You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用CloudFormation创建ECS Service时遇权限问题求助

问题

我正尝试通过CloudFormation JSON创建ECS服务,当前使用LambdaBrownlowRole角色兼顾多种用途,后续会拆分。以下是该角色的配置代码:

"LambdaBrownlowRole": {
      "Type": "AWS::IAM::Role",
      "Properties": {
        "RoleName": "LambdaBrownlowRole",
        "AssumeRolePolicyDocument": {
          "Version": "2012-10-17",
          "Statement": [
            {
              "Effect": "Allow",
              "Principal": {
                "Service": [
                  "lambda.amazonaws.com",
                  "events.amazonaws.com",
                  "ecs-tasks.amazonaws.com",
                  "ecs.amazonaws.com"
                ]
              },
              "Action": "sts:AssumeRole"
            }
          ]
        },
        "Policies": [
          {
            "PolicyName": "LambdaBrownlowPolicy",
            "PolicyDocument": {
              "Version": "2012-10-17",
              "Statement": [
                {
                  "Effect": "Allow",
                  "Action": [
                    "s3:GetObject",
                    "s3:PutObject",
                    "s3:ListBucket",
                    "s3:DeleteObject"
                  ],
                  "Resource": [
                    "arn:aws:s3:::afl-game-data/*",
                    "arn:aws:s3:::afl-game-data"
                  ]
                },
                {
                  "Effect": "Allow",
                  "Action": [
                    "dynamodb:PutItem",
                    "dynamodb:GetItem",
                    "dynamodb:Query",
                    "dynamodb:UpdateItem",
                    "dynamodb:Scan",
                    "dynamodb:BatchWriteItem",
                    "dynamodb:BatchGetItem"
                  ],
                  "Resource": "*"
                },
                {
                  "Effect": "Allow",
                  "Action": [
                    "logs:CreateLogGroup",
                    "logs:CreateLogStream",
                    "logs:PutLogEvents",
                    "logs:DescribeLogStreams"
                  ],
                  "Resource": "*"
                },
                {
                  "Effect": "Allow",
                  "Action": [
                    "ecs:CreateService",
                    "ecs:DescribeServices",
                    "ecs:UpdateService"
                  ],
                  "Resource": "*"
                }
              ]
            }
          }
        ]
      }
    },

以下是相关资源的JSON片段:

"ECSBrownlowTaskDefinition": {
      "Type": "AWS::ECS::TaskDefinition",
      "Properties": {
        "Family": "afl-brownlow-scrape",
        "ExecutionRoleArn": {
          "Fn::GetAtt": [
            "LambdaBrownlowRole",
            "Arn"
          ]
        },
        "Memory": "512",
        "Cpu": "256",
        "TaskRoleArn": {
          "Fn::GetAtt": [
            "LambdaBrownlowRole",
            "Arn"
          ]
        },
        "RequiresCompatibilities": [
          "FARGATE"
        ],
        "NetworkMode": "awsvpc",
        "ContainerDefinitions": [
          {
            "Name": "BrownlowScrape",
            "Image": {
              "Ref": "ECRRepositoryUriParameter"
            },
            "Essential": true,
            "Environment": [
              {
                "Name": "YEAR_TO_QUERY",
                "Value": {
                  "Ref": "YearToQueryParameter"
                }
              },
              {
                "Name": "BUCKET_NAME",
                "Value": {
                  "Ref": "BucketNameParameter"
                }
              },
              {
                "Name": "DATA_PATH",
                "Value": {
                  "Ref": "DataPathParameter"
                }
              }
            ],
            "LogConfiguration": {
              "LogDriver": "awslogs",
              "Options": {
                "awslogs-group": {
                  "Ref": "AFLScrapeLogGroup"
                },
                "awslogs-region": {
                  "Ref": "AWS::Region"
                },
                "awslogs-stream-prefix": "ecs"
              }
            }
          }
        ]
      }
    },
    "AFLScrapeLogGroup": {
      "Type": "AWS::Logs::LogGroup",
      "Properties": {
        "LogGroupName": "/ecs/afl-brownlow-scrape"
      }
    },
    "ECSServiceScrapeAFL": {
      "Type": "AWS::ECS::Service",
      "Properties": {
        "Cluster": "afl-brownlow-cluster",
        "ServiceName": "ServiceECSBrownlow",
        "TaskDefinition": {
          "Ref": "ECSBrownlowTaskDefinition"
        },
        "LaunchType": "FARGATE",
        "DesiredCount": 0,
        "Role": {
          "Fn::GetAtt": ["LambdaBrownlowRole", "Arn"]
        }
      }
    },
    "ECSScrapeScheduledRule": {
      "Type": "AWS::Events::Rule",
      "Properties": {
        "Name": "ecs-brownlow-scrape-weekly",
        "Description": "Scheduled rule for ECS brownlow-scrape",
        "RoleArn": {
          "Fn::GetAtt": [
            "LambdaExecutionRole",
            "Arn"
          ]
        },
        "ScheduleExpression": "cron(0/10 * ? * * *)",
        "State": "ENABLED",
        "Targets": [
          {
            "Arn": {
              "Fn::GetAtt": [
                "ECSServiceScrapeAFL",
                "Arn"
              ]
            },
            "Id": "ecs-brownlow-scrape",
            "EcsParameters": {
              "TaskDefinitionArn": {
                "Ref": "ECSBrownlowTaskDefinition"
              },
              "TaskCount": 1,
              "LaunchType": "FARGATE"
            }
          }
        ]
      }
    }

