You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

创建Serverless OpenSearch向量索引遇约束错误及Dashboard异常求助

部分解决但未彻底修复

遛狗15分钟回来后,我再次尝试创建索引,用的参数和之前完全一样。不管成功还是毫无进展,都一样让人窝火。
Dashboard还是没法正常工作。


我快没动力继续试了。跟着AWS官方教程操作,已经重新创建了约4次集合,怀疑自己哪里操作错了。

核心问题:创建向量索引时出现如下错误:

1 validation error detected: Value '[collection/products]' at 'resource' failed to satisfy constraint: Member must satisfy constraint: [Member must satisfy regular expression pattern: index/[a-z][a-z0-9-]{3,32}/(?![_-])[a-z0-9][a-z0-9_-]*(?<![,:\"*+/\|?#<>])]

看起来缺少index标识,但不知道问题出在哪?会不会和用户权限有关?

IAM策略

下面是给用户配置的权限极宽松的IAM策略(我知道*已经包含所有权限,这么做只是为了排查问题的无奈之举):

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "aoss:BatchGetCollection",
                "aoss:DeleteCollection",
                "aoss:UpdateAccessPolicy",
                "aoss:CreateAccessPolicy",
                "aoss:CreateSecurityPolicy",
                "aoss:ListCollections",
                "aoss:ListAccessPolicies",
                "aoss:CreateCollection",
                "aoss:DashboardsAccessAll",
                "aoss:APIAccessAll",
                "aoss:*"
            ],
            "Resource": "*",
            "Condition": {
                "IpAddress": {
                    "aws:SourceIp": [
                        "76.76.21.0/24",
                        "85.224.0.0/13"
                    ]
                }
            }
        }
    ]
}

暂时不用管IP限制,我清楚相关设置。

数据访问策略(可能是问题所在?)

因为我怀疑问题出在这,这是我唯一偏离教程的地方——在规则里添加了集合资源。注意!没法在collection/products后面加*,否则会报错。

[
  {
    "Rules": [
      {
        "Resource": [
          "collection/products"
        ],
        "Permission": [
          "aoss:CreateCollectionItems",
          "aoss:DeleteCollectionItems",
          "aoss:UpdateCollectionItems",
          "aoss:DescribeCollectionItems"
        ],
        "ResourceType": "collection"
      },
      {
        "Resource": [
          "index/products/*"
        ],
        "Permission": [
          "aoss:CreateIndex",
          "aoss:DeleteIndex",
          "aoss:UpdateIndex",
          "aoss:DescribeIndex",
          "aoss:ReadDocument",
          "aoss:WriteDocument"
        ],
        "ResourceType": "index"
      }
    ],
    "Principal": [
      "BLA"
    ],
    "Description": "products"
  }
]

编辑1

再次创建新集合时,出现如下异常提示:

The default principal is invalid please choose standard create option to configure this manually.

这是不是说明用户配置有问题?用户是通过可视化界面选的,格式没问题,但权限这么宽松的IAM策略怎么还会出问题...

编辑2

哦,说不定我应该先创建索引,再创建向量嵌入?大概是这样?

但严格按照教程操作后,OpenSearch Dashboard URL还是显示Not supported。

编辑3

尝试用代码创建索引也失败了,大概率是IAM策略的问题。现在已经重新创建了6次集合,但OpenSearch Dashboard始终显示Not supported。

内容的提问来源于stack exchange,提问作者Cookie

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 22:58:20