AWS Lambda执行Athena查询所需权限问题排查
问题分析与解决方案
你遇到的"table does not exist"错误并非真的表不存在,而是IAM权限配置存在两处关键缺失,导致Athena无法正常访问Glue元数据或S3数据源:
1. Glue资源ARN格式错误
现有策略中arn:*:glue:us-east-1:<account-id>:table/*的服务部分用了通配符*,不符合AWS ARN规范(ARN必须以arn:aws:开头),导致Glue表的读取权限未被正确授予,Athena无法获取表的元数据,从而抛出表不存在的错误。
2. 缺失S3桶列表权限
Athena访问S3中的数据源文件时,需要s3:ListBucket权限遍历桶内对象,现有策略仅配置了s3:GetObject、s3:PutObject和s3:GetBucketLocation,缺少该权限会导致Athena无法定位数据源文件,间接触发表不存在的错误。
修正后的IAM权限策略
将原有策略中的错误ARN修正,并添加s3:ListBucket权限,修正后的策略如下:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "s3:PutObject", "s3:GetObject", "s3:ListBucket", "athena:StartQueryExecution", "athena:GetQueryExecution", "athena:GetQueryResults", "s3:GetBucketLocation", "glue:GetDatabase", "glue:GetDatabases", "glue:GetTable", "glue:GetTables", "glue:GetPartition", "glue:GetPartitions" ], "Resource": [ "arn:aws:athena:us-east-1:<account-id>:workgroup/*", "arn:aws:s3:::pp-athena-result", "arn:aws:s3:::pp-athena-result/*", "arn:aws:s3:::prateek-glue-test", "arn:aws:s3:::prateek-glue-test/*", "arn:aws:glue:us-east-1:<account-id>:catalog", "arn:aws:glue:us-east-1:<account-id>:database/*", "arn:aws:glue:us-east-1:<account-id>:table/default/worldcities" ] } ] }
关键调整说明:
- 把错误的
arn:*:glue:...修正为arn:aws:glue:...,并将Glue表的资源范围缩小到具体的default/worldcities(遵循最小权限原则,也可保留table/*) - 添加
s3:ListBucket操作,确保Athena能遍历两个S3桶内的对象 - 移除冗余的
arn:aws:glue:...:catalog/*,catalog本身的权限已覆盖该范围
验证步骤
- 更新Lambda关联的IAM角色权限
- 重新执行Lambda函数中的Athena查询
- 确认"table does not exist"错误消失,查询正常返回结果
内容的提问来源于stack exchange,提问作者Prateek Pathak
相关产品推荐
相关产品推荐