创建ECSServiceScrapeAFL时收到错误:

Resource handler returned message: "Invalid request provided: CreateService error: Access denied (Service: AmazonECS; Status Code: 400; Error Code: AccessDeniedException; Request ID: XXX; Proxy: null)" (RequestToken: XXX, HandlerErrorCode: InvalidRequest)

请问缺少什么配置或权限?

解决方案

这个错误源于多方面的权限缺失,具体修正点如下:

1. 部署CloudFormation的IAM实体权限不足

执行CloudFormation部署的IAM用户/角色需要拥有调用ECS CreateService的权限,需添加以下权限策略:

{
  "Effect": "Allow",
  "Action": "ecs:CreateService",
  "Resource": "arn:aws:ecs:<你的AWS区域>:<你的AWS账户ID>:service/afl-brownlow-cluster/ServiceECSBrownlow"
}

测试阶段可将Resource设为*以简化配置,生产环境建议限定具体资源。

2. ECS服务角色需补充基础描述权限

ECS服务角色(LambdaBrownlowRole)使用Fargate启动类型时,需要权限查询VPC、子网、安全组等基础资源信息,需在LambdaBrownlowPolicy中添加:

{
  "Effect": "Allow",
  "Action": [
    "ec2:DescribeSubnets",
    "ec2:DescribeSecurityGroups",
    "ec2:DescribeVpcs",
    "elasticloadbalancing:DescribeLoadBalancers",
    "elasticloadbalancing:DescribeTargetGroups"
  ],
  "Resource": "*"
}

3. 任务执行角色需添加ECR镜像拉取权限

ECSBrownlowTaskDefinition的ExecutionRoleArn需要拉取ECR镜像的权限,当前LambdaBrownlowRole缺少这部分权限,需补充:

{
  "Effect": "Allow",
  "Action": [
    "ecr:GetDownloadUrlForLayer",
    "ecr:BatchGetImage",
    "ecr:BatchCheckLayerAvailability",
    "ecr:GetAuthorizationToken"
  ],
  "Resource": "*"
}

4. 检查ECS服务角色的信任策略

确认LambdaBrownlowRole的信任策略中包含ecs.amazonaws.com服务主体,当前配置已满足,但需确保无额外条件限制该服务角色的扮演权限。

内容的提问来源于stack exchange,提问作者Harry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 21:55:54