AWS Greengrass V2批量配置IoT策略部署失败问题排查
问题背景
我在已开放所需端口的EC2实例上配置AWS Greengrass V2批量部署,证书已生成且核心设备完成注册。为满足生产安全要求,采用了Greengrass核心最小IoT策略,具体策略如下:
{ "Statement": [ { "Action": [ "iot:Publish", "iot:Subscribe", "iot:Receive", "iot:Connect" ], "Effect": "Allow", "Resource": [ "arn:aws:iot:eu-central-1:123123123123:topic/data/${iot:Connection.Thing.ThingName}/*", "arn:aws:iot:eu-central-1:123123123123:topic/cmd/${iot:Connection.Thing.ThingName}/*" ] }, { "Action": [ "iot:Connect" ], "Effect": "Allow", "Resource": "arn:aws:iot:eu-central-1:123123123123:client/${iot:Connection.Thing.ThingName}*" }, { "Action": [ "iot:Subscribe" ], "Effect": "Allow", "Resource": [ "arn:aws:iot:eu-central-1:123123123123:topicfilter/$aws/things/${iot:Connection.Thing.ThingName}*/jobs/*", "arn:aws:iot:eu-central-1:123123123123:topicfilter/$aws/things/${iot:Connection.Thing.ThingName}*/shadow/*" ] }, { "Action": [ "iot:Receive", "iot:Publish" ], "Effect": "Allow", "Resource": [ "arn:aws:iot:eu-central-1:123123123123:topic/$aws/things/${iot:Connection.Thing.ThingName}*/greengrass/health/json", "arn:aws:iot:eu-central-1:123123123123:topic/$aws/things/${iot:Connection.Thing.ThingName}*/greengrassv2/health/json", "arn:aws:iot:eu-central-1:123123123123:topic/$aws/things/${iot:Connection.Thing.ThingName}*/jobs/*", "arn:aws:iot:eu-central-1:123123123123:topic/$aws/things/${iot:Connection.Thing.ThingName}*/shadow/*" ] }, { "Action": [ "greengrass:ResolveComponentCandidates", "greengrass:Get*", "greengrass:List*", "greengrass:Describe*", "greengrass:Resolve*", "greengrass:PutCertificateAuthorities" ], "Effect": "Allow", "Resource": "*" }, { "Action": "iot:AssumeRoleWithCertificate", "Effect": "Allow", "Resource": "arn:aws:iot:eu-central-1:123123123123:rolealias/TerraformGreengrassCoreTokenExchangeRoleAlias" } ], "Version": "2012-10-17" }
核心设备无法接收Thing Group的部署,且频繁断开连接,日志片段如下:
[...] 2023-01-05T08:58:18.602Z [DEBUG] (pool-2-thread-37) com.aws.greengrass.mqttclient.AwsIotMqttClient: Subscribing to topic. {clientId=TestCustomerCoreDevice, qos=AT_LEAST_ONCE, topic=$aws/things/TestCustomerCoreDevice/jobs/12312397-1d2d-1d2d-1d2d-01de629ddcf2/namespace-aws-gg-deployment/update/rejected} com.aws.greengrass.mqtt.bridge.clients.MQTTClient: Unable to connect. Will be retried after 120 seconds [...]
将订阅权限放宽到"arn:aws:iot:eu-central-1:123123123123:*"可正常工作,但不符合生产安全要求。推测问题与$aws前缀的topicfilter资源有关,但无法定位具体原因。权限放宽后可正常订阅data/TestCustomerCoreDevice/test主题,求最小权限下的解决办法。
解决方案
问题出在IoT策略中topicfilter的资源匹配规则,原策略里的${iot:Connection.Thing.ThingName}*多了一个通配符*,导致无法精确匹配设备的Thing名称(比如你的设备是TestCustomerCoreDevice,没有后缀)。
需要调整策略中以下两处的资源:
- **订阅权限(iot:Subscribe)**的topicfilter资源,去掉ThingName后的
* - **收发权限(iot:Receive/iot:Publish)**的topic资源,同样去掉ThingName后的
*
调整后的完整策略如下:
{ "Statement": [ { "Action": [ "iot:Publish", "iot:Subscribe", "iot:Receive", "iot:Connect" ], "Effect": "Allow", "Resource": [ "arn:aws:iot:eu-central-1:123123123123:topic/data/${iot:Connection.Thing.ThingName}/*", "arn:aws:iot:eu-central-1:123123123123:topic/cmd/${iot:Connection.Thing.ThingName}/*" ] }, { "Action": [ "iot:Connect" ], "Effect": "Allow", "Resource": "arn:aws:iot:eu-central-1:123123123123:client/${iot:Connection.Thing.ThingName}*" }, { "Action": [ "iot:Subscribe" ], "Effect": "Allow", "Resource": [ "arn:aws:iot:eu-central-1:123123123123:topicfilter/$aws/things/${iot:Connection.Thing.ThingName}/jobs/*", "arn:aws:iot:eu-central-1:123123123123:topicfilter/$aws/things/${iot:Connection.Thing.ThingName}/shadow/*" ] }, { "Action": [ "iot:Receive", "iot:Publish" ], "Effect": "Allow", "Resource": [ "arn:aws:iot:eu-central-1:123123123123:topic/$aws/things/${iot:Connection.Thing.ThingName}/greengrass/health/json", "arn:aws:iot:eu-central-1:123123123123:topic/$aws/things/${iot:Connection.Thing.ThingName}/greengrassv2/health/json", "arn:aws:iot:eu-central-1:123123123123:topic/$aws/things/${iot:Connection.Thing.ThingName}/jobs/*", "arn:aws:iot:eu-central-1:123123123123:topic/$aws/things/${iot:Connection.Thing.ThingName}/shadow/*" ] }, { "Action": [ "greengrass:ResolveComponentCandidates", "greengrass:Get*", "greengrass:List*", "greengrass:Describe*", "greengrass:Resolve*", "greengrass:PutCertificateAuthorities" ], "Effect": "Allow", "Resource": "*" }, { "Action": "iot:AssumeRoleWithCertificate", "Effect": "Allow", "Resource": "arn:aws:iot:eu-central-1:123123123123:rolealias/TerraformGreengrassCoreTokenExchangeRoleAlias" } ], "Version": "2012-10-17" }
补充说明
- Greengrass核心设备订阅部署相关的Job主题时,使用的是精确的Thing名称(无后缀),原策略中的
${iot:Connection.Thing.ThingName}*会匹配带后缀的名称,导致权限不匹配 - 保留
client资源中的*是合理的,因为Greengrass可能会在clientId后添加随机后缀用于重连 - 调整后策略仍保持最小权限,仅允许设备访问自身相关的IoT主题和Greengrass资源
内容的提问来源于stack exchange,提问作者DK_kbc
相关产品推荐
相关产品推荐

