调用CreateChangeSet操作时触发ValidationError:Fn::GetAtt引用未定义资源的SAM模板错误排查与解决请求
Fn::GetAtt references undefined resource ValidationError in Your SAM Template Let's break down exactly what's causing this error and how to fix each issue in your template:
The core problem here is that you're using !GetAtt to reference resources that haven't been defined anywhere in your SAM template. CloudFormation can't resolve these missing references, hence the ValidationError.
1. Missing Dynamomytracker DynamoDB Resource
In your testKinesisRole IAM policy, you have a permission block that references:
Resource: - !GetAtt Dynamomytracker.Arn
But there's no Dynamomytracker resource (of type AWS::DynamoDB::Table) defined in your template. To fix this:
- Either add the full
AWS::DynamoDB::Tabledefinition forDynamomytrackerto yourResourcessection, or - If this table exists outside the stack, replace
!GetAtt Dynamomytracker.Arnwith the direct ARN of the table (e.g.,arn:aws:dynamodb:us-east-1:123456789012:table/my_tracker_table).
2. Missing KinesisTest1 Stream Resource
Two parts of your template reference an undefined KinesisTest1 stream:
In LambdaTest1KinesisToDDB's Kinesis Event:
Stream: !GetAtt Kinesistest1.Arn
(Note: You also have a case mismatch here—Kinesistest1 vs the likely intended KinesisTest1)
In testKinesisToDDBRole's IAM Policy:
Resource: - !GetAtt KinesisTest1.Arn - !GetAtt KinesisTest2.Arn
Your template only defines KinesisTest2, so you need to:
- Add a matching
AWS::Kinesis::Streamresource forKinesisTest1(copy theKinesisTest2definition and adjust the name), or - If you intended to use
KinesisTest2for this Lambda, update both references to point toKinesisTest2.Arn, or - Use the ARN of an existing Kinesis stream if it's managed outside this stack.
3. Missing Dynamotest DynamoDB Resource
In your testKinesisToDDBRole policy, you have duplicate references to:
- !Sub - "${Table}*" - { Table: !GetAtt "Dynamotest.Arn" }
There's no Dynamotest table defined in your template. Fix this by:
- Adding the
AWS::DynamoDB::Tableresource forDynamotestto your template, or - Replacing the reference with the direct ARN of an existing table.
Bonus: Fix Duplicate S3 Event Filter Rules
While not related to your current error, your LambdaS3ToKinesis S3 event has invalid duplicate filter rules:
Rules: - Name: prefix Value: "${Environment}/test1/INPUT/" - Name: suffix Value: ".json" - Name: prefix Value: "${Environment}/test2/INPUT/" - Name: suffix Value: ".json"
S3 doesn't allow multiple prefix/suffix rules in a single filter. To match both paths, split this into two separate S3 Event entries:
Events: FileUploadTest1: Type: S3 Properties: Bucket: !Sub "${S3}" Events: s3:ObjectCreated:* Filter: S3Key: Rules: - Name: prefix Value: "${Environment}/test1/INPUT/" - Name: suffix Value: ".json" FileUploadTest2: Type: S3 Properties: Bucket: !Sub "${S3}" Events: s3:ObjectCreated:* Filter: S3Key: Rules: - Name: prefix Value: "${Environment}/test2/INPUT/" - Name: suffix Value: ".json"
Once you resolve all the undefined resource references, your CreateChangeSet operation should execute without the ValidationError.
内容的提问来源于stack exchange,提问作者adhi hari

