AWS SAM部署报Failed to create managed resources错误求解决方案
问题场景
执行 sam deploy --guided 命令部署Hello World示例SAM应用时出现权限报错,完整报错日志如下:
Configuring SAM deploy ====================== Looking for config file [samconfig.toml] : Not found Setting default arguments for 'sam deploy' ========================================= Stack Name [sam-app]: sam-app AWS Region [eu-west-1]: eu-west-1 #Shows you resources changes to be deployed and require a 'Y' to initiate deploy Confirm changes before deploy [y/N]: y #SAM needs permission to be able to create roles to connect to the resources in your template Allow SAM CLI IAM role creation [Y/n]: y #Preserves the state of previously provisioned resources when an operation fails Disable rollback [y/N]: y HelloWorldFunction may not have authorization defined, Is this okay? [y/N]: y Save arguments to configuration file [Y/n]: y SAM configuration file [samconfig.toml]: SAM configuration environment [default]: Looking for resources needed for deployment: Creating the required resources... Error: Failed to create managed resources: An error occurred (AccessDenied) when calling the CreateChangeSet operation: User: arn:aws:iam::899719272550:user/xxxxxxxx@xxxxxxxxxxxxxxxxxxxxxxxx is not authorized to perform: cloudformation:CreateChangeSet on resource: arn:aws:cloudformation:eu-west-1:899719272550:stack/aws-sam-cli-managed-default/* because no identity-based policy allows the cloudformation:CreateChangeSet action
问题原因
当前使用的IAM用户未被授予cloudformation:CreateChangeSet操作的身份权限,无法为SAM CLI依赖的aws-sam-cli-managed-default托管资源栈创建变更集,直接导致部署流程中断。
修复步骤
- 登录AWS控制台进入IAM服务页,定位到当前执行部署操作的IAM用户
- 为该用户添加对应权限策略:
- 必须包含的核心CloudFormation权限:
cloudformation:CreateChangeSet、cloudformation:CreateStack、cloudformation:DescribeStacks、cloudformation:UpdateStack、cloudformation:DeleteStack、cloudformation:DescribeChangeSet、cloudformation:ExecuteChangeSet、cloudformation:ListStackResources、cloudformation:DescribeStackEvents - 权限的资源范围需要覆盖两类资源:一是ARN为
arn:aws:cloudformation:<你使用的AWS区域>:<你的账号ID>:stack/aws-sam-cli-managed-default/*的托管栈资源,二是你本次要部署的SAM应用对应资源栈的ARN
- 必须包含的核心CloudFormation权限:
- 个人测试环境可以直接为用户附加AWS托管的
AdministratorAccess权限快速验证,部署完成后再按照最小权限原则收紧权限即可 - 权限配置生效后,重新执行
sam deploy --guided命令即可正常走通部署流程
补充排查点:如果配置完上述权限仍然报同类AccessDenied错误,检查该IAM用户是否被权限边界、账号所在组织的SCP策略限制了CloudFormation操作权限。
内容的提问来源于stack exchange,提问作者Chulendra Wibavashakthi
相关产品推荐
相关产品推荐

