如何在嵌套栈中引用父栈创建的IAM Role
嵌套栈中引用父栈IAM Role的问题解决
问题背景
我在尝试在嵌套栈中引用父栈创建的IAM Role时遇到问题,使用!Ref和!GetAtt都无法生效。已经在父栈中将IAM Role作为参数传递给嵌套栈,现在需要把父栈生成的IAM Role的ARN正确传递给子栈。
父栈YAML代码
AWSTemplateFormatVersion: '2010-09-09' Transform: AWS::Serverless-2016-10-31 Description: SAM Template for Nested application resources Resources: Layer: Type: AWS::Lambda::LayerVersion Properties: CompatibleRuntimes: - nodejs16.x Content: S3Bucket: bucketName S3Key: Key Description: My layer LayerName: lambdaLayer LicenseInfo: MIT SourceIAMRole: Type: AWS::IAM::Role Properties: RoleName: source-lambda-iam-omni-agent-role AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Sid: '' Effect: Allow Principal: Service: lambda.amazonaws.com Action: sts:AssumeRole Policies: - PolicyName: translate-policy PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: - comprehend:DetectDominantLanguage - translate:TranslateText Resource: '*' - PolicyName: invokeLambda-sns-sqs-sm-policy PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: - lambda:InvokeAsync - lambda:InvokeFunction - sns:Publish - iam:ListRoles - iam:GetRole - secretsmanager:GetSecretValue - secretsmanager:ListSecrets - secretsmanager:UpdateSecret - sqs:* Resource: '*' - PolicyName: sts-policy PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: - sts:AssumeRole Resource: '*' - PolicyName: write-cloudwatch-logs-policy PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: - logs:CreateLogStream - logs:CreateLogGroup - logs:PutLogEvents Resource: '*' ManagedPolicyArns: - arn:aws:iam::aws:policy/service-role/AWSLambdaKinesisExecutionRole - arn:aws:iam::aws:policy/service-role/AWSLambdaVPCAccessExecutionRole - arn:aws:iam::aws:policy/AmazonS3FullAccess - arn:aws:iam::aws:policy/AmazonAPIGatewayInvokeFullAccess - arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess - arn:aws:iam::aws:policy/AmazonConnect_FullAccess config: Type: AWS::Serverless::Application Properties: Location: customerconfig.yml Parameters: LayerARN: !Ref Layer IAMRole: !Ref SourceIAMRole DependsOn: - Layer - SourceIAMRole
子栈YAML代码
AWSTemplateFormatVersion: 2010-09-09 Description: Start from scratch starter project Transform: AWS::Serverless-2016-10-31 Globals: Function: Runtime: nodejs16.x Timeout: 15 CodeUri: ./ VpcConfig: SecurityGroupIds: - sg-005941cb59bd3c74e SubnetIds: - subnet-083b8c9bc31cefb69 - subnet-0f77f5b03c7fc1bc7 Layers: - !Ref LayerARN MemorySize: 128 Parameters: LayerARN: Type: String IAMRole: Type: String Resources: helloFromLambdaFunction: Type: AWS::Serverless::Function Properties: Role: !GetAtt IAMRole.Arn Handler: api/getapplicationconfig.handler Description: A Lambda function that returns a static string.
问题原因及解决方法
问题核心在于参数传递的内容和子栈引用方式不匹配:
- 父栈中
!Ref SourceIAMRole返回的是IAM Role的名称,而非ARN;子栈中试图对字符串参数使用!GetAtt IAMRole.Arn是错误的,因为该参数不是一个资源对象,无法通过!GetAtt获取属性。
方案一:直接传递ARN到子栈
修改父栈
将传递的参数改为IAM Role的ARN:
config: Type: AWS::Serverless::Application Properties: Location: customerconfig.yml Parameters: LayerARN: !Ref Layer IAMRoleARN: !GetAtt SourceIAMRole.Arn # 直接传递ARN DependsOn: - Layer - SourceIAMRole
修改子栈
更新参数名称并直接引用ARN:
Parameters: LayerARN: Type: String IAMRoleARN: # 参数名更清晰,表明是ARN Type: String Resources: helloFromLambdaFunction: Type: AWS::Serverless::Function Properties: Role: !Ref IAMRoleARN # 直接使用传递过来的ARN Handler: api/getapplicationconfig.handler Description: A Lambda function that returns a static string.
方案二:传递角色名称并在子栈拼接ARN
如果需要传递角色名称而非ARN,子栈中可以通过!Sub结合账户ID拼接出完整ARN:
# 子栈资源部分修改 Resources: helloFromLambdaFunction: Type: AWS::Serverless::Function Properties: Role: !Sub "arn:aws:iam::${AWS::AccountId}:role/${IAMRole}" Handler: api/getapplicationconfig.handler Description: A Lambda function that returns a static string.
内容的提问来源于stack exchange,提问作者Tayyab
相关产品推荐
相关产品推荐

