You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS MQTT Publish操作出现ForbiddenException异常,求解决方案

AWS MQTT Publish 报 ForbiddenException 解决方法

错误信息

{
  "errorMessage": "An error occurred (ForbiddenException) when calling the Publish operation: None",
  "errorType": "ClientError",
  "stackTrace": [
    "  File \"/var/task/lambda_function.py\", line 75, in lambda_handler\n    response = mqtt.publish(topic='iot/mqtttest', qos=1, payload = json.dumps(mqttData))\n",
    "  File \"/var/runtime/botocore/client.py\", line 391, in _api_call\n    return self._make_api_call(operation_name, kwargs)\n",
    "  File \"/var/runtime/botocore/client.py\", line 719, in _make_api_call\n    raise error_class(parsed_response, operation_name)\n"
  ]
}

排查解决步骤

  • 检查IAM权限:确保执行Publish操作的身份(如Lambda执行角色)拥有iot:Publish权限,且资源匹配目标主题iot/mqtttest。示例权限策略:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "iot:Publish",
      "Resource": "arn:aws:iot:你的区域ID:你的AWS账号ID:topic/iot/mqtttest"
    }
  ]
}

若需覆盖多个子主题,可将资源改为arn:aws:iot:你的区域ID:你的AWS账号ID:topic/iot/*。

  • 验证主题访问规则:确认目标主题iot/mqtttest未被AWS IoT的主题规则限制,不存在拒绝发布的策略配置。

  • 核对IoT端点配置:确认调用Publish时使用的AWS IoT Core端点正确,且与资源所在AWS区域一致,区域不匹配会导致权限校验失败。

  • 检查身份有效性:

    • 若用证书认证:确保证书已激活、未过期,且附加了允许iot:Publish的策略。
    • 若用IAM身份认证:确认角色信任关系配置正确,Lambda能获取有效访问凭证。
  • 确认主题名称合规:主题名称需符合AWS IoT规范,不能包含保留字符或格式错误。

内容的提问来源于stack exchange,提问作者user20602609

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 23:55:32