使用AWS CDK时Fargate服务无法写入DynamoDB表的问题求助
AWS CDK中Fargate服务访问DynamoDB的IAM权限问题
我用AWS CDK搭建基础设施,想让Fargate上的TypeScript应用读写DynamoDB表,但碰到了IAM权限问题。
Fargate服务和DynamoDB表都已经在AWS正常运行,但应用写入表时一直收到访问被拒的错误。
我试过多种方案,包括调用table.grantReadWriteData(fargateService.taskDefinition.taskRole)以及自定义IAM策略配置权限和操作,但执行putItem时始终弹出相同错误:
AccessDeniedException: User: {fargate-service-arn} is not authorized to perform: dynamodb:PutItem on resource: {dynamodb-table} because no identity-based policy allows the dynamodb:PutItem action
我是不是漏了什么关键步骤?
编辑(2022-09-19):
以下是定义Vpc、Cluster、容器镜像、FargateService和Table的简化代码:
export class FooCdkStack extends cdk.Stack { constructor(scope: Construct, id: string, props?: cdk.StackProps) { super(scope, id, props); const vpc = new Vpc(this, 'FooVpc', { maxAzs: 2, natGateways: 1 }); const cluster = new Cluster(this, 'FooCluster', { vpc }); const containerImage = ContainerImage.fromAsset( path.join(__dirname, '/../app'), { platform: Platform.LINUX_AMD64 // 我用的是M1 Mac,不加这个镜像无法正常工作 } ); const fargateService = new ApplicationLoadBalancedFargateService( this, 'FooFargateService', { assignPublicIp: true, cluster, memoryLimitMiB: 1024, cpu: 512, desiredCount: 1, taskImageOptions: { containerPort: PORT, image: containerImage } } ); fargateService.targetGroup.configureHealthCheck({ path: '/health' }); const serverTable = new Table(this, 'FooTable', { billingMode: BillingMode.PAY_PER_REQUEST, removalPolicy: cdk.RemovalPolicy.DESTROY, partitionKey: { name: 'id', type: AttributeType.STRING }, pointInTimeRecovery: true }); serverTable.grantReadWriteData(fargateService.taskDefinition.taskRole); } }
内容的提问来源于stack exchange,提问作者RPK
相关产品推荐
相关产品推荐

