You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用服务托管权限创建CloudFormation栈实例报错求助

CloudFormation create_stack_instances 参数验证错误排查

问题描述

使用服务托管权限,针对指定OU并通过账户列表交集过滤调用create_stack_instances创建CloudFormation栈实例时,触发参数验证错误:

  • CLI执行报错:参数验证失败,DeploymentTargets中存在未知参数"AccountFilterType",仅允许Accounts、AccountsUrl、OrganizationalUnitIds
  • Lambda执行报错:[ERROR] ParamValidationError: 参数验证失败,DeploymentTargets中存在未知参数"AccountFilterType",仅允许Accounts、AccountsUrl、OrganizationalUnitIds

相关代码与命令如下:

Lambda代码

def add_stack_to_stackset(StackSetName, accountid):
    response = CF.create_stack_instances(
        StackSetName=StackSetName,
        DeploymentTargets={
            'OrganizationalUnitIds': ['ou-blah'],
             'Accounts': [accountid],
            'AccountFilterType': 'INTERSECTION'
        },
        Regions=['us-east-1']
    )
    op_id = response['OperationId']
    return op_id

CLI命令

aws cloudformation create-stack-instances --stack-set-name demo --deployment-targets OrganizationalUnitIds=ou-blah,Accounts=12345,AccountFilterType=INTERSECTION --regions us-east-1

问题原因与修复方案

问题根源是**AccountFilterType参数被错误嵌套在DeploymentTargets结构体中**,该参数属于create_stack_instances的顶层参数,而非DeploymentTargets的子参数。

修复后的Lambda代码

def add_stack_to_stackset(StackSetName, accountid):
    response = CF.create_stack_instances(
        StackSetName=StackSetName,
        DeploymentTargets={
            'OrganizationalUnitIds': ['ou-blah'],
             'Accounts': [accountid]
        },
        AccountFilterType='INTERSECTION',
        Regions=['us-east-1']
    )
    op_id = response['OperationId']
    return op_id

修复后的CLI命令

aws cloudformation create-stack-instances --stack-set-name demo --deployment-targets OrganizationalUnitIds=ou-blah,Accounts=12345 --account-filter-type INTERSECTION --regions us-east-1

内容的提问来源于stack exchange,提问作者user2051904

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 10:30:43