You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ECS服务启动任务失败:无法假定指定ExecutionRole角色求助

问题描述

部署包含ECS集群、服务和任务定义的CloudFormation模板时,服务启动任务失败,报错:

service ECSService failed to launch a task with (error ECS was unable to assume the role 'arn:aws:iam:::role/ExecutionRole' that was provided for this task. Please verify that the role being passed has the proper trust relationship and permissions and that your IAM user has permissions to pass this role.).

角色定义如下:

ExecutionRole:
  Type: AWS::IAM::Role
  Properties:
    RoleName: ExecutionRole
    AssumeRolePolicyDocument:
      Statement:
        - Effect: Allow
          Action: sts:AssumeRole
          Principal:
            Service: ecs-tasks.amazonaws.com
    ManagedPolicyArns:
      - arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy
    Path: /myroles

服务相关定义:

Cluster:
  Type: AWS::ECS::Cluster
  Properties:
    ClusterName: Cluster
Service:
  Type: AWS::ECS::Service
  DependsOn:
    - ExecutionRole
  Properties:
    Cluster: !Ref Cluster
    DesiredCount: 1
    LaunchType: FARGATE
    NetworkConfiguration:
      AwsvpcConfiguration:
        AssignPublicIp: ENABLED
        SecurityGroups:
          - !Ref SecurityGroup
        Subnets:
          - !Ref PublicSubnet
    ServiceName: ECSService
    TaskDefinition: !Ref TaskDefinition
TaskDefinition:
  Type: AWS::ECS::TaskDefinition
  Properties:
    ContainerDefinitions:
      - Name: Container
        Image: !Ref TaskImage
    Cpu: .25 vCPU
    ExecutionRoleArn: !Ref ExecutionRole
    Family: GoCapture
    Memory: 0.5 GB
    NetworkMode: awsvpc
    RuntimePlatform:
      CpuArchitecture: X86_64
      OperatingSystemFamily: LINUX

配置看似符合规范,但仍报错,请问忽略了什么?


问题排查与解决

检查以下几个核心关键点:

  1. ARN格式缺失账户ID
    报错中的角色ARN为arn:aws:iam:::role/ExecutionRole,中间缺少AWS账户ID(正确格式应为arn:aws:iam::123456789012:role/myroles/ExecutionRole)。这说明!Ref ExecutionRole未正确返回完整ARN,可尝试改用!GetAtt ExecutionRole.Arn显式获取角色ARN,确保路径/myroles被包含在内。

  2. IAM用户的角色传递权限
    部署CloudFormation栈的IAM用户必须拥有iam:PassRole权限,且资源范围需覆盖该ExecutionRole。需添加如下权限策略:

    {
      "Effect": "Allow",
      "Action": "iam:PassRole",
      "Resource": "arn:aws:iam::[你的账户ID]:role/myroles/ExecutionRole"
    }
    
  3. 显式设置任务定义的依赖关系
    虽然服务已依赖ExecutionRole,但任务定义也需确保角色创建完成后再生成。可给TaskDefinition添加DependsOn: ExecutionRole,避免CloudFormation提前创建任务定义导致角色引用失效。

  4. 验证角色实际配置
    登录IAM控制台检查ExecutionRole的实际配置:

    • 确认信任策略确实包含ecs-tasks.amazonaws.com服务主体
    • 确认AmazonECSTaskExecutionRolePolicy托管策略已正确附加
    • 确认角色ARN完整包含账户ID和路径/myroles

内容的提问来源于stack exchange,提问作者Code-Apprentice

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 22:30:48