CloudFormation部署报错:指定KMS密钥策略中的ARN无效
CloudFormation模板报错排查与修正
核心错误点及修复方案
1. KMS密钥策略ARN无效
- 问题:
CustomKMSKey的密钥策略中,Resource字段错误使用了别名名称(CustomKMSKeyName),且Principal中的账号ID未通过!Sub解析,导致ARN格式无效。KMS密钥的ARN需对应密钥本身ID,而非别名;同时未解析的${AWS::AccountId}会被当作字符串处理,无法生成合法ARN。 - 修复:
- 用
!GetAtt CustomKMSKey.Arn直接引用当前密钥的ARN,或简化为*(密钥策略默认绑定当前密钥,范围已限定); - 用
!Sub解析账号ID,生成合法的root用户ARN。
- 用
2. KMS别名属性颠倒
- 问题:
CustomKMSKeyAlias的AliasName和TargetKeyId属性完全搞反。AliasName需要是alias/xxx格式的别名字符串,TargetKeyId才是要绑定的KMS密钥ID。 - 修复:将
AliasName设为!Ref CustomKMSKeyName,TargetKeyId设为!Ref CustomKMSKey。
3. 未定义参数引用
- 问题:
AccountBudget资源中引用了Amount参数,但模板未声明该参数,会导致部署失败。 - 修复:新增
Amount参数定义。
修正后的完整模板
AWSTemplateFormatVersion: "2010-09-09" Transform: AWS::Serverless-2016-10-31 Description: Creates an AWS budget and SNS topic for alerts. Parameters: CustomKMSKeyName: Type: String Default: "alias/company-budget-sns-encryption-key" Amount: Type: String Description: Value for the budget amount Resources: AccountBudget: Type: AWS::SSM::Parameter Properties: Name: do_not_edit_account_budgets Type: String Value: !Ref Amount CustomKMSKey: Type: AWS::KMS::Key Properties: Description: Custom KMS key for Budget alert SNS encryption KeyPolicy: Version: "2012-10-17" Statement: - Effect: Allow Principal: AWS: !Sub "arn:aws:iam::${AWS::AccountId}:root" # 替换为精细权限避免Security Hub通配符告警 Action: - kms:Encrypt - kms:Decrypt - kms:DescribeKey - kms:GenerateDataKey* Resource: !GetAtt CustomKMSKey.Arn CustomKMSKeyAlias: Type: AWS::KMS::Alias Properties: AliasName: !Ref CustomKMSKeyName TargetKeyId: !Ref CustomKMSKey SolutionArchitectSubscription: DependsOn: BudgetTopic Type: AWS::SNS::Subscription Properties: Endpoint: "{{resolve:ssm:/dev/contact_solution_architect}}" Protocol: email TopicArn: !Ref BudgetTopic BudgetTopic: Type: AWS::SNS::Topic Properties: TopicName: budget-alerts KmsMasterKeyId: !Ref CustomKMSKey BudgetTopicPolicy: DependsOn: BudgetTopic Type: AWS::SNS::TopicPolicy Properties: PolicyDocument: Id: allowbudget Version: "2012-10-17" Statement: - Sid: budget-id Effect: Allow Principal: Service: budgets.amazonaws.com Action: sns:Publish Resource: !Ref BudgetTopic Topics: - !Ref BudgetTopic
额外优化(针对Security Hub告警)
将KMS密钥策略中的kms:*替换为SNS加密所需的最小权限集合(如上述模板中的Encrypt、Decrypt等),避免通配符操作触发Security Hub告警。
内容的提问来源于stack exchange,提问作者user12494839
相关产品推荐
相关产品推荐

