You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

读取弹性IP未授权:AWS资源销毁IAM权限问题排查

问题:Terraform销毁AWS资源时遇EC2:DescribeAddresses未授权错误

执行Terraform销毁AWS资源时,收到如下错误:

Error: reading EC2 EIP (eipalloc-xxxx): UnauthorizedOperation: You are not authorized to perform this operation.

已确认该操作需要EC2:DescribeAddresses权限,尝试在IAM策略中使用通配符Resource: "*"排查资源定义问题,但未解决。当前Terraform使用的IAM角色关联策略如下:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "EC2",
            "Effect": "Allow",
            "Action": [
                "ec2:DeleteTags",
                "ec2:CreateNatGateway",
                "ec2:CreateInternetGateway",
                "ec2:CreateTags",
                "ec2:CreateVpc",
                "ec2:CreateRouteTable",
                "ec2:AssociateSubnetCidrBlock",
                "ec2:CreateSubnet",
                "ec2:AssociateRouteTable",
                "ec2:DescribeVpcs",
                "ec2:DescribeNatGateways",
                "ec2:DescribeSubnets"
            ],
            "Resource": [
                "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:route-table/*",
                "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:vpn-gateway/*",
                "arn:aws:ec2::xxxxxxxxxxxxxx:ipam-pool/*",
                "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:natgateway/*",
                "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:subnet/*",
                "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:vpc/*",
                "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:ipv6pool-ec2/*",
                "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:internet-gateway/*"
            ]
        },
        {
            "Sid": "EC2ElasticIPWildcard",
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeAddresses" //Action that allows it to read the elastic IP
            ],
            "Resource": [
                "arn:aws:ec2:ap-southeast-2:xxxxxxxxxxxxxx:elastic-ip/*" //Also tried a complete wildcard, but did not work
            ]
        },
        {
            "Sid": "Cognito",
            "Effect": "Allow",
            "Action": [
                "cognito-idp:DescribeUserPool",
                "cognito-idp:CreateUserPoolClient",
                "cognito-idp:DescribeUserPoolClient",
                "cognito-idp:CreateUserPool"
            ],
            "Resource": [
                "arn:aws:cognito-idp:ap-southeast-2:xxxxxxxxxxxxxx:*"
            ]
        },
        {
            "Sid": "S3",
            "Effect": "Allow",
            "Action": [
                "s3:PutObject",
                "s3:GetObject",
                "s3:ListAllMyBuckets",
                "s3:PutBucketPolicy",
                "s3:CreateBucket",
                "s3:ListBucket"
            ],
            "Resource": "arn:aws:s3:::*"
        }
    ]
}

解决方案

1. 修正ec2:DescribeAddresses的资源配置

ec2:DescribeAddresses属于EC2全局描述类操作,不支持指定具体的elastic-ip资源ARN,必须将该操作的Resource设置为"*"。将对应的IAM策略语句修改为:

{
    "Sid": "EC2ElasticIPDescribe",
    "Effect": "Allow",
    "Action": [
        "ec2:DescribeAddresses"
    ],
    "Resource": "*"
}

2. 补充销毁所需的额外权限(可选)

如果销毁操作还涉及删除弹性IP,需添加ec2:ReleaseAddress权限,同样使用Resource: "*":

{
    "Sid": "EC2ElasticIPManagement",
    "Effect": "Allow",
    "Action": [
        "ec2:DescribeAddresses",
        "ec2:ReleaseAddress"
    ],
    "Resource": "*"
}

3. 验证策略生效

更新IAM策略后,等待1-2分钟让AWS策略生效,再重新执行terraform destroy。


原因说明

EC2的大部分Describe*操作(包括DescribeAddresses)不支持资源级权限控制,即使指定具体资源ARN也无法生效,必须使用通配符*作为资源目标。这类操作是查询区域级资源列表的全局操作,而非针对单个资源的细粒度操作。

内容的提问来源于stack exchange,提问作者Gaurav Thantry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 06:32:11