You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS RDS Custom Oracle实例创建失败:IAM权限问题求助

AWS RDS自定义Oracle实例创建失败:IAM权限缺失排查求助

尝试创建AWS RDS自定义Oracle DB实例时失败,控制台提示实例角色AWSRDSCustomInstanceRole-ap-southeast-1缺失多项IAM权限,但该角色已关联包含对应权限的AWSRDSCustomIamRolePolicyExample策略。

Terraform资源代码

resource "aws_rds_custom_db_engine_version" "ora19-std-cev" {
   database_installation_files_s3_bucket_name = aws_s3_bucket.cev_bucket.id
   database_installation_files_s3_prefix      = "stdcev1/"
   engine                                     = "custom-oracle-ee-cdb"
   engine_version                             = "19.example.cdb_cev1"
   kms_key_id                                 = aws_kms_key.rds_custom_ora.arn
   manifest                                   = <<JSON
   {  
     "databaseInstallationFileNames":["V982063-01.zip"],
     "opatchFileNames":["p6880880_190000_Linux-x86-64.zip"],
     "psuRuPatchFileNames":["p32126828_190000_Linux-x86-64.zip"],
     "otherPatchFileNames":["p29213893_1910000DBRU_Generic.zip","p29782284_1910000DBRU_Generic.zip","p28730253_190000_Linux-x86-64.zip","p29374604_1910000DBRU_Linux-x86-64.zip","p28852325_190000_Linux-x86-64.zip","p29997937_190000_Linux-x86-64.zip","p31335037_190000_Linux-x86-64.zip","p31335142_190000_Generic.zip"]
   }
   JSON
 }

data "aws_rds_orderable_db_instance" "custom-example-oracle" {
   engine                     = "custom-oracle-ee-cdb" # CEV engine to be used
   engine_version             = "19.example.cdb_cev1"      # CEV engine version to be used
   license_model              = "bring-your-own-license"
   storage_type               = "gp3"
   preferred_instance_classes = ["db.r5.xlarge", "db.r5.2xlarge", "db.r5.4xlarge"]
   depends_on = [
     aws_rds_custom_db_engine_version.ora19-std-cev
   ]
 }

 resource "aws_db_instance_role_association" "db_inst_role_ora19inst-example" {
  db_instance_identifier = aws_db_instance.ora19inst-example.identifier
  feature_name           = "ORA_EXAMPLE_S3_INTEGRATION"
  role_arn               = aws_iam_role.rds_custom_role.arn
}
 
resource "aws_db_instance" "ora19inst-example" {
  allocated_storage           = 500
  auto_minor_version_upgrade  = false  # Custom for Oracle does not support minor version upgrades
  custom_iam_instance_profile = "AWSRDSCustomInstanceProfile-ap-southeast-1" # Instance profile is required for Custom for Oracle. See: https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/custom-setup-orcl.html#custom-setup-orcl.iam-vpc
  backup_retention_period     = 7
  db_subnet_group_name        = "db-oracle-private"
  engine                      = data.aws_rds_orderable_db_instance.custom-example-oracle.engine
  engine_version              = data.aws_rds_orderable_db_instance.custom-example-oracle.engine_version
  identifier                  = "ee-instance-test-example-1"
  instance_class              = data.aws_rds_orderable_db_instance.custom-example-oracle.instance_class
  kms_key_id                  = aws_kms_key.rds_custom_ora.arn
  license_model               = data.aws_rds_orderable_db_instance.custom-example-oracle.license_model
  multi_az                    = false # Custom for Oracle does not support multi-az
  password                    = "avoid-plaintext-passwords"
  username                    = "admin"
  storage_encrypted           = true

  timeouts {
    create = "1h"
    delete = "3h"
    update = "3h"
  }
}

resource "aws_iam_instance_profile" "aws_rds_custom_instance_profile" {
  name = "AWSRDSCustomInstanceProfile-ap-southeast-1"
  role = aws_iam_role.rds_custom_role.name
}
 
data "aws_iam_policy_document" "assume_rds_role" {
  statement {
    effect = "Allow"
 
    principals {
      type        = "Service"
      identifiers = ["ec2.amazonaws.com"]
    }
 
    actions = ["sts:AssumeRole"]
  }
}

resource "aws_iam_role" "rds_custom_role" {
  name               = "AWSRDSCustomInstanceRole-ap-southeast-1"
  path               = "/"
  assume_role_policy = data.aws_iam_policy_document.assume_rds_role.json
}
 
resource "aws_iam_role_policy_attachment" "rds-policy-attachment" {
  policy_arn = "arn:aws:iam::<removed>:policy/AWSRDSCustomIamRolePolicyExample"
  role       = aws_iam_role.rds_custom_role.name
}

