You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Lambda函数中添加指定标签以启动EMR集群解决权限报错

解决EMR RunJobFlow权限报错:添加指定标签

你的权限报错是因为IAM角色策略要求调用elasticmapreduce:RunJobFlow时,必须在请求中携带for-use-with-amazon-emr-managed-policies: true标签。只需在launch_transient_emr()函数的EMR集群创建请求中添加该标签即可。

具体修改方法

在调用boto3的emr_client.run_job_flow()方法时,添加顶层Tags参数(与Name、ReleaseLabel同级),格式为包含Key和Value的字典列表。

修改后的代码示例

import boto3

def launch_transient_emr():
    emr_client = boto3.client('emr', region_name='ap-southeast-1')
    response = emr_client.run_job_flow(
        Name='Transient-EMR-Cluster',
        ReleaseLabel='emr-6.15.0',
        # 添加要求的标签
        Tags=[
            {
                'Key': 'for-use-with-amazon-emr-managed-policies',
                'Value': 'true'
            }
        ],
        Instances={
            'InstanceGroups': [
                {
                    'Name': 'Master node',
                    'Market': 'ON_DEMAND',
                    'InstanceRole': 'MASTER',
                    'InstanceType': 'm5.xlarge',
                    'InstanceCount': 1
                },
                {
                    'Name': 'Core nodes',
                    'Market': 'ON_DEMAND',
                    'InstanceRole': 'CORE',
                    'InstanceType': 'm5.xlarge',
                    'InstanceCount': 2
                }
            ],
            'KeepJobFlowAliveWhenNoSteps': False,
            'TerminationProtected': False
        },
        # 保留你的其他原有参数(如Steps、JobFlowRole、ServiceRole等)
    )
    return response['JobFlowId']

说明

  • Tags是run_job_flow方法的合法顶层参数,添加后请求会携带该标签,满足IAM策略的StringEquals条件校验。
  • 无需修改IAM角色,仅需在代码中补充标签参数即可解决权限问题。

内容的提问来源于stack exchange,提问作者Lastchaos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 15:57:20