使用Terraform在AWS免费试用账户中创建VPC时执行Terraform apply命令遇403权限错误求助
Yes, I’ve run into this exact issue with AWS Free Tier accounts when using Terraform to provision VPCs! Let me walk through the most common causes and fixes that worked for me and others in the community:
IAM Permissions Mismatch: Even if you think your credentials are correct, the IAM user/role you’re using might not have the necessary permissions to create a VPC. Free Tier accounts don’t restrict VPC creation by default, but your IAM entity needs at least
ec2:CreateVpcpermission, plus related ones likeec2:CreateSubnet(if you’re creating subnets alongside it),ec2:CreateInternetGateway, etc. Double-check your IAM policy to make sure it includes these actions.Decode the Authorization Failure Message: That long encoded string in your error isn’t useless—you can get a detailed breakdown of why the auth failed with the AWS CLI. Run this command:
aws sts decode-authorization-message --encoded-message 4HZVo3-eWCS-YLhRy55P_0T13F_fPtA29TYrJrSe5_dyPxIcqRbh7_wCcrCZr2cpmb-B5--_fxVaOngBfHD_7yfnPH7NLf1rrqpb7ge1mvQrK8P0Ltfpgpm37nZXezZUoYf1t4peB25aCxnbfeboHpgJjcFnHvqvf5so5G2PufnGZSB4FUZMfdaqppnJ-sNT7b36TonHUDNbLhBVUl5Fwd8d02R-6ZraRYvDx-o4lDfP9xSWs6PMUFXNr1qzruYaeMYMxIe-9kGOQptgBLYZXsxr966ajor-p6aLJAKlIwPGN7Iz7v893oGpGgz_8wxTv4oEb5GnfYOuPOqSyEMLKI69b2JUvVU1m4tCcjKBaHJARP5sIiFSGhh4lb_E0_cKkmmFfKzyET2h8YkSD8U9Lm4rRtGbAEJvIoDZYDkNxlW7W2XvsccmLnQFeSxpLolVhguExkP7DT9uXffJzFEjQn-VkhqKnWlwv0vxIcOcoLP04Li5WAqRRr3l7yK2bYznfgThis will output a human-readable explanation of exactly which permission is missing or what restriction is blocking your operation.
Free Tier Quota Check: AWS Free Tier allows 1 VPC per region by default, plus 5 subnets, 1 internet gateway, etc. If you’ve already created a VPC in the same region via the AWS Console or another tool, you might be hitting that limit. Head over to your EC2 Dashboard’s VPC section to check for existing resources using up your quota.
Verify Terraform’s Credential Context: Sometimes Terraform is using a different AWS profile or credentials than you expect. Run
terraform consoleand enterdata.aws_caller_identity.current(if you’ve defined this data source in your config) to confirm which account and user Terraform is authenticating as. You can also check your~/.aws/credentialsfile or environment variables to ensure you’re pointing to your Free Tier account’s credentials.
In my case, decoding the message revealed my IAM policy was missing ec2:CreateInternetGateway—a permission my Terraform VPC module was trying to use. Adding that to the policy fixed the 403 error immediately.
内容的提问来源于stack exchange,提问作者Tech knowledge