AWSRDSCustomIamRolePolicyExample策略内容

{
    "Statement": [
        {
            "Action": [
                "ssm:DescribeAssociation",
                "ssm:GetDeployablePatchSnapshotForInstance",
                "ssm:GetDocument",
                "ssm:DescribeDocument",
                "ssm:GetManifest",
                "ssm:GetParameter",
                "ssm:GetParameters",
                "ssm:ListAssociations",
                "ssm:ListInstanceAssociations",
                "ssm:PutInventory",
                "ssm:PutComplianceItems",
                "ssm:PutConfigurePackageResult",
                "ssm:UpdateAssociationStatus",
                "ssm:UpdateInstanceAssociationStatus",
                "ssm:UpdateInstanceInformation",
                "ssm:GetConnectionStatus",
                "ssm:DescribeInstanceInformation",
                "ssmmessages:CreateControlChannel",
                "ssmmessages:CreateDataChannel",
                "ssmmessages:OpenControlChannel",
                "ssmmessages:OpenDataChannel"
            ],
            "Effect": "Allow",
            "Resource": "*"
        },
        {
            "Action": [
                "ec2messages:AcknowledgeMessage",
                "ec2messages:DeleteMessage",
                "ec2messages:FailMessage",
                "ec2messages:GetEndpoint",
                "ec2messages:GetMessages",
                "ec2messages:SendReply"
            ],
            "Effect": "Allow",
            "Resource": "*"
        },
        {
            "Action": [
                "logs:PutRetentionPolicy",
                "logs:PutLogEvents",
                "logs:DescribeLogStreams",
                "logs:DescribeLogGroups",
                "logs:CreateLogStream",
                "logs:CreateLogGroup"
            ],
            "Effect": "Allow",
            "Resource": "arn:aws:logs:ap-southeast-1:<removed>:log-group:rds-custom-instance*"
        },
        {
            "Action": [
                "s3:putObject",
                "s3:getObject",
                "s3:getObjectVersion"
            ],
            "Effect": "Allow",
            "Resource": "arn:aws:s3:::do-not-delete-rds-custom-*/*"
        },
        {
            "Action": "cloudwatch:PutMetricData",
            "Condition": {
                "StringEquals": {
                    "cloudwatch:namespace": [
                        "RDSCustomForOracle/Agent"
                    ]
                }
            },
            "Effect": "Allow",
            "Resource": "*"
        },
        {
            "Action": "events:PutEvents",
            "Effect": "Allow",
            "Resource": "*"
        },
        {
            "Action": [
                "secretsmanager:GetSecretValue",
                "secretsmanager:DescribeSecret"
            ],
            "Effect": "Allow",
            "Resource": "arn:aws:secretsmanager:ap-southeast-1:<removed>:secret:do-not-delete-rds-custom-*"
        },
        {
            "Action": "s3:ListBucketVersions",
            "Effect": "Allow",
            "Resource": "arn:aws:s3:::do-not-delete-rds-custom-*"
        },
        {
            "Action": [
                "ec2:CreateSnapshots"
            ],
            "Condition": {
                "StringEquals": {
                    "ec2:ResourceTag/AWSRDSCustom": "custom-oracle"
                }
            },
            "Effect": "Allow",
            "Resource": [
                "arn:aws:ec2:*:*:instance/*",
                "arn:aws:ec2:*:*:volume/*"
            ]
        },
        {
            "Action": "ec2:CreateSnapshots",
            "Effect": "Allow",
            "Resource": "arn:aws:ec2:*::snapshot/*"
        },
        {
            "Action": [
                "kms:Decrypt",
                "kms:GenerateDataKey"
            ],
            "Effect": "Allow",
            "Resource": "arn:aws:kms:ap-southeast-1:<removed>:key/bfe45637-514d-4ec0-82cd-94cc3ebbdaca"
        },
        {
            "Action": "ec2:CreateTags",
            "Condition": {
                "StringLike": {
                    "ec2:CreateAction": [
                        "CreateSnapshots"
                    ]
                }
            },
            "Effect": "Allow",
            "Resource": "*"
        }
    ],
    "Version": "2012-10-17"
}

报错信息

Terraform执行报错

│ Error: waiting for RDS DB Instance (ee-instance-test-example-1) create: unexpected state 'incompatible-create', wanted target 'available, storage-optimization'. last error: %!s(<nil>)
│
│   with aws_db_instance.ora19inst-example,
│   on oracle-rds.tf line 280, in resource "aws_db_instance" "ora19inst-example":
│  280: resource "aws_db_instance" "ora19inst-example" {

