You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Amazon Kendra调用Query接口出现AccessDeniedException问题求助

问题描述

我正在使用Amazon Kendra构建语义搜索引擎,以下是在SageMaker Notebook中编写的Python代码:

kendra = boto3.client("kendra",region_name='us-east-1')    
index_id = "05d8defe-e2-a9e3-3534de"
query = "boots please"

response = kendra.query(
    QueryText = query1,
    IndexId = index_id
)

执行后返回权限错误:

AccessDeniedException: An error occurred (AccessDeniedException) when calling the Query operation: User: arn:aws:sts::9174853:assumed-role/AmazonSageMaker-ExecutionRole-2023083103184/SageMaker is not authorized to perform: kendra:Query on resource: arn:aws:kendra:us-east-1:9174853:index/5ba72cde-24e-8736-020a21bce

已完成的操作步骤:创建S3存储桶并加载数据集,创建Kendra索引并分配角色,将索引与S3数据源关联并分配新角色(与索引角色不同),同步数据后执行上述代码。
补充说明:

  • 未手动分配任何权限,为唯一用户;
  • 索引和数据源使用了不同的IAM角色。
错误原因

执行代码的**SageMaker执行角色(AmazonSageMaker-ExecutionRole-2023083103184)**未被授予Kendra索引的kendra:Query权限。Kendra的索引角色、数据源角色与SageMaker执行角色是独立的三个IAM角色,AWS默认不会自动为跨服务角色赋予此类权限。

解决步骤
  1. 登录AWS控制台,进入IAM服务页面;
  2. 在角色列表中找到目标角色:AmazonSageMaker-ExecutionRole-2023083103184;
  3. 为该角色添加自定义IAM策略,策略内容如下:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "kendra:Query",
            "Resource": "arn:aws:kendra:us-east-1:9174853:index/5ba72cde-24e-8736-020a21bce"
        }
    ]
}
  1. 若需允许该角色查询所有Kendra索引,可将Resource字段修改为arn:aws:kendra:us-east-1:9174853:index/*;
  2. 保存策略后,重新在SageMaker Notebook中执行代码。

额外注意

代码中存在变量名错误:定义的查询变量为query,但调用kendra.query时使用了未定义的query1,会触发NameError,需修正为QueryText = query。

内容的提问来源于stack exchange,提问作者Apoorva

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 22:13:29