Amazon Kendra调用Query接口出现AccessDeniedException问题求助
问题描述
我正在使用Amazon Kendra构建语义搜索引擎,以下是在SageMaker Notebook中编写的Python代码:
kendra = boto3.client("kendra",region_name='us-east-1') index_id = "05d8defe-e2-a9e3-3534de" query = "boots please" response = kendra.query( QueryText = query1, IndexId = index_id )
执行后返回权限错误:
AccessDeniedException: An error occurred (AccessDeniedException) when calling the Query operation: User: arn:aws:sts::9174853:assumed-role/AmazonSageMaker-ExecutionRole-2023083103184/SageMaker is not authorized to perform: kendra:Query on resource: arn:aws:kendra:us-east-1:9174853:index/5ba72cde-24e-8736-020a21bce
已完成的操作步骤:创建S3存储桶并加载数据集,创建Kendra索引并分配角色,将索引与S3数据源关联并分配新角色(与索引角色不同),同步数据后执行上述代码。
补充说明:
- 未手动分配任何权限,为唯一用户;
- 索引和数据源使用了不同的IAM角色。
错误原因
执行代码的**SageMaker执行角色(AmazonSageMaker-ExecutionRole-2023083103184)**未被授予Kendra索引的kendra:Query权限。Kendra的索引角色、数据源角色与SageMaker执行角色是独立的三个IAM角色,AWS默认不会自动为跨服务角色赋予此类权限。
解决步骤
- 登录AWS控制台,进入IAM服务页面;
- 在角色列表中找到目标角色:
AmazonSageMaker-ExecutionRole-2023083103184; - 为该角色添加自定义IAM策略,策略内容如下:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "kendra:Query", "Resource": "arn:aws:kendra:us-east-1:9174853:index/5ba72cde-24e-8736-020a21bce" } ] }
- 若需允许该角色查询所有Kendra索引,可将
Resource字段修改为arn:aws:kendra:us-east-1:9174853:index/*; - 保存策略后,重新在SageMaker Notebook中执行代码。
额外注意
代码中存在变量名错误:定义的查询变量为query,但调用kendra.query时使用了未定义的query1,会触发NameError,需修正为QueryText = query。
内容的提问来源于stack exchange,提问作者Apoorva
相关产品推荐
相关产品推荐

