You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform创建KMS密钥时提示策略含无效主体,请帮忙审核策略

问题

使用Terraform创建AWS KMS密钥时,执行terraform apply报错:Policy contains a statement with one or more invalid principals

相关调试日志:

-----------------------------------------------------: timestamp=2023-03-29T17:08:19.091Z
     2023-03-29T17:08:19.091Z [DEBUG] provider.terraform-provider-aws_v4.0.0_x5: [aws-sdk-go] {"__type":"MalformedPolicyDocumentException","message":"Policy contains a statement with one or more invalid principals."}: timestamp=2023-03-29T17:08:19.091Z
     2023-03-29T17:08:19.091Z [DEBUG] provider.terraform-provider-aws_v4.0.0_x5: [aws-sdk-go] DEBUG: Validate Response kms/CreateKey failed, attempt 0/25, error MalformedPolicyDocumentException: Policy contains a statement with one or more invalid principals.: timestamp=2023-03-29T17:08:19.091Z
     2023-03-29T17:08:23.094Z [DEBUG] provider.terraform-provider-aws_v4.0.0_x5: [aws-sdk-go] DEBUG: Request kms/CreateKey Details:

对应的KMS密钥策略:

{
  "Statement": [
    {
      "Action": "kms:*",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::<account-id>:root"
      },
      "Resource": "*",
      "Sid": "Allow key administration to the Account."
    },
    {
      "Action": [
        "kms:Encrypt",
        "kms:Decrypt",
        "kms:ReEncrypt*",
        "kms:GenerateDataKey*",
        "kms:DescribeKey",
        "kms:List*"
      ],
      "Condition": {
        "StringEquals": {
          "aws:SourceAccount": "<account-id>"
        }
      },
      "Effect": "Allow",
      "Principal": {
        "Service": "sqs.amazonaws.com"
      },
      "Resource": "*",
      "Sid": "Allow SQS to use the key"
    },
    {
      "Action": [
        "kms:Encrypt",
        "kms:Decrypt",
        "kms:ReEncrypt*",
        "kms:GenerateDataKey*",
        "kms:DescribeKey",
        "kms:List*"
      ],
      "Condition": {
        "StringEquals": {
          "aws:SourceAccount": "<account-id>"
        }
      },
      "Effect": "Allow",
      "Principal": {
        "Service": "s3.amazonaws.com"
      },
      "Resource": "*",
      "Sid": "Allow S3 to use the key"
    },
    {
      "Action": [
        "kms:Encrypt",
        "kms:Decrypt",
        "kms:ReEncrypt*",
        "kms:GenerateDataKey*",
        "kms:DescribeKey",
        "kms:List*"
      ],
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::<account-id>:role/data-monitoring-service-account"
      },
      "Resource": "*",
      "Sid": "Allow IAM role to use the key"
    },
    {
      "Action": [
        "kms:Encrypt",
        "kms:Decrypt",
        "kms:ReEncrypt*",
        "kms:GenerateDataKey*",
        "kms:DescribeKey",
        "kms:List*"
      ],
      "Condition": {
        "StringEquals": {
          "aws:SourceAccount": "<account-id>"
        }
      },
      "Effect": "Allow",
      "Principal": {
        "Service": "ec2.amazonaws.com"
      },
      "Resource": "*",
      "Sid": "Allow EC2 to use the key"
    },
    {
      "Action": [
        "kms:Encrypt",
        "kms:Decrypt",
        "kms:ReEncrypt*",
        "kms:GenerateDataKey*",
        "kms:DescribeKey",
        "kms:List*"
      ],
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::<account-id>:role/af-service-account"
      },
      "Resource": "*",
      "Sid": "Allow IAM role to use the key"
    }
  ],
  "Version": "2008-10-17"
}

其中<account-id>为类似074150055827的AWS账号ID,需定位报错原因。


报错原因及修复方案

核心报错原因

策略中Sid为Allow EC2 to use the key的语句存在无效Principal:ec2.amazonaws.com。EC2服务本身不会直接以服务身份调用KMS,AWS不允许将该服务主体直接配置在KMS策略中,因此触发MalformedPolicyDocumentException错误。

修复步骤

  1. 移除无效的EC2服务主体语句:删除整个Sid为Allow EC2 to use the key的Statement。
  2. 授权EC2实例访问(若需要):如果要让EC2实例使用该KMS密钥,改为授权实例关联的IAM角色,添加类似其他IAM角色的Statement(注意设置唯一的Sid)。
  3. 修正重复的Sid:当前策略中有两个Statement使用相同的SidAllow IAM role to use the key,需改为唯一标识,例如Allow data-monitoring-service-account role to use the key和Allow af-service-account role to use the key。
  4. 优化Resource配置(可选):将策略中的Resource字段从*改为当前KMS密钥的ARN(可通过Terraform变量动态引用),提升配置安全性。

内容的提问来源于stack exchange,提问作者Lesha Pipiev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 08:37:02