在CloudFormation YAML中添加多资源时遇格式错误求助
修复CloudFormation YAML格式错误及模板问题
我帮你排查了模板里的几个关键YAML格式问题,这应该就是导致你报错的原因,下面是具体问题点和修复后的完整模板:
问题分析
- 行61的无效语法:
IoTDaasDevicePolicy的Roles字段下写了- Ref: IoTDaasDeviceRole的内容,这明显是输入错误,正确写法应该是!Ref IoTDaasDeviceRole。 - Resource数组格式错误:
iot:StartNextPendingJobExecution对应的Resource用了大括号{}包裹,但YAML中数组需要用中括号[](或换行缩进的列表形式),大括号是用来表示映射对象的,这里会直接导致解析失败。 - RoleName多余字符:
IoTDaasDeviceRole的RoleName里多了个点号(IoTDaasDeviceRole.,),需要去掉这个多余的点来保证角色名称格式合法。 - 参数描述的语法错误:
taaccountid的Description末尾多了一个闭合双引号",破坏了YAML的字符串结构,导致解析异常。 - 缩进一致性:统一了模板内所有嵌套字段的缩进(使用2个空格),避免混合缩进引发的格式问题。
修复后的完整模板
AWSTemplateFormatVersion: 2010-09-09 Description: >- This template creates IoT policy - attaches to a device certificate, IoT Topic Rule- used to forward messages to sns based on service key, and creates required IAM roles for these. Parameters: vpcname: Type: String Description: Enter vpcname vpcnamefirstletterupper: Type: String Description: Enter vpcname with camelcase, ex- "Usdevms" taaccountid: Type: String Description: Enter TA AccountID Resources: IoTDaasDeviceRole: Type: 'AWS::IAM::Role' Properties: RoleName: !Join ["", ["IoTDaasDeviceRole", !Ref vpcname]] MaxSessionDuration : 43200 AssumeRolePolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Principal: AWS: !Join ["", [!Sub 'arn:aws:iam::${AWS::AccountId}:role/Daas', !Ref vpcnamefirstletterupper, 'IotCredentialLambda']] Service: lambda.amazonaws.com Action: - 'sts:AssumeRole' IoTDaasDevicePolicy: Type: 'AWS::IAM::ManagedPolicy' Properties: Description: >- This Policy will be attached to the device role and lists the permissions given to device certificates ManagedPolicyName: !Join - '' - - 'IoTDaasDeviceConnectPolicy.' - !Ref vpcname PolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Action: 'iot:Connect' Resource: !Join - '' - - !Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:client/' - '*' - Effect: Allow Action: 'iot:Publish' Resource: !Join - '' - - !Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:topic/$aws/rules/daas_device_events_rule_' - !Ref vpcname - '/*' - Effect: Allow Action: 'iot:StartNextPendingJobExecution' Resource: - !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:things/', '*']] - !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:topic/$aws/things/thingName/jobs/start-next/']] - !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:topicfilter/$aws/things/thingName/jobs/start-next/accepted']] - !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:topicfilter/$aws/things/thingName/jobs/start-next/rejected']] - Effect: Allow Action: 'iot:UpdateJobExecution' Resource: !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:things/', '*']] - Effect: Allow Action: 'execute-api:Invoke' Resource: !Join ['', [!Sub 'arn:aws:execute-api:${AWS::Region}:', !Ref taaccountid, ':hpe5n6k1v8/Test/GET']] Roles: - !Ref IoTDaasDeviceRole
内容的提问来源于stack exchange,提问作者Dev Role
相关产品推荐
相关产品推荐

