使用CloudFormation创建ECS Service时遇权限问题求助
我正尝试通过CloudFormation JSON创建ECS服务,当前使用LambdaBrownlowRole角色兼顾多种用途,后续会拆分。以下是该角色的配置代码:
"LambdaBrownlowRole": { "Type": "AWS::IAM::Role", "Properties": { "RoleName": "LambdaBrownlowRole", "AssumeRolePolicyDocument": { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": [ "lambda.amazonaws.com", "events.amazonaws.com", "ecs-tasks.amazonaws.com", "ecs.amazonaws.com" ] }, "Action": "sts:AssumeRole" } ] }, "Policies": [ { "PolicyName": "LambdaBrownlowPolicy", "PolicyDocument": { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject", "s3:ListBucket", "s3:DeleteObject" ], "Resource": [ "arn:aws:s3:::afl-game-data/*", "arn:aws:s3:::afl-game-data" ] }, { "Effect": "Allow", "Action": [ "dynamodb:PutItem", "dynamodb:GetItem", "dynamodb:Query", "dynamodb:UpdateItem", "dynamodb:Scan", "dynamodb:BatchWriteItem", "dynamodb:BatchGetItem" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "logs:CreateLogGroup", "logs:CreateLogStream", "logs:PutLogEvents", "logs:DescribeLogStreams" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "ecs:CreateService", "ecs:DescribeServices", "ecs:UpdateService" ], "Resource": "*" } ] } } ] } },
以下是相关资源的JSON片段:
"ECSBrownlowTaskDefinition": { "Type": "AWS::ECS::TaskDefinition", "Properties": { "Family": "afl-brownlow-scrape", "ExecutionRoleArn": { "Fn::GetAtt": [ "LambdaBrownlowRole", "Arn" ] }, "Memory": "512", "Cpu": "256", "TaskRoleArn": { "Fn::GetAtt": [ "LambdaBrownlowRole", "Arn" ] }, "RequiresCompatibilities": [ "FARGATE" ], "NetworkMode": "awsvpc", "ContainerDefinitions": [ { "Name": "BrownlowScrape", "Image": { "Ref": "ECRRepositoryUriParameter" }, "Essential": true, "Environment": [ { "Name": "YEAR_TO_QUERY", "Value": { "Ref": "YearToQueryParameter" } }, { "Name": "BUCKET_NAME", "Value": { "Ref": "BucketNameParameter" } }, { "Name": "DATA_PATH", "Value": { "Ref": "DataPathParameter" } } ], "LogConfiguration": { "LogDriver": "awslogs", "Options": { "awslogs-group": { "Ref": "AFLScrapeLogGroup" }, "awslogs-region": { "Ref": "AWS::Region" }, "awslogs-stream-prefix": "ecs" } } } ] } }, "AFLScrapeLogGroup": { "Type": "AWS::Logs::LogGroup", "Properties": { "LogGroupName": "/ecs/afl-brownlow-scrape" } }, "ECSServiceScrapeAFL": { "Type": "AWS::ECS::Service", "Properties": { "Cluster": "afl-brownlow-cluster", "ServiceName": "ServiceECSBrownlow", "TaskDefinition": { "Ref": "ECSBrownlowTaskDefinition" }, "LaunchType": "FARGATE", "DesiredCount": 0, "Role": { "Fn::GetAtt": ["LambdaBrownlowRole", "Arn"] } } }, "ECSScrapeScheduledRule": { "Type": "AWS::Events::Rule", "Properties": { "Name": "ecs-brownlow-scrape-weekly", "Description": "Scheduled rule for ECS brownlow-scrape", "RoleArn": { "Fn::GetAtt": [ "LambdaExecutionRole", "Arn" ] }, "ScheduleExpression": "cron(0/10 * ? * * *)", "State": "ENABLED", "Targets": [ { "Arn": { "Fn::GetAtt": [ "ECSServiceScrapeAFL", "Arn" ] }, "Id": "ecs-brownlow-scrape", "EcsParameters": { "TaskDefinitionArn": { "Ref": "ECSBrownlowTaskDefinition" }, "TaskCount": 1, "LaunchType": "FARGATE" } } ] } }
创建ECSServiceScrapeAFL时收到错误:
Resource handler returned message: "Invalid request provided: CreateService error: Access denied (Service: AmazonECS; Status Code: 400; Error Code: AccessDeniedException; Request ID: XXX; Proxy: null)" (RequestToken: XXX, HandlerErrorCode: InvalidRequest)
请问缺少什么配置或权限?
这个错误源于多方面的权限缺失,具体修正点如下:
1. 部署CloudFormation的IAM实体权限不足
执行CloudFormation部署的IAM用户/角色需要拥有调用ECS CreateService的权限,需添加以下权限策略:
{ "Effect": "Allow", "Action": "ecs:CreateService", "Resource": "arn:aws:ecs:<你的AWS区域>:<你的AWS账户ID>:service/afl-brownlow-cluster/ServiceECSBrownlow" }
测试阶段可将Resource设为*以简化配置,生产环境建议限定具体资源。
2. ECS服务角色需补充基础描述权限
ECS服务角色(LambdaBrownlowRole)使用Fargate启动类型时,需要权限查询VPC、子网、安全组等基础资源信息,需在LambdaBrownlowPolicy中添加:
{ "Effect": "Allow", "Action": [ "ec2:DescribeSubnets", "ec2:DescribeSecurityGroups", "ec2:DescribeVpcs", "elasticloadbalancing:DescribeLoadBalancers", "elasticloadbalancing:DescribeTargetGroups" ], "Resource": "*" }
3. 任务执行角色需添加ECR镜像拉取权限
ECSBrownlowTaskDefinition的ExecutionRoleArn需要拉取ECR镜像的权限,当前LambdaBrownlowRole缺少这部分权限,需补充:
{ "Effect": "Allow", "Action": [ "ecr:GetDownloadUrlForLayer", "ecr:BatchGetImage", "ecr:BatchCheckLayerAvailability", "ecr:GetAuthorizationToken" ], "Resource": "*" }
4. 检查ECS服务角色的信任策略
确认LambdaBrownlowRole的信任策略中包含ecs.amazonaws.com服务主体,当前配置已满足,但需确保无额外条件限制该服务角色的扮演权限。
内容的提问来源于stack exchange,提问作者Harry

