You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用CreateChangeSet操作时触发ValidationError:Fn::GetAtt引用未定义资源的SAM模板错误排查与解决请求

Fixing the Fn::GetAtt references undefined resource ValidationError in Your SAM Template

Let's break down exactly what's causing this error and how to fix each issue in your template:

The core problem here is that you're using !GetAtt to reference resources that haven't been defined anywhere in your SAM template. CloudFormation can't resolve these missing references, hence the ValidationError.


1. Missing Dynamomytracker DynamoDB Resource

In your testKinesisRole IAM policy, you have a permission block that references:

Resource:
  - !GetAtt Dynamomytracker.Arn

But there's no Dynamomytracker resource (of type AWS::DynamoDB::Table) defined in your template. To fix this:

  • Either add the full AWS::DynamoDB::Table definition for Dynamomytracker to your Resources section, or
  • If this table exists outside the stack, replace !GetAtt Dynamomytracker.Arn with the direct ARN of the table (e.g., arn:aws:dynamodb:us-east-1:123456789012:table/my_tracker_table).

2. Missing KinesisTest1 Stream Resource

Two parts of your template reference an undefined KinesisTest1 stream:

In LambdaTest1KinesisToDDB's Kinesis Event:

Stream: !GetAtt Kinesistest1.Arn

(Note: You also have a case mismatch here—Kinesistest1 vs the likely intended KinesisTest1)

In testKinesisToDDBRole's IAM Policy:

Resource:
  - !GetAtt KinesisTest1.Arn
  - !GetAtt KinesisTest2.Arn

Your template only defines KinesisTest2, so you need to:

  • Add a matching AWS::Kinesis::Stream resource for KinesisTest1 (copy the KinesisTest2 definition and adjust the name), or
  • If you intended to use KinesisTest2 for this Lambda, update both references to point to KinesisTest2.Arn, or
  • Use the ARN of an existing Kinesis stream if it's managed outside this stack.

3. Missing Dynamotest DynamoDB Resource

In your testKinesisToDDBRole policy, you have duplicate references to:

- !Sub
  - "${Table}*"
  - { Table: !GetAtt "Dynamotest.Arn" }

There's no Dynamotest table defined in your template. Fix this by:

  • Adding the AWS::DynamoDB::Table resource for Dynamotest to your template, or
  • Replacing the reference with the direct ARN of an existing table.

Bonus: Fix Duplicate S3 Event Filter Rules

While not related to your current error, your LambdaS3ToKinesis S3 event has invalid duplicate filter rules:

Rules:
  - Name: prefix
    Value: "${Environment}/test1/INPUT/"
  - Name: suffix
    Value: ".json"
  - Name: prefix
    Value: "${Environment}/test2/INPUT/"
  - Name: suffix
    Value: ".json"

S3 doesn't allow multiple prefix/suffix rules in a single filter. To match both paths, split this into two separate S3 Event entries:

Events:
  FileUploadTest1:
    Type: S3
    Properties:
      Bucket: !Sub "${S3}"
      Events: s3:ObjectCreated:*
      Filter:
        S3Key:
          Rules:
            - Name: prefix
              Value: "${Environment}/test1/INPUT/"
            - Name: suffix
              Value: ".json"
  FileUploadTest2:
    Type: S3
    Properties:
      Bucket: !Sub "${S3}"
      Events: s3:ObjectCreated:*
      Filter:
        S3Key:
          Rules:
            - Name: prefix
              Value: "${Environment}/test2/INPUT/"
            - Name: suffix
              Value: ".json"

Once you resolve all the undefined resource references, your CreateChangeSet operation should execute without the ValidationError.

内容的提问来源于stack exchange,提问作者adhi hari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 16:37:50