You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用boto3将AMI共享至多个OrganizationARN?

如何通过boto3将AMI共享至多个AWS组织ARN

你尝试的代码逻辑是正确的,AWS EC2的modify_image_attribute API本身支持一次性添加多个组织ARN作为启动权限对象,只是boto3官方文档未给出多组织共享的示例。

正确代码示例

import boto3

# 定义要共享的多个AWS组织ARN
gr_org = [
    {'OrganizationArn': 'arn:aws:organizations::123456789:organization/o-123456789'},
    {'OrganizationArn': 'arn:aws:organizations::987654321:organization/o-987654321'}
]

# 初始化EC2客户端,替换为你的目标区域
ec2Client = boto3.client('ec2', region_name='us-east-1')

# 执行AMI共享操作,替换为你的AMI ID
ec2Client.modify_image_attribute(
    ImageId='ami-xxxxxxxxx',
    LaunchPermission={'Add': gr_org},
    OperationType='add',
    DryRun=False
)

验证共享结果

可以通过describe_image_attribute接口确认共享是否生效:

response = ec2Client.describe_image_attribute(
    ImageId='ami-xxxxxxxxx',
    Attribute='launchPermission'
)
# 打印所有拥有启动权限的实体
print(response['LaunchPermissions'])

注意事项

  • 执行代码的IAM身份必须具备ec2:ModifyImageAttribute权限
  • 确保目标AWS组织与当前账号之间存在有效的信任关系,否则共享操作可能失败

内容的提问来源于stack exchange,提问作者3ldud3r1n0

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 01:54:23