You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Terraform实现Route53的ChangeResourceRecordSetsNormalizedRecordNames权限

Terraform实现Route53特定记录集权限限制

需求说明

需要通过Terraform配置IAM权限,让指定身份仅能修改Route53特定托管区中匹配service-*.{domain_name}格式的记录集,对应目标JSON权限配置如下:

{
  "Effect": "Allow",
  "Action": "route53:ChangeResourceRecordSets",
  "Resource": "arn:aws:route53:::hostedzone/xxxxxxx",
  "Condition": {
    "ForAllValues:StringLike": {
      "route53:ChangeResourceRecordSetsNormalizedRecordNames": ["service-*.{domain_name}"]
    }
  }
}

正确的Terraform配置

以下是对应上述JSON配置的Terraform代码,修正了条件测试类型、变量名和值的格式问题:

statement {
  sid    = "AllowRoute53SpecificRecords"
  effect = "Allow"
  actions = [
    "route53:ChangeResourceRecordSets"
  ]
  # 可替换为固定托管区ARN,或通过data资源动态获取ID
  resources = ["arn:aws:route53:::hostedzone/${data.aws_route53_zone.target_zone.zone_id}"]

  condition {
    # 需与目标JSON保持一致,使用ForAllValues:StringLike
    test     = "ForAllValues:StringLike"
    # 严格匹配Route53官方定义的条件键
    variable = "route53:ChangeResourceRecordSetsNormalizedRecordNames"
    # 替换为你的域名规则,确保包含通配符和正确域名后缀
    values   = ["service-*.${var.domain_name}"]
  }
}

关键注意事项

  • 条件测试类型:必须使用ForAllValues:StringLike,确保所有变更的记录集都符合匹配规则,而非你之前尝试的ForAnyValue:StringLike。
  • 变量名准确性:条件变量名必须严格为route53:ChangeResourceRecordSetsNormalizedRecordNames,大小写和拼写不能出错。
  • 值的格式:values数组中的内容要包含通配符*,并正确拼接域名变量,例如service-*.example.com。
  • 托管区ARN格式:Route53托管区ARN固定格式为arn:aws:route53:::hostedzone/[ZONE_ID],注意中间为三个冒号。

内容的提问来源于stack exchange,提问作者Adam E

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 20:03:15