You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

从Power BI连接Athena时遇AccessDeniedException权限错误求助

解决Power BI连接Athena的Glue权限问题

错误信息

ODBC: ERROR [HY000] [Simba][Athena] (1041) An error has been thrown from the AWS Glue client. Athena Error No: 15, HTTP Response Code: 400, Exception Name: AccessDeniedException, Error Message: User: arn:aws:iam::006244860144:user/amls-athenabi-user-dev is not authorized to perform: glue:GetDatabases on resource: arn:aws:glue:us-east-1:xxxxxxx:catalog because no identity-based policy allows the glue:GetDatabases action.

问题分析

错误明确指出IAM用户缺少*glue:GetDatabases*权限,查看提供的IAM策略,所有允许的Glue操作列表中均未包含该动作,导致Power BI连接Athena时无法获取Glue数据库列表,触发权限拒绝错误。

解决方案

需要在IAM策略中添加glue:GetDatabases权限,推荐将其加入VisualEditor1语句组(该组资源范围为*,且已包含其他Glue数据库/表相关操作),修改后的完整策略如下:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "glue:BatchCreatePartition",
                "athena:StartQueryExecution",
                "glue:GetPartitions",
                "s3:GetObjectVersionTagging",
                "glue:UpdateTable",
                "athena:GetQueryResults",
                "glue:DeleteTable",
                "s3:GetStorageLensConfigurationTagging",
                "s3:GetObjectAcl",
                "s3:GetBucketObjectLockConfiguration",
                "s3:GetIntelligentTieringConfiguration",
                "athena:StopQueryExecution",
                "s3:GetObjectVersionAcl",
                "s3:GetBucketPolicyStatus",
                "glue:UpdateDatabase",
                "athena:GetQueryResultsStream",
                "s3:GetObjectRetention",
                "glue:CreateTable",
                "glue:GetTables",
                "s3:GetBucketWebsite",
                "s3:GetJobTagging",
                "s3:GetMultiRegionAccessPoint",
                "s3:GetObjectAttributes",
                "s3:GetObjectLegalHold",
                "s3:GetBucketNotification",
                "s3:DescribeMultiRegionAccessPointOperation",
                "s3:GetReplicationConfiguration",
                "s3:ListMultipartUploadParts",
                "s3:PutObject",
                "s3:GetObject",
                "glue:GetPartition",
                "s3:DescribeJob",
                "glue:BatchDeleteTable",
                "s3:GetAnalyticsConfiguration",
                "s3:GetObjectVersionForReplication",
                "glue:DeletePartition",
                "s3:GetAccessPointForObjectLambda",
                "athena:BatchGetQueryExecution",
                "s3:GetStorageLensDashboard",
                "s3:GetLifecycleConfiguration",
                "s3:GetInventoryConfiguration",
                "s3:GetBucketTagging",
                "glue:DeleteDatabase",
                "s3:GetAccessPointPolicyForObjectLambda",
                "glue:BatchDeletePartition",
                "s3:GetBucketLogging",
                "s3:ListBucketVersions",
                "s3:ListBucket",
                "s3:GetAccelerateConfiguration",
                "s3:GetObjectVersionAttributes",
                "s3:GetBucketPolicy",
                "athena:ListQueryExecutions",
                "s3:GetEncryptionConfiguration",
                "s3:GetObjectVersionTorrent",
                "s3:AbortMultipartUpload",
                "s3:GetBucketRequestPayment",
                "s3:GetAccessPointPolicyStatus",
                "s3:GetObjectTagging",
                "glue:CreatePartition",
                "s3:GetMetricsConfiguration",
                "s3:GetBucketOwnershipControls",
                "glue:UpdatePartition",
                "s3:GetBucketPublicAccessBlock",
                "s3:GetMultiRegionAccessPointPolicyStatus",
                "s3:ListBucketMultipartUploads",
                "s3:GetMultiRegionAccessPointPolicy",
                "s3:GetAccessPointPolicyStatusForObjectLambda",
                "glue:BatchGetPartition",
                "s3:GetBucketVersioning",
                "s3:GetBucketAcl",
                "s3:GetAccessPointConfigurationForObjectLambda",
                "glue:GetTable",
                "glue:GetDatabase",
                "s3:GetObjectTorrent",
                "s3:GetMultiRegionAccessPointRoutes",
                "s3:GetStorageLensConfiguration",
                "glue:CreateDatabase",
                "athena:GetQueryExecution",
                "s3:GetBucketCORS",
                "s3:GetBucketLocation",
                "s3:GetAccessPointPolicy",
                "s3:GetObjectVersion"
            ],
            "Resource": [
                "arn:aws:athena:us-east-1:xxxxxxx:workgroup/primary",
                "arn:aws:glue:us-east-1:xxxxxxx:catalog",
                "arn:aws:s3:::datos-parquet-desarrollo"
            ]
        },
        {
            "Sid": "VisualEditor1",
            "Effect": "Allow",
            "Action": [
                "glue:GetDatabases",
                "glue:BatchCreatePartition",
                "glue:UpdateDatabase",
                "glue:CreateTable",
                "glue:DeleteDatabase",
                "glue:GetTables",
                "glue:GetPartitions",
                "glue:BatchDeletePartition",
                "glue:UpdateTable",
                "glue:BatchGetPartition",
                "glue:DeleteTable",
                "glue:GetTable",
                "glue:GetDatabase",
                "glue:GetPartition",
                "glue:CreateDatabase",
                "glue:BatchDeleteTable",
                "glue:CreatePartition",
                "glue:DeletePartition",
                "glue:UpdatePartition"
            ],
            "Resource": "*"
        },
        {
            "Sid": "VisualEditor2",
            "Effect": "Allow",
            "Action": [
                "s3:ListStorageLensConfigurations",
                "s3:ListAccessPointsForObjectLambda",
                "s3:GetAccessPoint",
                "s3:GetAccountPublicAccessBlock",
                "s3:ListAllMyBuckets",
                "s3:ListAccessPoints",
                "s3:ListJobs",
                "s3:ListMultiRegionAccessPoints"
            ],
            "Resource": "arn:aws:glue:us-east-1:xxxxxxxx:catalog"
        }
    ]
}

修改说明

  • 在VisualEditor1的Action数组开头添加"glue:GetDatabases",确保用户拥有获取Glue数据库列表的核心权限
  • 该语句组的Resource为*,覆盖所有Glue资源,匹配Power BI连接Athena时的权限访问范围

验证步骤

  • 将修改后的策略更新至目标IAM用户
  • 等待1-2分钟让IAM策略生效
  • 重新发起Power BI与Athena的连接,确认权限错误已消除

内容的提问来源于stack exchange,提问作者Douglas Guzman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 01:05:23