调用DescribeLaunchTemplates遇UnauthorizedOperation错误的IAM权限排查
问题:Ansible部署AWS启动模板时IAM权限不足报错
执行的Ansible脚本
- name: base64 conversion command: base64 -w 0 roles/inspect/tasks/user_data_cs.sh register: userdata - debug: var: userdata.stdout #To deploy the user data in lauch template - name: User data deployment ec2_launch_template: name: "{{ LT_name }}" image_id: "ami-##########" key_name: "aws-dev" block_device_mappings: - device_name: "/dev/sdb" ebs: volume_size: 20 encrypted: true - device_name: "/dev/xvda" ebs: volume_size: 10 volume_type: gp2 delete_on_termination: yes encrypted: true default_version: 1 ebs_optimized: no iam_instance_profile: "aws-ec2-role" network_interfaces: - device_index : 0 delete_on_termination: yes associate_public_ip_address: no groups: ["sg-##########"] instance_type: t3.small user_data: "{{ userdata.stdout }}" when: name_env == "dev"
执行时的错误信息
TASK [inspect : User data deployment] ****************************************** An exception occurred during task execution. To see the full traceback, use -vvv. The error was: botocore.exceptions.ClientError: An error occurred (UnauthorizedOperation) when calling the DescribeLaunchTemplates operation: You are not authorized to perform this operation. [WARNING]: The value 1 (type int) in a string field was converted to '1' (type string). If this does not look like what you expect, quote the entire value to ensure it does not change. fatal: [127.0.0.1]: FAILED! => {"boto3_version": "1.24.38", "botocore_version": "1.27.38", "changed": false, "error": {"code": "UnauthorizedOperation", "message": "You are not authorized to perform this operation."}, "msg": "Could not check existing launch templates. This may be an IAM permission problem.: An error occurred (UnauthorizedOperation) when calling the DescribeLaunchTemplates operation: You are not authorized to perform this operation.", "response_metadata": {"http_headers": {"cache-control": "no-cache, no-store", "content-type": "text/xml;charset=UTF-8", "date": "Thu, 05 Jan 2023 13:17:02 GMT", "server": "AmazonEC2", "strict-transport-security": "max-age=31536000; includeSubDomains", "transfer-encoding": "chunked", "vary": "accept-encoding", "x-amzn-requestid": "c0cd0411-c88e-4569-bd91-21dd46708224"}, "http_status_code": 403, "request_id": "c0cd0411-c88e-4569-bd91-21dd46708224", "retry_attempts": 0}}
当前IAM权限配置
我配置了两个IAM策略:
第一个策略:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "elasticloadbalancing:DescribeLoadBalancers", "autoscaling:UpdateAutoScalingGroup", "autoscaling:CreateOrUpdateTags" ], "Resource": "*" } ] }
第二个策略:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "application-autoscaling:RegisterScalableTarget", "application-autoscaling:DeleteScheduledAction", "application-autoscaling:DescribeScalableTargets", "application-autoscaling:DeleteScalingPolicy", "elasticloadbalancing:DescribeLoadBalancers", "autoscaling:DescribeAutoScalingGroups", "application-autoscaling:DescribeScalingActivities", "application-autoscaling:DescribeScalingPolicies", "application-autoscaling:PutScalingPolicy", "elasticloadbalancing:DescribeTargetGroups", "autoscaling:DescribeLoadBalancerTargetGroups", "application-autoscaling:DescribeScheduledActions", "application-autoscaling:PutScheduledAction", "application-autoscaling:DeregisterScalableTarget" ], "Resource": "*" } ] }
疑问
我发现IAM中找不到DescribeLaunchTemplate动作,尝试添加autoscaling:DescribeLaunchTemplate、elasticloadbalancing:DescribeLaunchTemplate、application-autoscaling:DescribeLaunchTemplate以及单独的DescribeLaunchTemplate都无效,请问该怎么配置正确的IAM权限解决这个问题?
解决方案
Launch Template是EC2服务下的资源,对应的IAM动作前缀为ec2:,而非autoscaling:或其他服务前缀。需要添加以下权限到IAM策略中:
必要权限清单
ec2:DescribeLaunchTemplates:Ansible的ec2_launch_template模块执行时会先检查现有启动模板,必须拥有该权限ec2:CreateLaunchTemplate:用于创建新的启动模板ec2:ModifyLaunchTemplate:用于更新已有的启动模板ec2:DescribeLaunchTemplateVersions:模块可能需要查询启动模板的版本信息
更新后的IAM策略示例
可以新增一个策略,或者将权限合并到现有策略中:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ec2:DescribeLaunchTemplates", "ec2:CreateLaunchTemplate", "ec2:ModifyLaunchTemplate", "ec2:DescribeLaunchTemplateVersions" ], "Resource": "*" } ] }
补充说明
- 如果需要更精细的权限控制,可以将
Resource指定为具体的启动模板ARN,格式为arn:aws:ec2:区域ID:账号ID:launch-template/模板名称 - 权限更新后,需确保IAM实体(用户/角色)已正确关联策略,策略生效通常需要1-5分钟
内容的提问来源于stack exchange,提问作者niitinkalburgi
相关产品推荐
相关产品推荐

