You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS CDK部署AppSync栈时出现IAM策略主体无效错误

AWS CDK部署含AppSync的栈时IAM策略主体错误问题

部署包含AppSync的AWS CDK栈时,部分资源创建失败,CloudFormation控制台栈事件显示如下错误:

Invalid principal in policy: "SERVICE":"appsync" (Service: AmazonIdentityManagement; Status Code: 400; Error Code: MalformedPolicyDocument; Request ID: 8d98f07c-d717-4dfe-af96-14f2d72d993f; Proxy: null)

怀疑是清理个人开发者账号时误删了某些资源,但因AWS经验有限,不清楚需要补充创建什么资源,推测和IAM策略相关但不知道具体配置。

用cdk init sample-app --language=typescript创建的全新空白项目,直接运行cdk deploy可正常完成部署。最初使用cdk-appsync-transformer创建连接DynamoDB表的GraphQL端点时触发该错误,删除CDKToolkit CloudFormation栈后重新执行cdk bootstrap也无法解决问题。为排除第三方库影响,改用AWS官方的AppSync Construct Library,严格按照官方示例操作,仍出现相同错误(仅失败的资源类型不同)。

复现步骤

  • 创建新文件夹
  • 在文件夹内执行命令:cdk init sample-app --language=typescript
  • 安装AWS AppSync Construct Library:npm i @aws-cdk/aws-appsync-alpha@2.58.1-alpha.0 --save
  • 按AWS文档完成以下配置:
    • 创建lib/schema.graphql文件,内容如下:
type demo {
    id: String!
    version: String!
}
type Query {
    getDemos: [ demo! ]
}
input DemoInput {
    version: String!
}
type Mutation {
    addDemo(input: DemoInput!): demo
}
  • 更新lib/<projectName>-stack.ts文件为如下内容:
import * as appsync from '@aws-cdk/aws-appsync-alpha';
import { Duration, Stack, StackProps } from 'aws-cdk-lib';
import * as dynamodb from 'aws-cdk-lib/aws-dynamodb';
import * as sns from 'aws-cdk-lib/aws-sns';
import * as subs from 'aws-cdk-lib/aws-sns-subscriptions';
import * as sqs from 'aws-cdk-lib/aws-sqs';
import { Construct } from 'constructs';
import * as path from 'path';

export class CdkTest3Stack extends Stack {
    constructor(scope: Construct, id: string, props?: StackProps) {
        super(scope, id, props);

        const queue = new sqs.Queue(this, 'CdkTest3Queue', {
            visibilityTimeout: Duration.seconds(300)
        });

        const topic = new sns.Topic(this, 'CdkTest3Topic');

        topic.addSubscription(new subs.SqsSubscription(queue));

        const api = new appsync.GraphqlApi(this, 'Api', {
            name: 'demo',
            schema: appsync.SchemaFile.fromAsset(path.join(__dirname, 'schema.graphql')),
            authorizationConfig: {
                defaultAuthorization: {
                    authorizationType: appsync.AuthorizationType.IAM,
                },
            },
            xrayEnabled: true,
        });

        const demoTable = new dynamodb.Table(this, 'DemoTable', {
            partitionKey: {
                name: 'id',
                type: dynamodb.AttributeType.STRING,
            },
        });

        const demoDS = api.addDynamoDbDataSource('demoDataSource', demoTable);

        // Resolver for the Query "getDemos" that scans the DynamoDb table and returns the entire list.
        // Resolver Mapping Template Reference:
        // https://docs.aws.amazon.com/appsync/latest/devguide/resolver-mapping-template-reference-dynamodb.html
        demoDS.createResolver('QueryGetDemosResolver', {
            typeName: 'Query',
            fieldName: 'getDemos',
            requestMappingTemplate: appsync.MappingTemplate.dynamoDbScanTable(),
            responseMappingTemplate: appsync.MappingTemplate.dynamoDbResultList(),
        });

        // Resolver for the Mutation "addDemo" that puts the item into the DynamoDb table.
        demoDS.createResolver('MutationAddDemoResolver', {
            typeName: 'Mutation',
            fieldName: 'addDemo',
            requestMappingTemplate: appsync.MappingTemplate.dynamoDbPutItem(
                appsync.PrimaryKey.partition('id').auto(),
                appsync.Values.projecting('input'),
            ),
            responseMappingTemplate: appsync.MappingTemplate.dynamoDbResultItem(),
        });

        //To enable DynamoDB read consistency with the `MappingTemplate`:
        demoDS.createResolver('QueryGetDemosConsistentResolver', {
            typeName: 'Query',
            fieldName: 'getDemosConsistent',
            requestMappingTemplate: appsync.MappingTemplate.dynamoDbScanTable(true),
            responseMappingTemplate: appsync.MappingTemplate.dynamoDbResultList(),
        });
    }
}
  • 执行命令:cdk deploy

内容的提问来源于stack exchange,提问作者Jonathan L.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 12:45:37