You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

克隆EC2后已配置IAM角色无法生效的问题排查与解决

EC2跨可用区克隆后IAM角色失效问题的解决方案

问题场景

将EC2实例通过「创建镜像+基于镜像启动新实例」的方式从原可用区迁移到新可用区后,控制台显示实例配置完全一致,IAM角色也已正确分配,但新实例无法使用该IAM角色:

  • 旧实例执行aws sts get-caller-identity能正常返回身份信息
  • 新实例执行同一命令返回:

C:>aws sts get-caller-identity
Unable to locate credentials. You can configure credentials by running "aws configure".

已尝试的无效操作

  • 取消并重新分配IAM角色
  • 创建全新的IAM角色及实例配置文件后分配给新实例
  • 多次重启新实例

排查过程

进一步测试元数据访问发现:

  • 旧实例可通过curl http://169.254.169.254/latest/meta-data/iam/security-credentials正常获取IAM凭证信息
  • 新实例执行该命令返回连接超时:

curl: (28) Failed to connect to 169.254.169.254 port 80 after 21226 ms: Couldn't connect to server

执行route print检查路由表后发现关键问题:AWS添加的169.254.169.xxx段持久路由仍指向原可用区的网关,导致新实例无法访问当前可用区的元数据服务。

修复步骤

通过以下命令删除旧路由并添加指向当前可用区网关的新路由:

route delete 169.254.169.123 
route delete 169.254.169.249 
route delete 169.254.169.250
route delete 169.254.169.251
route delete 169.254.169.253
route delete 169.254.169.254


route add 169.254.169.123 mask 255.255.255.255 <你的网关地址>  metric 15 if <网络接口编号> -p
route add 169.254.169.249 mask 255.255.255.255 <你的网关地址>  metric 15 if <网络接口编号> -p
route add 169.254.169.250 mask 255.255.255.255 <你的网关地址>  metric 15 if <网络接口编号> -p
route add 169.254.169.251 mask 255.255.255.255 <你的网关地址>  metric 30 if <网络接口编号> -p
route add 169.254.169.253 mask 255.255.255.255 <你的网关地址>  metric 30 if <网络接口编号> -p
route add 169.254.169.254 mask 255.255.255.255 <你的网关地址>  metric 30 if <网络接口编号> -p

参数说明

  • <你的网关地址>:新实例所在可用区的VPC网关地址
  • <网络接口编号>:执行route print命令后,开头列表中对应实例主网络接口的编号(示例中为6)

内容的提问来源于stack exchange,提问作者Yefka

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 03:23:39