AWS控制台日志

You can't create the DB instance because of incompatible resources. The IAM instance profile role [AWSRDSCustomInstanceRole-ap-southeast-1] is missing the following permissions: EFFECT [Allow] on ACTION(S) [ssm:DescribeAssociation, ssm:DescribeDocument, ssm:GetConnectionStatus, ssm:GetDeployablePatchSnapshotForInstance, ssmmessages:OpenControlChannel, ssm:GetParameters, ssm:ListInstanceAssociations, ssm:PutConfigurePackageResult, ssmmessages:CreateControlChannel, ssm:GetParameter, ssm:UpdateAssociationStatus, ssm:GetManifest, ssmmessages:CreateDataChannel, ssm:PutInventory, ssm:UpdateInstanceInformation, ssm:DescribeInstanceInformation, ssmmessages:OpenDataChannel, ssm:GetDocument, ssm:ListAssociations, ssm:PutComplianceItems, ssm:UpdateInstanceAssociationStatus] for RESOURCE(S) [*], EFFECT [Allow] on ACTION(S) [ec2messages:DeleteMessage, ec2messages:FailMessage, ec2messages:GetEndpoint, ec2messages:AcknowledgeMessage, ec2messages:GetMessages, ec2messages:SendReply] for RESOURCE(S) [*], EFFECT [Allow] on ACTION(S) [logs:CreateLogStream, logs:DescribeLogStreams, logs:PutRetentionPolicy, logs:PutLogEvents, logs:CreateLogGroup] for RESOURCE(S) [arn:aws:logs:ap-southeast-1:<removed>:log-group:rds-custom-instance*], EFFECT [Allow] on ACTION(S) [s3:getObjectVersion, s3:getObject, s3:putObject] for RESOURCE(S) [arn:aws:s3:::do-not-delete-rds-custom-*/*], EFFECT [Allow] on ACTION(S) [cloudwatch:PutMetricData] for RESOURCE(S) [*] with CONDITION(S) [{Condition Key: [cloudwatch:namespace], Type: [StringEquals], Values: [RDSCustomForOracle/Agent]}], EFFECT [Allow] on ACTION(S) [events:PutEvents] for RESOURCE(S) [*], EFFECT [Allow] on ACTION(S) [secretsmanager:GetSecretValue, secretsmanager:DescribeSecret] for RESOURCE(S) [arn:aws:secretsmanager:ap-southeast-1:<removed>:secret:do-not-delete-rds-custom-*], EFFECT [Allow] on ACTION(S) [s3:ListBucketVersions] for RESOURCE(S) [arn:aws:s3:::do-not-delete-rds-custom-*], EFFECT [Allow] on ACTION(S) [ec2:CreateSnapshots] for RESOURCE(S) [arn:aws:ec2:*:*:instance/*, arn:aws:ec2:*:*:volume/*] with CONDITION(S) [{Condition Key: [ec2:ResourceTag/AWSRDSCustom], Type: [StringEquals], Values: [custom-oracle]}], EFFECT [Allow] on ACTION(S) [ec2:CreateSnapshots] for RESOURCE(S) [arn:aws:ec2:*::snapshot/*], EFFECT [Allow] on ACTION(S) [ec2:CreateTags] for RESOURCE(S) [*] with CONDITION(S) [{Condition Key: [ec2:CreateAction], Type: [StringLike], Values: [CreateSnapshots]}]

已验证信息

  • 实例配置文件AWSRDSCustomInstanceProfile-ap-southeast-1存在
  • 角色AWSRDSCustomInstanceRole-ap-southeast-1已附加AWSRDSCustomIamRolePolicyExample策略
  • 角色无内联策略

排查建议

  • 等待策略生效延迟:IAM策略附加后可能需要几分钟才能完全生效,等待10-15分钟后重新尝试创建实例
  • 验证策略权限匹配:逐行对比报错要求的权限与策略中的权限,确认没有拼写错误(比如动作名称大小写、资源ARN中的账号ID是否替换正确)
  • 检查角色信任关系:确认角色的信任策略允许ec2.amazonaws.com扮演该角色(当前配置已设置,但可通过IAM控制台再次验证)
  • 检查权限边界与会话策略:如果角色设置了权限边界或会话策略,可能会限制附加策略的权限,需确保这些边界不会阻止所需权限
  • 替换为托管策略测试:暂时将自定义策略替换为AWS托管策略AWSRDSCustomInstanceRolePolicy,尝试创建实例,若成功则说明自定义策略存在问题
  • 验证策略资源范围:确认策略中指定的资源ARN(如日志、S3桶、密钥等)与实际环境中的资源匹配,没有使用占位符(如<removed>)未替换的情况

内容的提问来源于stack exchange,提问作者puolneaj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 10:47:03