You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

更新AWS CodeBuild项目环境遇策略绑定错误,求解决方法

问题:AWS CodeBuild配置VPC时遇到策略关联错误

问题背景

部署构建服务器时,发现现有AWS CodeBuild项目无法访问VPC内资源,检查后确认项目未配置VPC、安全组和子网。尝试进入AWS CodeBuild控制台(路径:开发者工具 > CodeBuild > 构建项目 > <my project> > 编辑环境),添加管理HTTP服务器的VPC、安全组和子网时,保存报错:
The policy is attached to 2 entities but it must be attached to a single role

当前该CodeBuild使用的IAM角色仅附加了一个自定义策略,策略内容如下:

{
    "Statement": [
        {
            "Action": [
                "iam:PassRole"
            ],
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEqualsIfExists": {
                    "iam:PassedToService": [
                        "cloudformation.amazonaws.com",
                        "elasticbeanstalk.amazonaws.com",
                        "ec2.amazonaws.com",
                        "ecs-tasks.amazonaws.com"
                    ]
                }
            }
        },
        {
            "Action": [
                "codecommit:CancelUploadArchive",
                "codecommit:GetBranch",
                "codecommit:GetCommit",
                "codecommit:GetRepository",
                "codecommit:GetUploadArchiveStatus",
                "codecommit:UploadArchive"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "codedeploy:CreateDeployment",
                "codedeploy:GetApplication",
                "codedeploy:GetApplicationRevision",
                "codedeploy:GetDeployment",
                "codedeploy:GetDeploymentConfig",
                "codedeploy:RegisterApplicationRevision"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "codestar-connections:UseConnection"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "elasticbeanstalk:*",
                "ec2:*",
                "elasticloadbalancing:*",
                "autoscaling:*",
                "cloudwatch:*",
                "s3:*",
                "sns:*",
                "cloudformation:*",
                "rds:*",
                "sqs:*",
                "ecs:*"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "lambda:InvokeFunction",
                "lambda:ListFunctions"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "opsworks:CreateDeployment",
                "opsworks:DescribeApps",
                "opsworks:DescribeCommands",
                "opsworks:DescribeDeployments",
                "opsworks:DescribeInstances",
                "opsworks:DescribeStacks",
                "opsworks:UpdateApp",
                "opsworks:UpdateStack"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "cloudformation:CreateStack",
                "cloudformation:DeleteStack",
                "cloudformation:DescribeStacks",
                "cloudformation:UpdateStack",
                "cloudformation:CreateChangeSet",
                "cloudformation:DeleteChangeSet",
                "cloudformation:DescribeChangeSet",
                "cloudformation:ExecuteChangeSet",
                "cloudformation:SetStackPolicy",
                "cloudformation:ValidateTemplate"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "codebuild:BatchGetBuilds",
                "codebuild:StartBuild",
                "codebuild:BatchGetBuildBatches",
                "codebuild:StartBuildBatch"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Effect": "Allow",
            "Action": [
                "devicefarm:ListProjects",
                "devicefarm:ListDevicePools",
                "devicefarm:GetRun",
                "devicefarm:GetUpload",
                "devicefarm:CreateUpload",
                "devicefarm:ScheduleRun"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "servicecatalog:ListProvisioningArtifacts",
                "servicecatalog:CreateProvisioningArtifact",
                "servicecatalog:DescribeProvisioningArtifact",
                "servicecatalog:DeleteProvisioningArtifact",
                "servicecatalog:UpdateProduct"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "cloudformation:ValidateTemplate"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "ecr:DescribeImages"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "states:DescribeExecution",
                "states:DescribeStateMachine",
                "states:StartExecution"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "appconfig:StartDeployment",
                "appconfig:StopDeployment",
                "appconfig:GetDeployment"
            ],
            "Resource": "*"
        }
    ],
    "Version": "2012-10-17"
}

修复步骤

  1. 确认策略关联情况
    错误提示说明该自定义策略被同时附加到了两个IAM实体(角色、用户或组),但CodeBuild配置VPC时要求关联角色的策略只能专属该角色,不能共享。

    • 进入IAM控制台 > 策略 > 找到该自定义策略 > 切换到「关联实体」标签页,查看除了CodeBuild角色外是否有其他实体关联了此策略。
  2. 分离共享策略
    有两种可行方案:

    • 方案一:复制策略为其他实体创建独立副本
      1. 选中该策略,点击「复制」按钮
      2. 修改新策略的名称(避免与原策略混淆)
      3. 将新策略附加给原本共享该策略的其他实体
      4. 从其他实体上移除原策略,确保原策略仅关联CodeBuild的IAM角色
    • 方案二:为CodeBuild角色创建专属策略
      1. 复制原策略内容,创建一个全新的自定义策略
      2. 将新策略附加到CodeBuild的IAM角色上
      3. 移除CodeBuild角色上的原策略,确保原策略只关联其他需要的实体
  3. 补充VPC访问权限
    原策略缺少CodeBuild在VPC内运行所需的权限,需在CodeBuild角色的策略中添加以下语句:

    {
        "Effect": "Allow",
        "Action": [
            "ec2:CreateNetworkInterface",
            "ec2:DescribeNetworkInterfaces",
            "ec2:DeleteNetworkInterface",
            "ec2:DescribeSubnets",
            "ec2:DescribeSecurityGroups",
            "ec2:DescribeVpcs"
        ],
        "Resource": "*"
    }
    

    这些权限用于CodeBuild创建、管理弹性网络接口(ENI),是访问VPC资源的必要条件。

  4. 重新配置VPC设置
    完成上述操作后,回到CodeBuild项目的「编辑环境」页面,重新选择目标VPC、子网和安全组,保存即可。

内容的提问来源于stack exchange,提问作者alilland

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 21:37:54