AWS RDS Custom Oracle实例创建失败:IAM权限问题求助
AWS RDS自定义Oracle实例创建失败:IAM权限缺失排查求助
尝试创建AWS RDS自定义Oracle DB实例时失败,控制台提示实例角色AWSRDSCustomInstanceRole-ap-southeast-1缺失多项IAM权限,但该角色已关联包含对应权限的AWSRDSCustomIamRolePolicyExample策略。
Terraform资源代码
resource "aws_rds_custom_db_engine_version" "ora19-std-cev" { database_installation_files_s3_bucket_name = aws_s3_bucket.cev_bucket.id database_installation_files_s3_prefix = "stdcev1/" engine = "custom-oracle-ee-cdb" engine_version = "19.example.cdb_cev1" kms_key_id = aws_kms_key.rds_custom_ora.arn manifest = <<JSON { "databaseInstallationFileNames":["V982063-01.zip"], "opatchFileNames":["p6880880_190000_Linux-x86-64.zip"], "psuRuPatchFileNames":["p32126828_190000_Linux-x86-64.zip"], "otherPatchFileNames":["p29213893_1910000DBRU_Generic.zip","p29782284_1910000DBRU_Generic.zip","p28730253_190000_Linux-x86-64.zip","p29374604_1910000DBRU_Linux-x86-64.zip","p28852325_190000_Linux-x86-64.zip","p29997937_190000_Linux-x86-64.zip","p31335037_190000_Linux-x86-64.zip","p31335142_190000_Generic.zip"] } JSON } data "aws_rds_orderable_db_instance" "custom-example-oracle" { engine = "custom-oracle-ee-cdb" # CEV engine to be used engine_version = "19.example.cdb_cev1" # CEV engine version to be used license_model = "bring-your-own-license" storage_type = "gp3" preferred_instance_classes = ["db.r5.xlarge", "db.r5.2xlarge", "db.r5.4xlarge"] depends_on = [ aws_rds_custom_db_engine_version.ora19-std-cev ] } resource "aws_db_instance_role_association" "db_inst_role_ora19inst-example" { db_instance_identifier = aws_db_instance.ora19inst-example.identifier feature_name = "ORA_EXAMPLE_S3_INTEGRATION" role_arn = aws_iam_role.rds_custom_role.arn } resource "aws_db_instance" "ora19inst-example" { allocated_storage = 500 auto_minor_version_upgrade = false # Custom for Oracle does not support minor version upgrades custom_iam_instance_profile = "AWSRDSCustomInstanceProfile-ap-southeast-1" # Instance profile is required for Custom for Oracle. See: https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/custom-setup-orcl.html#custom-setup-orcl.iam-vpc backup_retention_period = 7 db_subnet_group_name = "db-oracle-private" engine = data.aws_rds_orderable_db_instance.custom-example-oracle.engine engine_version = data.aws_rds_orderable_db_instance.custom-example-oracle.engine_version identifier = "ee-instance-test-example-1" instance_class = data.aws_rds_orderable_db_instance.custom-example-oracle.instance_class kms_key_id = aws_kms_key.rds_custom_ora.arn license_model = data.aws_rds_orderable_db_instance.custom-example-oracle.license_model multi_az = false # Custom for Oracle does not support multi-az password = "avoid-plaintext-passwords" username = "admin" storage_encrypted = true timeouts { create = "1h" delete = "3h" update = "3h" } } resource "aws_iam_instance_profile" "aws_rds_custom_instance_profile" { name = "AWSRDSCustomInstanceProfile-ap-southeast-1" role = aws_iam_role.rds_custom_role.name } data "aws_iam_policy_document" "assume_rds_role" { statement { effect = "Allow" principals { type = "Service" identifiers = ["ec2.amazonaws.com"] } actions = ["sts:AssumeRole"] } } resource "aws_iam_role" "rds_custom_role" { name = "AWSRDSCustomInstanceRole-ap-southeast-1" path = "/" assume_role_policy = data.aws_iam_policy_document.assume_rds_role.json } resource "aws_iam_role_policy_attachment" "rds-policy-attachment" { policy_arn = "arn:aws:iam::<removed>:policy/AWSRDSCustomIamRolePolicyExample" role = aws_iam_role.rds_custom_role.name }
