You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudFormation部署报错:指定KMS密钥策略中的ARN无效

CloudFormation模板报错排查与修正

核心错误点及修复方案


1. KMS密钥策略ARN无效

  • 问题:CustomKMSKey的密钥策略中,Resource字段错误使用了别名名称(CustomKMSKeyName),且Principal中的账号ID未通过!Sub解析,导致ARN格式无效。KMS密钥的ARN需对应密钥本身ID,而非别名;同时未解析的${AWS::AccountId}会被当作字符串处理,无法生成合法ARN。
  • 修复:
    • 用!GetAtt CustomKMSKey.Arn直接引用当前密钥的ARN,或简化为*(密钥策略默认绑定当前密钥,范围已限定);
    • 用!Sub解析账号ID,生成合法的root用户ARN。

2. KMS别名属性颠倒

  • 问题:CustomKMSKeyAlias的AliasName和TargetKeyId属性完全搞反。AliasName需要是alias/xxx格式的别名字符串,TargetKeyId才是要绑定的KMS密钥ID。
  • 修复:将AliasName设为!Ref CustomKMSKeyName,TargetKeyId设为!Ref CustomKMSKey。

3. 未定义参数引用

  • 问题:AccountBudget资源中引用了Amount参数,但模板未声明该参数,会导致部署失败。
  • 修复:新增Amount参数定义。

修正后的完整模板

AWSTemplateFormatVersion: "2010-09-09"
Transform: AWS::Serverless-2016-10-31
Description: Creates an AWS budget and SNS topic for alerts.

Parameters:
  CustomKMSKeyName:
    Type: String
    Default: "alias/company-budget-sns-encryption-key"
  Amount:
    Type: String
    Description: Value for the budget amount

Resources:
  AccountBudget:
    Type: AWS::SSM::Parameter
    Properties:
      Name: do_not_edit_account_budgets
      Type: String
      Value: !Ref Amount

  CustomKMSKey:
    Type: AWS::KMS::Key
    Properties:
      Description: Custom KMS key for Budget alert SNS encryption
      KeyPolicy:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Principal:
              AWS: !Sub "arn:aws:iam::${AWS::AccountId}:root"
            # 替换为精细权限避免Security Hub通配符告警
            Action:
              - kms:Encrypt
              - kms:Decrypt
              - kms:DescribeKey
              - kms:GenerateDataKey*
            Resource: !GetAtt CustomKMSKey.Arn

  CustomKMSKeyAlias:
    Type: AWS::KMS::Alias
    Properties:
      AliasName: !Ref CustomKMSKeyName
      TargetKeyId: !Ref CustomKMSKey

  SolutionArchitectSubscription:
    DependsOn: BudgetTopic
    Type: AWS::SNS::Subscription
    Properties:
      Endpoint: "{{resolve:ssm:/dev/contact_solution_architect}}"
      Protocol: email
      TopicArn: !Ref BudgetTopic

  BudgetTopic:
    Type: AWS::SNS::Topic
    Properties:
      TopicName: budget-alerts
      KmsMasterKeyId: !Ref CustomKMSKey

  BudgetTopicPolicy:
    DependsOn: BudgetTopic
    Type: AWS::SNS::TopicPolicy
    Properties:
      PolicyDocument:
        Id: allowbudget
        Version: "2012-10-17"
        Statement:
          - Sid: budget-id
            Effect: Allow
            Principal:
              Service: budgets.amazonaws.com
            Action: sns:Publish
            Resource: !Ref BudgetTopic
      Topics:
        - !Ref BudgetTopic

额外优化(针对Security Hub告警)

将KMS密钥策略中的kms:*替换为SNS加密所需的最小权限集合(如上述模板中的Encrypt、Decrypt等),避免通配符操作触发Security Hub告警。

内容的提问来源于stack exchange,提问作者user12494839

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 11:24:54