AWS IAM simulate-principal-policy返回错误结果与实际操作矛盾的原因
Let me break down why you're seeing this contradiction between the IAM simulator and real-world execution:
1. Mismatched Resource Type in Simulator Command
The core issue here is the resource ARN you used in the simulator vs. what the ec2:CreateSnapshot action actually targets.
When you ran the simulator, you specified an instance ARN:
aws --profile my_profile iam simulate-principal-policy --policy-source-arn arn:aws:iam::777777777777:role/MyRole --action-names ec2:CreateSnapshot --resource-arns "arn:aws:ec2:eu-west-1:777777777777:i-6a6aa66aa66aa6666"But the
ec2:CreateSnapshotaction doesn't operate on EC2 instances—it works exclusively on EBS volumes (or snapshot resources themselves). The simulator correctly returnsimplicitDenybecause your policy doesn't grant permission to performec2:CreateSnapshoton an instance resource (since that's not a valid target for the action).When you ran the actual
create-snapshotcommand, you targeted an EBS volume (vol-xxxxxxxxxxxxxxxxx), and your policy sets"Resource": "*"—so AWS allows the action because it's targeting a valid resource type that your policy covers.
2. Fix the Simulator Command to Match Real Behavior
To get the simulator result aligned with your actual successful snapshot creation, run it with a volume ARN instead of an instance ARN:
aws --profile my_profile iam simulate-principal-policy --policy-source-arn arn:aws:iam::777777777777:role/MyRole --action-names ec2:CreateSnapshot --resource-arns "arn:aws:ec2:eu-west-1:777777777777:vol-xxxxxxxxxxxxxxxxx"
This should return Allow, matching what you see in practice.
3. Less Likely Edge Cases to Check (If Needed)
If you still see discrepancies after fixing the resource ARN, verify:
- Are there any unaccounted inline/managed policies attached to the role? Sometimes permissions can come from unexpected additional policies.
- Did you wait for policy propagation? IAM policies can take a few minutes to apply, but since your real command worked, this is probably not the issue here.
内容的提问来源于stack exchange,提问作者MyCoolAwsomeName