AWSRDSCustomIamRolePolicyExample策略内容
{ "Statement": [ { "Action": [ "ssm:DescribeAssociation", "ssm:GetDeployablePatchSnapshotForInstance", "ssm:GetDocument", "ssm:DescribeDocument", "ssm:GetManifest", "ssm:GetParameter", "ssm:GetParameters", "ssm:ListAssociations", "ssm:ListInstanceAssociations", "ssm:PutInventory", "ssm:PutComplianceItems", "ssm:PutConfigurePackageResult", "ssm:UpdateAssociationStatus", "ssm:UpdateInstanceAssociationStatus", "ssm:UpdateInstanceInformation", "ssm:GetConnectionStatus", "ssm:DescribeInstanceInformation", "ssmmessages:CreateControlChannel", "ssmmessages:CreateDataChannel", "ssmmessages:OpenControlChannel", "ssmmessages:OpenDataChannel" ], "Effect": "Allow", "Resource": "*" }, { "Action": [ "ec2messages:AcknowledgeMessage", "ec2messages:DeleteMessage", "ec2messages:FailMessage", "ec2messages:GetEndpoint", "ec2messages:GetMessages", "ec2messages:SendReply" ], "Effect": "Allow", "Resource": "*" }, { "Action": [ "logs:PutRetentionPolicy", "logs:PutLogEvents", "logs:DescribeLogStreams", "logs:DescribeLogGroups", "logs:CreateLogStream", "logs:CreateLogGroup" ], "Effect": "Allow", "Resource": "arn:aws:logs:ap-southeast-1:<removed>:log-group:rds-custom-instance*" }, { "Action": [ "s3:putObject", "s3:getObject", "s3:getObjectVersion" ], "Effect": "Allow", "Resource": "arn:aws:s3:::do-not-delete-rds-custom-*/*" }, { "Action": "cloudwatch:PutMetricData", "Condition": { "StringEquals": { "cloudwatch:namespace": [ "RDSCustomForOracle/Agent" ] } }, "Effect": "Allow", "Resource": "*" }, { "Action": "events:PutEvents", "Effect": "Allow", "Resource": "*" }, { "Action": [ "secretsmanager:GetSecretValue", "secretsmanager:DescribeSecret" ], "Effect": "Allow", "Resource": "arn:aws:secretsmanager:ap-southeast-1:<removed>:secret:do-not-delete-rds-custom-*" }, { "Action": "s3:ListBucketVersions", "Effect": "Allow", "Resource": "arn:aws:s3:::do-not-delete-rds-custom-*" }, { "Action": [ "ec2:CreateSnapshots" ], "Condition": { "StringEquals": { "ec2:ResourceTag/AWSRDSCustom": "custom-oracle" } }, "Effect": "Allow", "Resource": [ "arn:aws:ec2:*:*:instance/*", "arn:aws:ec2:*:*:volume/*" ] }, { "Action": "ec2:CreateSnapshots", "Effect": "Allow", "Resource": "arn:aws:ec2:*::snapshot/*" }, { "Action": [ "kms:Decrypt", "kms:GenerateDataKey" ], "Effect": "Allow", "Resource": "arn:aws:kms:ap-southeast-1:<removed>:key/bfe45637-514d-4ec0-82cd-94cc3ebbdaca" }, { "Action": "ec2:CreateTags", "Condition": { "StringLike": { "ec2:CreateAction": [ "CreateSnapshots" ] } }, "Effect": "Allow", "Resource": "*" } ], "Version": "2012-10-17" }
报错信息
Terraform执行报错
│ Error: waiting for RDS DB Instance (ee-instance-test-example-1) create: unexpected state 'incompatible-create', wanted target 'available, storage-optimization'. last error: %!s(<nil>) │ │ with aws_db_instance.ora19inst-example, │ on oracle-rds.tf line 280, in resource "aws_db_instance" "ora19inst-example": │ 280: resource "aws_db_instance" "ora19inst-example" {
