You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform管理API Gateway REST API触发403权限错误,排查缺失权限

问题:Terraform管理API Gateway REST API时权限缺失排查

场景说明

使用以下Terraform资源块管理AWS API Gateway REST API:

resource "aws_api_gateway_rest_api" "api" {
  tags = local.tags
  name = local.name_prefix
}

resource "aws_api_gateway_account" "metering" {
  cloudwatch_role_arn = aws_iam_role.cloudwatch.arn
}

执行错误

Error: reading API Gateway REST API (nkrcj743be): AccessDeniedException:
│ status code: 403, request id:

当前已附加的权限策略

[
    "apigateway:GetRestApi",
    "iam:GetRole",
    "iam:PassRole",
    "apigateway:GetResources",         
    "apigateway:GetRestApis",       
    "apigateway:GetAccount",
    "apigateway:GetMethod",
    "apigateway:GetIntegration",
    "apigateway:GetDeployment",
    "apigateway:GetStage"
]

需要补充的权限

针对你使用的两个Terraform资源,需补充以下必要权限:

  • apigateway:CreateRestApi:用于创建REST API实例
  • apigateway:UpdateRestApi:用于更新API的名称、标签等配置
  • apigateway:UpdateAccount:用于修改API Gateway账户的CloudWatch角色关联(对应aws_api_gateway_account资源的更新操作)
  • apigateway:DeleteRestApi:(可选)如果需要销毁API资源时添加

额外注意

如果补充权限后仍出现403错误,需检查权限策略的资源范围是否覆盖目标API及账户资源,建议将资源设置为:

  • REST API相关:arn:aws:apigateway:*::/restapis/*
  • 账户配置相关:arn:aws:apigateway:*::/account

内容的提问来源于stack exchange,提问作者CyberPunk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 08:22:59