You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS备份政策创建失败:政策文档不符合指定类型要求

修复AWS Organizations备份政策CloudFormation模板格式错误

问题原因分析

收到「The provided policy document does not meet the requirements of the specified policy type」错误,是因为模板的Content部分不符合AWS Organizations备份政策的JSON schema规范,同时错误混用了CloudFormation转换语法和政策结构。主要问题包括:

  • 错误在政策内容中使用@@assign/@@append等CloudFormation扩展语法
  • 数字类型字段(如备份窗口时长、保留天数)使用了字符串格式
  • Copy Actions、标签、资源选择器的结构不符合备份政策要求

修正后的模板

AWSTemplateFormatVersion: '2010-09-09'
Transform:
  - 'AWS::LanguageExtensions'
Parameters:
  pOrgBackupTargetOUs:
    Description: 要绑定备份政策的AWS组织OU列表(逗号分隔)
    Type: CommaDelimitedList
  pCentralBackupVaultArn:
    Description: 集中式AWS备份Vault的ARN,作为所有备份的二级存储位置
    Type: String
  pCrossAccountBackupRole:
    Description: 执行跨账户备份操作的IAM角色名称
    Type: String
  pMemberAccountBackupVault:
    AllowedPattern: ^[a-zA-Z0-9\-\_\.]{1,50}$
    ConstraintDescription: 成员账户备份Vault的名称(区分大小写)
    Type: String
  pTagKey:
    Type: String 
    Description: 分配给备份资源的标签键
    Default: 'project'
  pTagValue:
    Type: String 
    Description: 分配给备份资源的标签值
    Default: 'aws-backup'
Resources:
  rOrgDailyBackUpPolicy:
    Type: AWS::Organizations::Policy
    Properties:
      Name: org-daily-backup-policy
      Description: 根据资源选择条件配置的每日备份政策
      Type: BACKUP_POLICY
      TargetIds: !Ref pOrgBackupTargetOUs
      Content:
        Fn::ToJsonString:
          plans:
            OrgBackupPlanDaily:
              rules:
                OrgDailyBackupRule:
                  schedule_expression: cron(0 19 ? * * *)
                  start_backup_window_minutes: 60
                  complete_backup_window_minutes: 1200
                  lifecycle:
                    delete_after_days: 14
                  target_backup_vault_name: !Ref pMemberAccountBackupVault
                  recovery_point_tags:
                    !Ref pTagKey: !Ref pTagValue
                  copy_actions:
                    - target_backup_vault_arn: !Ref pCentralBackupVaultArn
                      lifecycle:
                        delete_after_days: 14
              backup_plan_tags:
                !Ref pTagKey: !Ref pTagValue
              regions:
                - eu-central-1
              selections:
                - name: OrgDailyBackupSelection
                  iam_role_arn: !Sub 'arn:aws:iam::$${AWS::AccountId}:role/${pCrossAccountBackupRole}'
                  tag_key: 'backup'
                  tag_values:
                    - 'daily'

关键修正点说明

  • 移除CloudFormation扩展语法:将@@assign/@@append替换为标准CloudFormation函数(!Ref/!Sub),确保政策内容是纯JSON结构
  • 修正字段类型:将备份窗口时长、保留天数等数字字段从字符串改为数字类型(如'60'→60)
  • 调整Copy Actions结构:改为数组格式,每个副本操作是独立对象,符合备份政策schema
  • 简化标签结构:恢复标签的键值对原生格式,移除冗余的tag_key/tag_value嵌套
  • 修正资源选择器结构:selections改为数组,每个选择器包含name、iam_role_arn、tag_key、tag_values等必填字段,同时用$${AWS::AccountId}在!Sub中正确转义账户ID变量
  • 规范Regions格式:直接定义字符串数组,无需使用扩展语法

内容的提问来源于stack exchange,提问作者AceP

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 13:17:10