AWS控制台日志
You can't create the DB instance because of incompatible resources. The IAM instance profile role [AWSRDSCustomInstanceRole-ap-southeast-1] is missing the following permissions: EFFECT [Allow] on ACTION(S) [ssm:DescribeAssociation, ssm:DescribeDocument, ssm:GetConnectionStatus, ssm:GetDeployablePatchSnapshotForInstance, ssmmessages:OpenControlChannel, ssm:GetParameters, ssm:ListInstanceAssociations, ssm:PutConfigurePackageResult, ssmmessages:CreateControlChannel, ssm:GetParameter, ssm:UpdateAssociationStatus, ssm:GetManifest, ssmmessages:CreateDataChannel, ssm:PutInventory, ssm:UpdateInstanceInformation, ssm:DescribeInstanceInformation, ssmmessages:OpenDataChannel, ssm:GetDocument, ssm:ListAssociations, ssm:PutComplianceItems, ssm:UpdateInstanceAssociationStatus] for RESOURCE(S) [*], EFFECT [Allow] on ACTION(S) [ec2messages:DeleteMessage, ec2messages:FailMessage, ec2messages:GetEndpoint, ec2messages:AcknowledgeMessage, ec2messages:GetMessages, ec2messages:SendReply] for RESOURCE(S) [*], EFFECT [Allow] on ACTION(S) [logs:CreateLogStream, logs:DescribeLogStreams, logs:PutRetentionPolicy, logs:PutLogEvents, logs:CreateLogGroup] for RESOURCE(S) [arn:aws:logs:ap-southeast-1:<removed>:log-group:rds-custom-instance*], EFFECT [Allow] on ACTION(S) [s3:getObjectVersion, s3:getObject, s3:putObject] for RESOURCE(S) [arn:aws:s3:::do-not-delete-rds-custom-*/*], EFFECT [Allow] on ACTION(S) [cloudwatch:PutMetricData] for RESOURCE(S) [*] with CONDITION(S) [{Condition Key: [cloudwatch:namespace], Type: [StringEquals], Values: [RDSCustomForOracle/Agent]}], EFFECT [Allow] on ACTION(S) [events:PutEvents] for RESOURCE(S) [*], EFFECT [Allow] on ACTION(S) [secretsmanager:GetSecretValue, secretsmanager:DescribeSecret] for RESOURCE(S) [arn:aws:secretsmanager:ap-southeast-1:<removed>:secret:do-not-delete-rds-custom-*], EFFECT [Allow] on ACTION(S) [s3:ListBucketVersions] for RESOURCE(S) [arn:aws:s3:::do-not-delete-rds-custom-*], EFFECT [Allow] on ACTION(S) [ec2:CreateSnapshots] for RESOURCE(S) [arn:aws:ec2:*:*:instance/*, arn:aws:ec2:*:*:volume/*] with CONDITION(S) [{Condition Key: [ec2:ResourceTag/AWSRDSCustom], Type: [StringEquals], Values: [custom-oracle]}], EFFECT [Allow] on ACTION(S) [ec2:CreateSnapshots] for RESOURCE(S) [arn:aws:ec2:*::snapshot/*], EFFECT [Allow] on ACTION(S) [ec2:CreateTags] for RESOURCE(S) [*] with CONDITION(S) [{Condition Key: [ec2:CreateAction], Type: [StringLike], Values: [CreateSnapshots]}]
已验证信息
- 实例配置文件
AWSRDSCustomInstanceProfile-ap-southeast-1存在 - 角色
AWSRDSCustomInstanceRole-ap-southeast-1已附加AWSRDSCustomIamRolePolicyExample策略 - 角色无内联策略
排查建议
- 等待策略生效延迟:IAM策略附加后可能需要几分钟才能完全生效,等待10-15分钟后重新尝试创建实例
- 验证策略权限匹配:逐行对比报错要求的权限与策略中的权限,确认没有拼写错误(比如动作名称大小写、资源ARN中的账号ID是否替换正确)
- 检查角色信任关系:确认角色的信任策略允许
ec2.amazonaws.com扮演该角色(当前配置已设置,但可通过IAM控制台再次验证) - 检查权限边界与会话策略:如果角色设置了权限边界或会话策略,可能会限制附加策略的权限,需确保这些边界不会阻止所需权限
- 替换为托管策略测试:暂时将自定义策略替换为AWS托管策略
AWSRDSCustomInstanceRolePolicy,尝试创建实例,若成功则说明自定义策略存在问题 - 验证策略资源范围:确认策略中指定的资源ARN(如日志、S3桶、密钥等)与实际环境中的资源匹配,没有使用占位符(如
<removed>)未替换的情况
内容的提问来源于stack exchange,提问作者puolneaj
相关产品推荐
相关产品推荐

