You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在嵌套栈中引用父栈创建的IAM Role

嵌套栈中引用父栈IAM Role的问题解决

问题背景

我在尝试在嵌套栈中引用父栈创建的IAM Role时遇到问题,使用!Ref和!GetAtt都无法生效。已经在父栈中将IAM Role作为参数传递给嵌套栈,现在需要把父栈生成的IAM Role的ARN正确传递给子栈。

父栈YAML代码

AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Description:
  SAM Template for Nested application resources

Resources:
  Layer:
    Type: AWS::Lambda::LayerVersion
    Properties:
      CompatibleRuntimes:
        - nodejs16.x
      Content:
        S3Bucket: bucketName
        S3Key: Key
      Description: My layer
      LayerName: lambdaLayer
      LicenseInfo: MIT
  SourceIAMRole:
    Type: AWS::IAM::Role
    Properties:
      RoleName: source-lambda-iam-omni-agent-role
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
        - Sid: ''
          Effect: Allow
          Principal:
            Service: lambda.amazonaws.com
          Action: sts:AssumeRole
      Policies:
      - PolicyName: translate-policy
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action: 
              - comprehend:DetectDominantLanguage
              - translate:TranslateText
            Resource: '*'
      - PolicyName: invokeLambda-sns-sqs-sm-policy
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action: 
              - lambda:InvokeAsync
              - lambda:InvokeFunction
              - sns:Publish
              - iam:ListRoles
              - iam:GetRole
              - secretsmanager:GetSecretValue
              - secretsmanager:ListSecrets
              - secretsmanager:UpdateSecret
              - sqs:*
            Resource: '*'
      - PolicyName: sts-policy
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action: 
              - sts:AssumeRole
            Resource: '*'
      - PolicyName: write-cloudwatch-logs-policy
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action: 
              - logs:CreateLogStream
              - logs:CreateLogGroup
              - logs:PutLogEvents
            Resource: '*'
      ManagedPolicyArns:
      - arn:aws:iam::aws:policy/service-role/AWSLambdaKinesisExecutionRole
      - arn:aws:iam::aws:policy/service-role/AWSLambdaVPCAccessExecutionRole
      - arn:aws:iam::aws:policy/AmazonS3FullAccess
      - arn:aws:iam::aws:policy/AmazonAPIGatewayInvokeFullAccess
      - arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess
      - arn:aws:iam::aws:policy/AmazonConnect_FullAccess
      
  config:
    Type: AWS::Serverless::Application
    Properties:
      Location: customerconfig.yml
      Parameters:
        LayerARN: !Ref Layer
        IAMRole: !Ref SourceIAMRole
    DependsOn:
      - Layer
      - SourceIAMRole

子栈YAML代码

AWSTemplateFormatVersion: 2010-09-09
Description:
  Start from scratch starter project

Transform: AWS::Serverless-2016-10-31

Globals:
  Function:
    Runtime: nodejs16.x
    Timeout: 15
    CodeUri: ./
    VpcConfig:
        SecurityGroupIds:
          - sg-005941cb59bd3c74e
        SubnetIds:
          - subnet-083b8c9bc31cefb69
          - subnet-0f77f5b03c7fc1bc7
    Layers:
      - !Ref LayerARN
    MemorySize: 128

Parameters:
  LayerARN:
    Type: String
  IAMRole:
    Type: String
    
Resources:
  helloFromLambdaFunction:
    Type: AWS::Serverless::Function
    Properties:
      Role: !GetAtt IAMRole.Arn
      Handler: api/getapplicationconfig.handler
      Description: A Lambda function that returns a static string.

问题原因及解决方法

问题核心在于参数传递的内容和子栈引用方式不匹配:

  • 父栈中!Ref SourceIAMRole返回的是IAM Role的名称,而非ARN;子栈中试图对字符串参数使用!GetAtt IAMRole.Arn是错误的,因为该参数不是一个资源对象,无法通过!GetAtt获取属性。

方案一:直接传递ARN到子栈

修改父栈

将传递的参数改为IAM Role的ARN:

config:
  Type: AWS::Serverless::Application
  Properties:
    Location: customerconfig.yml
    Parameters:
      LayerARN: !Ref Layer
      IAMRoleARN: !GetAtt SourceIAMRole.Arn  # 直接传递ARN
  DependsOn:
    - Layer
    - SourceIAMRole

修改子栈

更新参数名称并直接引用ARN:

Parameters:
  LayerARN:
    Type: String
  IAMRoleARN:  # 参数名更清晰,表明是ARN
    Type: String
    
Resources:
  helloFromLambdaFunction:
    Type: AWS::Serverless::Function
    Properties:
      Role: !Ref IAMRoleARN  # 直接使用传递过来的ARN
      Handler: api/getapplicationconfig.handler
      Description: A Lambda function that returns a static string.

方案二:传递角色名称并在子栈拼接ARN

如果需要传递角色名称而非ARN,子栈中可以通过!Sub结合账户ID拼接出完整ARN:

# 子栈资源部分修改
Resources:
  helloFromLambdaFunction:
    Type: AWS::Serverless::Function
    Properties:
      Role: !Sub "arn:aws:iam::${AWS::AccountId}:role/${IAMRole}"
      Handler: api/getapplicationconfig.handler
      Description: A Lambda function that returns a static string.

内容的提问来源于stack exchange,提问作者Tayyab

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 22:25:22