You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IAM创建角色报错MalformedPolicyDocument:AssumeRole策略仅允许STS AssumeRole操作

问题原因与解决方案

你混淆了IAM角色的信任策略和权限策略的作用:

  • 信任策略(即你通过--assume-role-policy-document指定的文档)仅用于定义哪些实体可以扮演该角色,因此动作只能是sts:AssumeRole,不能包含autoscaling、ec2这类其他服务的API操作。
  • 你需要的autoscaling和ec2操作权限,应该写入权限策略,之后再附加到角色上,而非塞进信任策略。

正确操作步骤

1. 编写正确的信任策略(IAM_Trust_Policy.json)

该文档仅负责授权指定服务扮演角色:

{
    "Version": "2012-10-17",
    "Statement": {
        "Effect": "Allow",
        "Principal": {
            "Service": [
                "ec2.amazonaws.com",
                "autoscaling.amazonaws.com"
            ]   
        },
        "Action": "sts:AssumeRole"
    }
}

2. 创建角色

使用上述信任策略执行创建命令:

aws iam create-role --role-name AutoscalingRole-Name --assume-role-policy-document file://./IAM_Trust_Policy.json

3. 编写权限策略(示例命名为Autoscaling_Permissions_Policy.json)

将你需要的操作权限写入此文档:

{
    "Version": "2012-10-17",
    "Statement": {
        "Effect": "Allow",
        "Action": [
            "autoscaling:DescribeAutoScalingGroups",
            "autoscaling:DescribeAutoScalingInstances",
            "autoscaling:DescribeLaunchConfigurations",
            "autoscaling:DescribeTags",
            "autoscaling:SetDesiredCapacity",
            "autoscaling:TerminateInstanceInAutoScalingGroup",
            "ec2:DescribeLaunchTemplateVersions"
        ],
        "Resource": "*"
    }
}

4. 给角色附加权限策略

执行以下命令将权限策略绑定到已创建的角色:

aws iam put-role-policy --role-name AutoscalingRole-Name --policy-name AutoscalingPermissions --policy-document file://./Autoscaling_Permissions_Policy.json

完成以上操作后,你的Auto Scaling角色将同时拥有正确的信任关系和所需的操作权限。

内容的提问来源于stack exchange,提问作者Miloš Milutinov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 21:45:29