You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置IAM策略强制用户使用指定EC2启动模板创建实例?

配置IAM策略限制仅通过指定EC2 Launch Template创建实例

你之前的策略核心问题是没有正确填写Launch Template的ARN,EC2 Launch Template是有ARN的,且ec2:LaunchTemplate条件仅支持ARN格式的值,使用模板ID无法生效。

以下是修改后的完整策略,你需要将策略中的arn:aws:ec2:us-east-1:123456789012:launch-template/lt-0abcdef1234567890替换为你实际的Launch Template ARN:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "AllowRunInstancesWithSpecifiedLaunchTemplate",
            "Effect": "Allow",
            "Action": "ec2:RunInstances",
            "Resource": "*",
            "Condition": {
                "StringLikeIfExists": {
                    "ec2:InstanceType": "t2.micro"
                },
                "ArnEquals": {
                    "ec2:LaunchTemplate": "arn:aws:ec2:us-east-1:123456789012:launch-template/lt-0abcdef1234567890"
                }
            }
        },
        {
            "Sid": "AllowEC2RelatedDescribeActions",
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeInstances",
                "ec2:DescribeAddresses",
                "ec2:GetEbsEncryptionByDefault",
                "ec2:DescribeVolumesModifications",
                "ec2:DescribeSnapshots",
                "kms:DescribeCustomKeyStores",
                "ec2:DescribeInstanceTypeOfferings",
                "ec2:StartInstances",
                "ec2:DescribeAvailabilityZones",
                "ec2:CreateSnapshot",
                "ec2:GetEbsDefaultKmsKeyId",
                "ec2:DescribeKeyPairs",
                "ec2:DescribeInstanceStatus",
                "ec2:TerminateInstances",
                "ec2:DescribeLaunchTemplates",
                "ec2:DescribeTags",
                "ec2:CreateTags",
                "ec2:DescribeLaunchTemplateVersions",
                "ec2:AssignPrivateIpAddresses",
                "ec2:StopInstances",
                "ec2:DescribeSecurityGroups",
                "ec2:CreateVolume",
                "ec2:DescribeImages",
                "kms:ListKeys",
                "ec2:CreateSnapshots",
                "ec2:DescribeVpcs",
                "kms:ListAliases",
                "ec2:DescribeInstanceTypes",
                "ec2:DescribeSubnets"
            ],
            "Resource": "*"
        }
    ]
}

关键说明:

  • 获取Launch Template ARN:你可以在EC2控制台的「启动模板」详情页找到ARN,也可以通过AWS CLI命令获取:
    aws ec2 describe-launch-templates --launch-template-ids lt-你的模板ID --query 'LaunchTemplates[0].LaunchTemplateArn'
    
  • 条件限制逻辑:ArnEquals确保用户只能通过指定的Launch Template调用ec2:RunInstances,配合StringLikeIfExists保留了实例类型为t2.micro的限制(如果不需要可直接删除该条件)。
  • 权限范围:第二个Statement保留了你原本需要的EC2描述、实例生命周期管理等权限,确保用户能正常管理实例但只能通过指定模板创建。

内容的提问来源于stack exchange,提问作者allhandsofsorrow

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 08:09:16