You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Elemental MediaConvert:Cognito未授权用户执行操作遭权限拒绝

AWS Elemental MediaConvert 转码作业权限问题排查

问题背景

我尝试通过代码创建AWS Elemental MediaConvert作业,转码S3存储桶中的视频文件,后端代码如下:

const client = new MediaConvertClient({
  region: 'us-east-1',
  endpoint: 'https://abcdefghi.mediaconvert.us-east-1.amazonaws.com',
  credentials: fromCognitoIdentityPool({
    clientConfig: { region: 'us-east-1' },
    identityPoolId: 'us-east-1:xxxx-xxx-xxx-xxx-xxxxxxx',
  })
});
const command = new CreateJobCommand(job);
const response = await client.send(command);

我使用控制台中已成功完成的作业JSON作为job参数,运行时先出现第一个权限错误:

Error: AccessDeniedException: User: arn:aws:sts::XXXXX:assumed-role/Cognito_MyAppElementalMediaConverterUnauth_Role/CognitoIdentityCredentials is not authorized to perform: mediaconvert:CreateJob on resource: *

为MediaConvertClient添加endpoint URI后认证成功,但又触发新的权限错误:

AccessDeniedException: User: arn:aws:sts::XXXXXXX:assumed-role/Cognito_MyAppeElementalMediaaConverterUnauth_Role/CognitoIdentityCredentials is not authorized to perform: iam:PassRole on resource: arn:aws:iam::XXXXX:role/*

已为Cognito_MyAppeElementalMediaaConverterUnauth_Role添加对应权限,但问题仍存在。


解决方案

1. 修复 mediaconvert:CreateJob 权限

确保Cognito未授权角色(Cognito_MyAppElementalMediaConverterUnauth_Role)附加的IAM策略包含mediaconvert:CreateJob权限,示例策略如下:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "mediaconvert:CreateJob",
      "Resource": "*"
    }
  ]
}

如果作业指定了特定队列,可将资源范围限定为队列ARN(如arn:aws:mediaconvert:us-east-1:XXXXX:queues/your-queue-name),提升权限安全性。

2. 修复 iam:PassRole 权限

这个错误源于MediaConvert作业需要使用独立IAM角色访问S3等资源,而你的Cognito角色需要被允许将该角色传递给MediaConvert服务,需重点检查以下几点:

  • 角色名称拼写:确认报错中的角色名Cognito_MyAppeElementalMediaaConverterUnauth_Role与控制台实际角色名一致(注意MyAppe/Mediaa可能是笔误),确保权限附加到了正确角色。
  • 限定资源范围:不要使用通配符*,将iam:PassRole的资源限定为MediaConvert作业实际使用的角色ARN,并添加服务条件限制,示例策略:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "iam:PassRole",
      "Resource": "arn:aws:iam::XXXXX:role/MediaConvertAccessRole",
      "Condition": {
        "StringEquals": {
          "iam:PassedToService": "mediaconvert.amazonaws.com"
        }
      }
    }
  ]
}
  • 作业配置中的角色ARN:检查复制的job参数里Role字段是否指向正确的IAM角色,且该角色拥有访问S3输入/输出桶的权限。
  • MediaConvert角色的信任关系:确保MediaConvert使用的角色的信任策略允许mediaconvert.amazonaws.com作为信任实体,示例信任策略:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Service": "mediaconvert.amazonaws.com"
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

额外检查项

  • 验证MediaConvert endpoint URI正确性:可通过AWS CLI命令aws mediaconvert describe-endpoints --region us-east-1获取官方端点。
  • 等待权限生效:IAM策略更新后通常需要1-5分钟才能全局生效,请勿立即重试。
  • 确认Cognito身份池配置:确保未授权用户对应的角色是你配置了权限的角色,避免角色关联错误。

内容的提问来源于stack exchange,提问作者dzona

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 13:40:36