读取弹性IP未授权:AWS资源销毁IAM权限问题排查
问题:Terraform销毁AWS资源时遇EC2:DescribeAddresses未授权错误
执行Terraform销毁AWS资源时,收到如下错误:
Error: reading EC2 EIP (eipalloc-xxxx): UnauthorizedOperation: You are not authorized to perform this operation.
已确认该操作需要EC2:DescribeAddresses权限,尝试在IAM策略中使用通配符Resource: "*"排查资源定义问题,但未解决。当前Terraform使用的IAM角色关联策略如下:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "EC2", "Effect": "Allow", "Action": [ "ec2:DeleteTags", "ec2:CreateNatGateway", "ec2:CreateInternetGateway", "ec2:CreateTags", "ec2:CreateVpc", "ec2:CreateRouteTable", "ec2:AssociateSubnetCidrBlock", "ec2:CreateSubnet", "ec2:AssociateRouteTable", "ec2:DescribeVpcs", "ec2:DescribeNatGateways", "ec2:DescribeSubnets" ], "Resource": [ "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:route-table/*", "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:vpn-gateway/*", "arn:aws:ec2::xxxxxxxxxxxxxx:ipam-pool/*", "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:natgateway/*", "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:subnet/*", "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:vpc/*", "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:ipv6pool-ec2/*", "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:internet-gateway/*" ] }, { "Sid": "EC2ElasticIPWildcard", "Effect": "Allow", "Action": [ "ec2:DescribeAddresses" //Action that allows it to read the elastic IP ], "Resource": [ "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:elastic-ip/*" //Also tried a complete wildcard, but did not work ] }, { "Sid": "Cognito", "Effect": "Allow", "Action": [ "cognito-idp:DescribeUserPool", "cognito-idp:CreateUserPoolClient", "cognito-idp:DescribeUserPoolClient", "cognito-idp:CreateUserPool" ], "Resource": [ "arn:aws:cognito-idp:ap-southeast-2:xxxxxxxxxxxxxx:*" ] }, { "Sid": "S3", "Effect": "Allow", "Action": [ "s3:PutObject", "s3:GetObject", "s3:ListAllMyBuckets", "s3:PutBucketPolicy", "s3:CreateBucket", "s3:ListBucket" ], "Resource": "arn:aws:s3:::*" } ] }
解决方案
1. 修正ec2:DescribeAddresses的资源配置
ec2:DescribeAddresses属于EC2全局描述类操作,不支持指定具体的elastic-ip资源ARN,必须将该操作的Resource设置为"*"。将对应的IAM策略语句修改为:
{ "Sid": "EC2ElasticIPDescribe", "Effect": "Allow", "Action": [ "ec2:DescribeAddresses" ], "Resource": "*" }
2. 补充销毁所需的额外权限(可选)
如果销毁操作还涉及删除弹性IP,需添加ec2:ReleaseAddress权限,同样使用Resource: "*":
{ "Sid": "EC2ElasticIPManagement", "Effect": "Allow", "Action": [ "ec2:DescribeAddresses", "ec2:ReleaseAddress" ], "Resource": "*" }
3. 验证策略生效
更新IAM策略后,等待1-2分钟让AWS策略生效,再重新执行terraform destroy。
原因说明
EC2的大部分Describe*操作(包括DescribeAddresses)不支持资源级权限控制,即使指定具体资源ARN也无法生效,必须使用通配符*作为资源目标。这类操作是查询区域级资源列表的全局操作,而非针对单个资源的细粒度操作。
内容的提问来源于stack exchange,提问作者Gaurav Thantry
相关产品推荐
相关产品推荐

