You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决Step Functions状态机无权限创建managed-rule的问题?

问题:自定义IAM角色创建AWS Step Function时提示无权创建managed-rule

错误信息

Error: creating Step Functions State Machine (<step func name>): AccessDeniedException: '<step func arn>' is not authorized to create managed-rule.

我的配置

我使用内部Terraform模块创建Step Function,指定自定义IAM角色而非模块自动生成角色,核心配置如下:

Step Function模块代码

module "step-function-crawler-execution" {
  source = "git@github.com:Schroders-Personal-Wealth/terraform-shared-library.git//services/step-functions?ref=steps-func-0.1.0"

  name       = local.state_machine_def.crawler_wrapper.name
  type       = var.stepfunc_type
  definition = jsonencode(local.state_machine_def.crawler_wrapper.definition)

  publish           = var.stepfunc_publish
  create_role       = false
  use_existing_role = true
  role_arn          = module.stepfunc-iam-role.arn
  attach_policies_for_integrations = false

  tags = var.service_tags
}

IAM角色配置

module "stepfunc-iam-role" {
  source  = "cloudposse/iam-role/aws"
  version = "0.16.2"

  enabled = true
  name    = "${var.env}-${var.stepfunc_role_name}"
  principals = {
    "Service" = ["states.eu-west-1.amazonaws.com"]
  }
  assume_role_actions = [
    "sts:AssumeRole", "sts:TagSession"
  ]
  managed_policy_arns = [
    "arn:aws:iam::aws:policy/service-role/AWSGlueServiceRole"
  ]
  permissions_boundary = "arn:aws:iam::${data.aws_caller_identity.current.account_id}:policy/permissions-boundary"

  policy_document_count = 7
  policy_documents = [
    data.aws_iam_policy_document.glue_perms.json,
    data.aws_iam_policy_document.glue_crawler_perms.json,
    data.aws_iam_policy_document.lambda_perms.json,
    data.aws_iam_policy_document.statemachine_perms.json,
    data.aws_iam_policy_document.ddb_perms.json,
    data.aws_iam_policy_document.log_perms.json,
    data.aws_iam_policy_document.event_perms.json,
  ]
  policy_description = var.stepfunc_policy_desc
  role_description   = var.stepfunc_role_desc

  tags = var.service_tags
}

关键权限配置

EventBridge权限(已放宽至最大)

data "aws_iam_policy_document" "event_perms" {
  statement {
    sid    = "EB_perms"
    effect = "Allow"
    actions = [
      "events:*"
    ]
    resources = [
      "*"
    ]
  }
}

Step Function自身权限

data "aws_iam_policy_document" "statemachine_perms" {
  statement {
    sid    = ""
    effect = "Allow"
    actions = [
      "states:Describe*",
      "states:Create*",
      "states:Update*",
      "states:List*",
      "states:Start*",
      "states:StopExecution"
    ]
    resources = [
      module.step-function-crawler-execution.state_machine_arn,
      module.step-function-schema-validation.state_machine_arn,
      module.step-function-cleanzone.state_machine_arn
    ]
  }
}

Lambda、Glue、DynamoDB等业务相关权限已按需配置,此处省略。

已尝试的无效操作

  • 放宽EventBridge权限至events:*,资源设为*
  • 尝试使用模块服务集成自动创建角色,提示密钥与集成列表不匹配(实际核对完全一致)

解决方案

1. 检查权限边界策略

你的IAM角色配置了permissions_boundary,这是最可能的问题根源:即使角色附加了允许events:*的策略,权限边界会限制角色实际可用权限。

  • 查看permissions-boundary策略内容,确认是否包含events:PutRule、events:PutTargets、events:DeleteRule这些创建managed-rule必需的操作
  • 如果没有,更新权限边界策略添加对应操作,或根据需求调整权限边界

2. 禁用模块自动创建EventBridge规则

部分Step Function Terraform模块会默认创建EventBridge规则用于调度状态机,若你不需要该功能:

  • 查阅模块文档,找到禁用自动创建EventBridge规则的参数(如create_event_rule这类布尔参数),设置为false

3. 确认信任策略区域匹配

虽然当前信任策略配置了states.eu-west-1.amazonaws.com,需确保该区域与你部署Step Function的区域完全一致,避免区域不匹配导致权限问题。


内容的提问来源于stack exchange,提问作者SamuelCook

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 06:34:57