创建向量索引及配置AOSS权限策略遇故障求助
问题:向量索引创建失败与权限策略JSON无效
遇到的两个问题
- 创建向量索引时触发**"Failed to fetch"**错误
- 仅扩充权限列表后,添加策略时提示Policy JSON无效
我的Policy代码
[ { "Rules": [ { "Resource": [ "collection/easy-vector-search-collection" ], "Permission": [ "aoss:CreateCollectionItems", "aoss:DeleteCollectionItems", "aoss:UpdateCollectionItems", "aoss:DescribeCollectionItems", "aoss:CreateIndex", "aoss:DeleteIndex", "aoss:UpdateIndex", "aoss:DescribeIndex", "aoss:ReadDocument", "aoss:WriteDocument" ], "ResourceType": "collection" } ], "Principal": [ "arn:aws:iam::example_id:user/example_user" ], "Description": "Rule 1" } ]
错误信息(中文翻译)
Policy JSON无效,错误详情: [$[0].Rules[0].Permission[4]: 不在枚举值列表[aoss:CreateCollectionItems, aoss:DeleteCollectionItems, aoss:UpdateCollectionItems, aoss:DescribeCollectionItems, aoss:*]中, $[0].Rules[0].Resource[1]: 不匹配正则模式^index/(?:[a-z][a-z0-9-]{2,31}\*?|\*)/([a-z;0-9&$%][+.\-_a-z;0-9&$%]*\*?|\*)$, $[0].Rules[0].Permission[2]: 不在枚举值列表[aoss:ReadDocument, aoss:WriteDocument, aoss:CreateIndex, aoss:DeleteIndex, aoss:UpdateIndex, aoss:DescribeIndex, aoss:*]中, $[0].Rules[0].ResourceType: 必须为固定值index, $[0].Rules[0].Permission[0]: 不在枚举值列表[aoss:ReadDocument, aoss:WriteDocument, aoss:CreateIndex, aoss:DeleteIndex, aoss:UpdateIndex, aoss:DescribeIndex, aoss:*]中, $[0].Rules[0].Resource[2]: 不匹配正则模式^index/(?:[a-z][a-z0-9-]{2,31}\*?|\*)/([a-z;0-9&$%][+.\-_a-z;0-9&$%]*\*?|\*)$, $[0].Rules[0].Resource[0]: 不匹配正则模式^index/(?:[a-z][a-z0-9-]{2,31}\*?|\*)/([a-z;0-9&$%][+.\-_a-z;0-9&$%]*\*?|\*)$, $[0].Rules[0].Permission[3]: 不在枚举值列表[aoss:ReadDocument, aoss:WriteDocument, aoss:CreateIndex, aoss:DeleteIndex, aoss:UpdateIndex, aoss:DescribeIndex, aoss:*]中, $[0].Rules[0].Permission[1]: 不在枚举值列表[aoss:ReadDocument, aoss:WriteDocument, aoss:CreateIndex, aoss:DeleteIndex, aoss:UpdateIndex, aoss:DescribeIndex, aoss:*]中, $[0].Rules[0].Resource[3]: 不匹配正则模式^index/(?:[a-z][a-z0-9-]{2,31}\*?|\*)/([a-z;0-9&$%][+.\-_a-z;0-9&$%]*\*?|\*)$]
问题解决方法
1. 修正权限策略JSON
错误信息明确指出核心问题:同一个规则不能混合集合(collection)和索引(index)的权限与资源类型,必须拆分规则并匹配对应权限枚举:
修正后的Policy代码
[ { "Rules": [ // 集合资源对应的权限规则 { "Resource": [ "collection/easy-vector-search-collection" ], "Permission": [ "aoss:CreateCollectionItems", "aoss:DeleteCollectionItems", "aoss:UpdateCollectionItems", "aoss:DescribeCollectionItems" ], "ResourceType": "collection" }, // 索引资源对应的权限规则 { "Resource": [ "index/easy-vector-search-collection/your-index-name" // 替换为实际索引名称 ], "Permission": [ "aoss:CreateIndex", "aoss:DeleteIndex", "aoss:UpdateIndex", "aoss:DescribeIndex", "aoss:ReadDocument", "aoss:WriteDocument" ], "ResourceType": "index" } ], "Principal": [ "arn:aws:iam::example_id:user/example_user" ], "Description": "Collection and Index Permissions" } ]
修正要点
- 拆分规则:分别为
collection和index类型创建独立规则,每个规则的ResourceType与权限、资源格式严格匹配 - 权限匹配:集合规则仅使用集合类权限,索引规则仅使用索引类权限,禁止交叉混用
- 资源格式:索引资源必须遵循
index/[集合名称]/[索引名称]的格式,替换代码中的your-index-name为实际索引名
2. "Failed to fetch"错误排查
该错误多与权限、网络或服务状态相关,按以下步骤排查:
- 确认修正后的Policy已成功应用,当前IAM用户拥有
aoss:CreateIndex权限 - 检查网络连接,确保能正常访问向量搜索服务的API端点
- 验证目标集合
easy-vector-search-collection已创建且状态正常 - 查看服务端日志或控制台,获取更详细的错误原因(如集合不存在、索引参数错误等)
内容的提问来源于stack exchange,提问作者Caroline Cah
相关产品推荐
相关产品推荐

