You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab Runner部署Terraform遇Route53:ListHostedZones权限拒绝问题

问题解决:Route53 ListHostedZones 权限拒绝错误

问题根源

route53:ListHostedZones 是Route53的全局列表类操作,这类操作不支持AWS资源级权限控制。你当前的IAM策略中,虽然配置了Action: "*",但绑定的Resource是arn:aws:route53:::*,而该操作无法识别这种资源指定,导致权限验证失败。

修正后的IAM策略

需要单独为route53:ListHostedZones添加允许规则,指定Resource: "*",或者调整原有策略的资源范围,示例如下:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "AllowRoute53ListActions",
            "Effect": "Allow",
            "Action": "route53:ListHostedZones",
            "Resource": "*"
        },
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": "*",
            "Resource": [                
                "arn:aws:route53:::*",
                "arn:aws:acm:us-east-1:12345678:certificate/*"
            ]
        }
    ]
}

补充说明

AWS中大部分以List、Describe开头的全局操作,都不支持资源级权限,必须将Resource设为*才能让权限规则生效。如果不想过度授权,也可以单独列出需要的List类Action,而非直接用*覆盖所有操作。

内容的提问来源于stack exchange,提问作者LP13

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 09:11:31