访问AWS SQS队列时触发“queue does not exist”错误,求助排查
背景信息
我有一台EC2实例,其角色已附加以下IAM策略:
{ "Statement": [ ... 其他Allow语句 { "Action": "sqs:*", "Effect": "Allow", "Resource": [ "arn:aws:sqs:us-east-1:us-east-1:111111111111:automation-document-dev" ] } ], "Version": "2012-10-17" }
automation-document-dev的SQS访问策略如下:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowSQSS3BucketNotification", "Effect": "Allow", "Principal": { "Service": "s3.amazonaws.com" }, "Action": "sqs:SendMessage", "Resource": "arn:aws:sqs:us-east-1:111111111111:automation-document-dev", "Condition": { "ArnEquals": { "aws:SourceArn": "arn:aws:s3:::doc-storage-dev" } } } ] }
通过SSH登录到该EC2实例执行命令:
aws sqs get-queue-url --queue-name automation-document-dev
收到错误:
An error occurred (AWS.SimpleQueueService.NonExistentQueue) when calling the GetQueueUrl operation:
The specified queue does not exist or you do not have access to it.
我遗漏了什么配置?IAM角色/策略看起来已具备访问队列的所有权限(我用get-queue-url作为测试操作)。据我所知,只要EC2实例角色拥有服务权限,就无需修改SQS的访问策略。
问题根源与解决方案
1. IAM策略中的ARN格式错误
你提供的IAM策略里,SQS队列的ARN存在格式错误:
arn:aws:sqs:us-east-1:us-east-1:111111111111:automation-document-dev
正确的SQS ARN格式应为arn:aws:sqs:<区域>:<AWS账号ID>:<队列名>,你在区域字段后重复写入了us-east-1,挤占了账号ID的位置,导致IAM策略无法匹配到正确的队列资源。
修正后的Resource ARN应为:
arn:aws:sqs:us-east-1:111111111111:automation-document-dev
2. 验证区域一致性
执行aws sqs get-queue-url命令时,如果EC2实例的默认区域与队列所在的us-east-1不一致,需要显式指定区域参数:
aws sqs get-queue-url --queue-name automation-document-dev --region us-east-1
否则AWS CLI会使用实例的默认区域发起请求,导致找不到目标队列。
3. SQS访问策略的补充说明
你提到的“只要EC2实例角色拥有服务权限,就无需修改SQS的访问策略”是正确的:当SQS队列未设置显式访问策略时,AWS默认允许同一账号内的IAM实体(如EC2角色)通过自身IAM权限访问队列;即使队列设置了访问策略,只要策略中没有拒绝该角色的访问规则,同时IAM角色拥有对应权限,就可以正常访问。当前你的SQS访问策略仅允许S3发送消息,未添加拒绝规则,因此只要IAM权限配置正确,不会影响EC2角色的访问。
内容的提问来源于stack exchange,提问作者Georgi Koemdzhiev

