Terraform创建KMS密钥时提示策略含无效主体,请帮忙审核策略
问题
使用Terraform创建AWS KMS密钥时,执行terraform apply报错:Policy contains a statement with one or more invalid principals
相关调试日志:
-----------------------------------------------------: timestamp=2023-03-29T17:08:19.091Z 2023-03-29T17:08:19.091Z [DEBUG] provider.terraform-provider-aws_v4.0.0_x5: [aws-sdk-go] {"__type":"MalformedPolicyDocumentException","message":"Policy contains a statement with one or more invalid principals."}: timestamp=2023-03-29T17:08:19.091Z 2023-03-29T17:08:19.091Z [DEBUG] provider.terraform-provider-aws_v4.0.0_x5: [aws-sdk-go] DEBUG: Validate Response kms/CreateKey failed, attempt 0/25, error MalformedPolicyDocumentException: Policy contains a statement with one or more invalid principals.: timestamp=2023-03-29T17:08:19.091Z 2023-03-29T17:08:23.094Z [DEBUG] provider.terraform-provider-aws_v4.0.0_x5: [aws-sdk-go] DEBUG: Request kms/CreateKey Details:
对应的KMS密钥策略:
{ "Statement": [ { "Action": "kms:*", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::<account-id>:root" }, "Resource": "*", "Sid": "Allow key administration to the Account." }, { "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey", "kms:List*" ], "Condition": { "StringEquals": { "aws:SourceAccount": "<account-id>" } }, "Effect": "Allow", "Principal": { "Service": "sqs.amazonaws.com" }, "Resource": "*", "Sid": "Allow SQS to use the key" }, { "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey", "kms:List*" ], "Condition": { "StringEquals": { "aws:SourceAccount": "<account-id>" } }, "Effect": "Allow", "Principal": { "Service": "s3.amazonaws.com" }, "Resource": "*", "Sid": "Allow S3 to use the key" }, { "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey", "kms:List*" ], "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::<account-id>:role/data-monitoring-service-account" }, "Resource": "*", "Sid": "Allow IAM role to use the key" }, { "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey", "kms:List*" ], "Condition": { "StringEquals": { "aws:SourceAccount": "<account-id>" } }, "Effect": "Allow", "Principal": { "Service": "ec2.amazonaws.com" }, "Resource": "*", "Sid": "Allow EC2 to use the key" }, { "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey", "kms:List*" ], "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::<account-id>:role/af-service-account" }, "Resource": "*", "Sid": "Allow IAM role to use the key" } ], "Version": "2008-10-17" }
其中<account-id>为类似074150055827的AWS账号ID,需定位报错原因。
报错原因及修复方案
核心报错原因
策略中Sid为Allow EC2 to use the key的语句存在无效Principal:ec2.amazonaws.com。EC2服务本身不会直接以服务身份调用KMS,AWS不允许将该服务主体直接配置在KMS策略中,因此触发MalformedPolicyDocumentException错误。
修复步骤
- 移除无效的EC2服务主体语句:删除整个Sid为
Allow EC2 to use the key的Statement。 - 授权EC2实例访问(若需要):如果要让EC2实例使用该KMS密钥,改为授权实例关联的IAM角色,添加类似其他IAM角色的Statement(注意设置唯一的Sid)。
- 修正重复的Sid:当前策略中有两个Statement使用相同的Sid
Allow IAM role to use the key,需改为唯一标识,例如Allow data-monitoring-service-account role to use the key和Allow af-service-account role to use the key。 - 优化Resource配置(可选):将策略中的
Resource字段从*改为当前KMS密钥的ARN(可通过Terraform变量动态引用),提升配置安全性。
内容的提问来源于stack exchange,提问作者Lesha Pipiev
相关产品推荐
相关产品推荐

