You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS OpenSearch Serverless创建索引遇403访问拒绝求助

AWS OpenSearch Serverless 创建索引时403权限错误排查

我正在搭建AWS OpenSearch Serverless的最小可用示例,编写了如下Python代码:

import boto3
from opensearchpy import OpenSearch, RequestsHttpConnection, AWSV4SignerAuth

host = 'onb565zzbfkjr3spn8v5.us-east-1.aoss.amazonaws.com'
region = 'us-east-1'

credentials = boto3.Session().get_credentials()
auth = AWSV4SignerAuth(credentials, region)
client = OpenSearch(
    hosts = [{
        'host': host,
        'port': 443
    }],
    http_auth = auth,
    use_ssl = True,
    verify_certs=True,
    connection_class = RequestsHttpConnection
)

def create_index(index_name):
    index_body = {
      'settings': {
        'index': {
          'number_of_shards': 1
        }
      }
    }
    response = client.indices.create(index_name, body=index_body)
    print('\nCreating index:')
    print(response)

create_index('myindex')

已执行以下操作:

  • 创建了拥有AmazonOpenSearchServiceFullAccess、AmazonESFullAccess权限的IAM用户,还添加了两个内联策略:
    策略1:
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Sid": "VisualEditor0",
                "Effect": "Allow",
                "Action": "aoss:APIAccessAll",
                "Resource": "*"
            }
        ]
    }
    
    策略2:
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Sid": "VisualEditor0",
                "Effect": "Allow",
                "Action": "aoss:DashboardsAccessAll",
                "Resource": "*"
            }
        ]
    }
    
    (创建集合时未显示后两项权限)
  • 执行aws configure配置密钥和区域
  • 创建了设置为Public访问、指定该IAM用户为主体且开启全部访问权限的集合

尽管完成上述操作,创建索引时仍返回403(Access denied)错误,请问我遗漏了什么?

更新:已在AWS社区提交相同问题。


内容的提问来源于stack exchange,提问作者AlwaysLearning

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 22:20:25