You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS SAM部署报Failed to create managed resources错误求解决方案

问题场景

执行 sam deploy --guided 命令部署Hello World示例SAM应用时出现权限报错,完整报错日志如下:

Configuring SAM deploy
======================

        Looking for config file [samconfig.toml] :  Not found

        Setting default arguments for 'sam deploy'
        =========================================
        Stack Name [sam-app]: sam-app
        AWS Region [eu-west-1]: eu-west-1
        #Shows you resources changes to be deployed and require a 'Y' to initiate deploy
        Confirm changes before deploy [y/N]: y
        #SAM needs permission to be able to create roles to connect to the resources in your template
        Allow SAM CLI IAM role creation [Y/n]: y
        #Preserves the state of previously provisioned resources when an operation fails
        Disable rollback [y/N]: y
        HelloWorldFunction may not have authorization defined, Is this okay? [y/N]: y
        Save arguments to configuration file [Y/n]: y
        SAM configuration file [samconfig.toml]: 
        SAM configuration environment [default]: 

        Looking for resources needed for deployment:
        Creating the required resources...
Error: Failed to create managed resources: An error occurred (AccessDenied) when calling the CreateChangeSet operation: User: arn:aws:iam::899719272550:user/xxxxxxxx@xxxxxxxxxxxxxxxxxxxxxxxx is not authorized to perform: cloudformation:CreateChangeSet on resource: arn:aws:cloudformation:eu-west-1:899719272550:stack/aws-sam-cli-managed-default/* because no identity-based policy allows the cloudformation:CreateChangeSet action 
问题原因

当前使用的IAM用户未被授予cloudformation:CreateChangeSet操作的身份权限,无法为SAM CLI依赖的aws-sam-cli-managed-default托管资源栈创建变更集,直接导致部署流程中断。

修复步骤
  • 登录AWS控制台进入IAM服务页,定位到当前执行部署操作的IAM用户
  • 为该用户添加对应权限策略:
    • 必须包含的核心CloudFormation权限:cloudformation:CreateChangeSet、cloudformation:CreateStack、cloudformation:DescribeStacks、cloudformation:UpdateStack、cloudformation:DeleteStack、cloudformation:DescribeChangeSet、cloudformation:ExecuteChangeSet、cloudformation:ListStackResources、cloudformation:DescribeStackEvents
    • 权限的资源范围需要覆盖两类资源:一是ARN为arn:aws:cloudformation:<你使用的AWS区域>:<你的账号ID>:stack/aws-sam-cli-managed-default/*的托管栈资源,二是你本次要部署的SAM应用对应资源栈的ARN
  • 个人测试环境可以直接为用户附加AWS托管的AdministratorAccess权限快速验证,部署完成后再按照最小权限原则收紧权限即可
  • 权限配置生效后,重新执行sam deploy --guided命令即可正常走通部署流程

补充排查点:如果配置完上述权限仍然报同类AccessDenied错误,检查该IAM用户是否被权限边界、账号所在组织的SCP策略限制了CloudFormation操作权限。

内容的提问来源于stack exchange,提问作者Chulendra Wibavashakthi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.29 12:09:18