue:CreateTable","glue:GetTable","glue:UpdateTable","glue:DeleteTable","glue:GetTables","glue:GetPartition","glue:GetPartitions","glue:CreatePartition","glue:BatchCreatePartition","glue:GetUserDefinedFunctions"],"Resource": ["*"]},{"Sid": "AllowEMRReadOnlyActions","Effect": "Allow","Action": ["elasticmapreduce:ListInstances","elasticmapreduce:DescribeCluster","elasticmapreduce:ListSteps"],"Resource": "*"},{"Sid": "AllowEC2ENIActionsWithEMRTags","Effect": "Allow","Action": ["ec2:CreateNetworkInterfacePermission","ec2:DeleteNetworkInterface"],"Resource": ["arn:aws:ec2:*:*:network-interface/*"],"Condition": {"StringEquals": {"aws:ResourceTag/for-use-with-amazon-emr-managed-policies": "true"}}},{"Sid": "AllowEC2ENIAttributeAction","Effect": "Allow","Action": ["ec2:ModifyNetworkInterfaceAttribute"],"Resource": ["arn:aws:ec2:*:*:instance/*","arn:aws:ec2:*:*:network-interface/*","arn:aws:ec2:*:*:security-group/*"]},{"Sid": "AllowEC2SecurityGroupActionsWithEMRTags","Effect": "Allow","Action": ["ec2:AuthorizeSecurityGroupEgress","ec2:AuthorizeSecurityGroupIngress","ec2:RevokeSecurityGroupEgress","ec2:RevokeSecurityGroupIngress","ec2:DeleteNetworkInterfacePermission"],"Resource": "*","Condition": {"StringEquals": {"aws:ResourceTag/for-use-with-amazon-emr-managed-policies": "true"}}},{"Sid": "AllowDefaultEC2SecurityGroupsCreationWithEMRTags","Effect": "Allow","Action": ["ec2:CreateSecurityGroup"],"Resource": ["arn:aws:ec2:*:*:security-group/*"],"Condition": {"StringEquals": {"aws:RequestTag/for-use-with-amazon-emr-managed-policies": "true"}}},{"Sid": "AllowDefaultEC2SecurityGroupsCreationInVPCWithEMRTags","Effect": "Allow","Action": ["ec2:CreateSecurityGroup"],"Resource": ["arn:aws:ec2:*:*:vpc/*"],"Condition": {"StringEquals": {"aws:ResourceTag/for-use-with-amazon-emr-managed-policies": "true"}}},{"Sid": "AllowAddingEMRTagsDuringDefaultSecurityGroupCreation","Effect": "Allow","Action": ["ec2:CreateTags"],"Resource": "arn:aws:ec2:*:*:security-group/*","Condition": {"StringEquals": {"aws:RequestTag/for-use-with-amazon-emr-managed-policies": "true","ec2:CreateAction": "CreateSecurityGroup"}}},{"Sid": "AllowEC2ENICreationWithEMRTags","Effect": "Allow","Action": ["ec2:CreateNetworkInterface"],"Resource": ["arn:aws:ec2:*:*:network-interface/*"],"Condition": {"StringEquals": {"aws:RequestTag/for-use-with-amazon-emr-managed-policies": "true"}}},{"Sid": "AllowEC2ENICreationInSubnetAndSecurityGroupWithEMRTags","Effect": "Allow","Action": ["ec2:CreateNetworkInterface"],"Resource": ["arn:aws:ec2:*:*:subnet/*","arn:aws:ec2:*:*:security-group/*"],"Condition": {"StringEquals": {"aws:ResourceTag/for-use-with-amazon-emr-managed-policies": "true"}}},{"Sid": "AllowAddingTagsDuringEC2ENICreation","Effect": "Allow","Action": ["ec2:CreateTags"],"Resource": "arn:aws:ec2:*:*:network-interface/*","Condition": {"StringEquals": {"ec2:CreateAction": "CreateNetworkInterface"}}},{"Sid": "AllowEC2ReadOnlyActions","Effect": "Allow","Action": ["ec2:DescribeSecurityGroups","ec2:DescribeNetworkInterfaces","ec2:DescribeTags","ec2:DescribeInstances","ec2:DescribeSubnets","ec2:DescribeVpcs"],"Resource": "*"},{"Sid": "AllowSecretsManagerReadOnlyActionsWithEMRTags","Effect": "Allow","Action": ["secretsmanager:GetSecretValue"],"Resource": "arn:aws:secretsmanager:*:*:secret:*","Condition": {"StringEquals": {"aws:ResourceTag/for-use-with-amazon-emr-managed-policies": "true"}}},{"Sid": "AllowWorkspaceCollaboration","Effect": "Allow","Action": ["iam:GetUser","iam:GetRole","iam:ListUsers","iam:ListRoles","sso:GetManagedApplicationInstance","sso-directory:SearchUsers"],"Resource": "*"}]}
排查方向
- 核对EMR Serverless应用的运行时角色:确保该角色具备S3读写、Glue数据目录访问等基础权限,且信任策略允许
emr-serverless.amazonaws.com扮演。 - 验证信任策略中的账号ID和ARN:确认
aws:SourceAccount是当前AWS账号的真实ID,aws:SourceArn的区域、账号ID与实际EMR Studio工作区完全匹配。 - 检查区域一致性:EMR Studio工作区和EMR Serverless应用必须处于同一区域(当前配置为us-east-2),跨区域会导致权限验证失败。
- 查看CloudTrail日志:搜索
emr-serverless:StartSession或elasticmapreduce:CreateEditor相关事件,通过日志中的具体拒绝信息定位问题。 - 确认EMR Serverless应用状态:应用需处于已启动状态,未启动的应用无法创建内核会话。
内容的提问来源于stack exchange,提问作者jagrat
相关产品推荐
相关产品推荐

