AWS备份政策创建失败:政策文档不符合指定类型要求
修复AWS Organizations备份政策CloudFormation模板格式错误
问题原因分析
收到「The provided policy document does not meet the requirements of the specified policy type」错误,是因为模板的Content部分不符合AWS Organizations备份政策的JSON schema规范,同时错误混用了CloudFormation转换语法和政策结构。主要问题包括:
- 错误在政策内容中使用
@@assign/@@append等CloudFormation扩展语法 - 数字类型字段(如备份窗口时长、保留天数)使用了字符串格式
- Copy Actions、标签、资源选择器的结构不符合备份政策要求
修正后的模板
AWSTemplateFormatVersion: '2010-09-09' Transform: - 'AWS::LanguageExtensions' Parameters: pOrgBackupTargetOUs: Description: 要绑定备份政策的AWS组织OU列表(逗号分隔) Type: CommaDelimitedList pCentralBackupVaultArn: Description: 集中式AWS备份Vault的ARN,作为所有备份的二级存储位置 Type: String pCrossAccountBackupRole: Description: 执行跨账户备份操作的IAM角色名称 Type: String pMemberAccountBackupVault: AllowedPattern: ^[a-zA-Z0-9\-\_\.]{1,50}$ ConstraintDescription: 成员账户备份Vault的名称(区分大小写) Type: String pTagKey: Type: String Description: 分配给备份资源的标签键 Default: 'project' pTagValue: Type: String Description: 分配给备份资源的标签值 Default: 'aws-backup' Resources: rOrgDailyBackUpPolicy: Type: AWS::Organizations::Policy Properties: Name: org-daily-backup-policy Description: 根据资源选择条件配置的每日备份政策 Type: BACKUP_POLICY TargetIds: !Ref pOrgBackupTargetOUs Content: Fn::ToJsonString: plans: OrgBackupPlanDaily: rules: OrgDailyBackupRule: schedule_expression: cron(0 19 ? * * *) start_backup_window_minutes: 60 complete_backup_window_minutes: 1200 lifecycle: delete_after_days: 14 target_backup_vault_name: !Ref pMemberAccountBackupVault recovery_point_tags: !Ref pTagKey: !Ref pTagValue copy_actions: - target_backup_vault_arn: !Ref pCentralBackupVaultArn lifecycle: delete_after_days: 14 backup_plan_tags: !Ref pTagKey: !Ref pTagValue regions: - eu-central-1 selections: - name: OrgDailyBackupSelection iam_role_arn: !Sub 'arn:aws:iam::$${AWS::AccountId}:role/${pCrossAccountBackupRole}' tag_key: 'backup' tag_values: - 'daily'
关键修正点说明
- 移除CloudFormation扩展语法:将
@@assign/@@append替换为标准CloudFormation函数(!Ref/!Sub),确保政策内容是纯JSON结构 - 修正字段类型:将备份窗口时长、保留天数等数字字段从字符串改为数字类型(如
'60'→60) - 调整Copy Actions结构:改为数组格式,每个副本操作是独立对象,符合备份政策schema
- 简化标签结构:恢复标签的键值对原生格式,移除冗余的
tag_key/tag_value嵌套 - 修正资源选择器结构:
selections改为数组,每个选择器包含name、iam_role_arn、tag_key、tag_values等必填字段,同时用$${AWS::AccountId}在!Sub中正确转义账户ID变量 - 规范Regions格式:直接定义字符串数组,无需使用扩展语法
内容的提问来源于stack exchange,提问作者AceP
相关产品推荐
相关产品推荐

