You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在CloudFormation YAML中添加多资源时遇格式错误求助

修复CloudFormation YAML格式错误及模板问题

我帮你排查了模板里的几个关键YAML格式问题,这应该就是导致你报错的原因,下面是具体问题点和修复后的完整模板:

问题分析

  • 行61的无效语法:IoTDaasDevicePolicy的Roles字段下写了- Ref: IoTDaasDeviceRole的内容,这明显是输入错误,正确写法应该是!Ref IoTDaasDeviceRole。
  • Resource数组格式错误:iot:StartNextPendingJobExecution对应的Resource用了大括号{}包裹,但YAML中数组需要用中括号[](或换行缩进的列表形式),大括号是用来表示映射对象的,这里会直接导致解析失败。
  • RoleName多余字符:IoTDaasDeviceRole的RoleName里多了个点号(IoTDaasDeviceRole.,),需要去掉这个多余的点来保证角色名称格式合法。
  • 参数描述的语法错误:taaccountid的Description末尾多了一个闭合双引号",破坏了YAML的字符串结构,导致解析异常。
  • 缩进一致性:统一了模板内所有嵌套字段的缩进(使用2个空格),避免混合缩进引发的格式问题。

修复后的完整模板

AWSTemplateFormatVersion: 2010-09-09
Description: >-
  This template creates IoT policy - attaches to a device certificate, IoT Topic Rule- used to forward messages to sns based on service key, and creates required IAM roles for these.
Parameters:
  vpcname:
    Type: String
    Description: Enter vpcname
  vpcnamefirstletterupper:
    Type: String
    Description: Enter vpcname with camelcase, ex- "Usdevms"
  taaccountid:
    Type: String
    Description: Enter TA AccountID
Resources:
  IoTDaasDeviceRole:
    Type: 'AWS::IAM::Role'
    Properties:
      RoleName: !Join ["", ["IoTDaasDeviceRole", !Ref vpcname]]
      MaxSessionDuration : 43200
      AssumeRolePolicyDocument:
        Version: 2012-10-17
        Statement:
          - Effect: Allow
            Principal:
              AWS: !Join ["", [!Sub 'arn:aws:iam::${AWS::AccountId}:role/Daas', !Ref vpcnamefirstletterupper, 'IotCredentialLambda']]
              Service: lambda.amazonaws.com
            Action:
              - 'sts:AssumeRole'
  IoTDaasDevicePolicy:
    Type: 'AWS::IAM::ManagedPolicy'
    Properties:
      Description: >-
        This Policy will be attached to the device role and lists the permissions given to device certificates
      ManagedPolicyName: !Join
        - ''
        - - 'IoTDaasDeviceConnectPolicy.'
          - !Ref vpcname
      PolicyDocument:
        Version: 2012-10-17
        Statement:
          - Effect: Allow
            Action: 'iot:Connect'
            Resource: !Join
              - ''
              - - !Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:client/'
                - '*'
          - Effect: Allow
            Action: 'iot:Publish'
            Resource: !Join
              - ''
              - - !Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:topic/$aws/rules/daas_device_events_rule_'
                - !Ref vpcname
                - '/*'
          - Effect: Allow
            Action: 'iot:StartNextPendingJobExecution'
            Resource: 
              - !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:things/', '*']]
              - !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:topic/$aws/things/thingName/jobs/start-next/']]
              - !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:topicfilter/$aws/things/thingName/jobs/start-next/accepted']]
              - !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:topicfilter/$aws/things/thingName/jobs/start-next/rejected']]
          - Effect: Allow
            Action: 'iot:UpdateJobExecution'
            Resource: !Join ["", [!Sub 'arn:aws:iot:${AWS::Region}:${AWS::AccountId}:things/', '*']]
          - Effect: Allow
            Action: 'execute-api:Invoke'
            Resource: !Join ['', [!Sub 'arn:aws:execute-api:${AWS::Region}:', !Ref taaccountid, ':hpe5n6k1v8/Test/GET']]
      Roles:
        - !Ref IoTDaasDeviceRole

内容的提问来源于stack exchange,提问作者Dev Role

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 07:58:13