You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS IAM身份中心内联策略动态引用用户名问题求助

AWS IAM身份中心内联策略动态引用用户名问题

我尝试在AWS IAM身份中心的内联策略中动态引用用户名,目标是通过命令aws ec2-instance-connect ssh --instance-id xxx --os-user xxx登录虚拟机并添加用户。静态指定ec2:osuser(如"ec2:osuser": "xxxxx")时可正常工作,但用${aws:username}动态引用就不行。我的AWS账号中有2个从Azure同步的用户,想确认${aws:username}是否对应这两个账号的用户名?

当前使用的策略:

{
"Version": "2012-10-17",
"Statement": [
    {
        "Effect": "Allow",
        "Action": "ec2-instance-connect:SendSSHPublicKey",
        "Resource": "*",
        "Condition": {
            "StringEqual": {
                "ec2:osuser": [
                    "arn:aws:iam::11111111:user/${aws:username}"
                ]
            }
        }
    },
    {
        "Effect": "Allow",
        "Action": "ec2:DescribeInstances",
        "Resource": "*"
    }
]
}

问题分析与解决

  1. ${aws:username}的对应关系
    在IAM身份中心环境下,${aws:username}对应的就是从Azure同步过来的IAM身份中心用户的用户名,和你在身份中心控制台看到的用户名一致,也就是这两个同步账号的用户名。

  2. 策略错误点
    你当前把${aws:username}拼在了IAM用户ARN里,但ec2:osuser条件要求的是虚拟机操作系统层面的纯用户名,和静态指定时的格式一致,不需要加任何ARN前缀。

  3. 修正后的策略

{
"Version": "2012-10-17",
"Statement": [
    {
        "Effect": "Allow",
        "Action": "ec2-instance-connect:SendSSHPublicKey",
        "Resource": "*",
        "Condition": {
            "StringEqual": {
                "ec2:osuser": "${aws:username}"
            }
        }
    },
    {
        "Effect": "Allow",
        "Action": "ec2:DescribeInstances",
        "Resource": "*"
    }
]
}
  1. 额外验证建议
    可以执行aws sts get-caller-identity查看当前用户的详细信息,或者直接在IAM身份中心控制台查看用户的用户名,确认${aws:username}的值是否和你要登录的虚拟机OS用户名一致。如果同步过来的用户名和OS用户名不匹配,要么调整虚拟机的OS用户名,要么考虑使用其他IAM身份中心变量(如${aws:userid})来适配。

内容的提问来源于stack exchange,提问作者Zackk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 06:43:20