CloudFormation部署ECS Fargate定时任务报RunTask权限错误如何解决
备注:问题已解决,解决方案位于提问末尾。
问题描述
通过CloudFormation部署ECS Fargate资源,创建了一个每50分钟运行一次的定时任务,配置无误且已成功同步到AWS控制台,但出现调用失败问题,CloudTrail中报错信息为:
"User: arn:aws:sts::XXX:assumed-role/CloudWatchBackupEventRoleSA/0b3175d7b79e37638d901f6fbd132647 is not authorized to perform: ecs:RunTask on resource: arn:aws:ecs:sa-east-1:XXX:task-definition/family-metrics:10"
以下是使用的TaskDefinition、TaskExecutionRole、CloudWatchEvECSRole(该角色已配置RunTask、PassRole等操作权限)的资源配置代码:
资源配置代码
TaskDefinition: Type: AWS::ECS::TaskDefinition # DependsOn: Listener Properties: RequiresCompatibilities: - FARGATE ExecutionRoleArn: !Ref TaskExecutionRole TaskRoleArn: !Ref TaskExecutionRole Cpu: !Ref ContainerCpu Memory: !Ref ContainerMemory ContainerDefinitions: - Name: !Sub ${ContainerName} Image: !Sub '${ImageName}' PortMappings: - ContainerPort: !Ref ExposedPortInDockerfile Cpu: !Ref ContainerCpu Memory: !Ref ContainerMemory MemoryReservation: !Ref ContainerMemoryReservation Essential: true LogConfiguration: LogDriver: awslogs Options: awslogs-region: !Sub "${AWS::Region}" awslogs-group: !Sub "${Feature}-${Micro}" awslogs-stream-prefix: !Sub "${Feature}-${Micro}" Family: !Sub "family-${Feature}-${Micro}" NetworkMode: awsvpc DependsOn: CloudWatchLogGroup TaskExecutionRole: Type: "AWS::IAM::Role" Properties: AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: "Allow" Principal: Service: - ecs-tasks.amazonaws.com Action: "sts:AssumeRole" Policies: - PolicyName: policy-name PolicyDocument: Version: "2012-10-17" Statement: - Effect: "Allow" Action: - ecr:GetAuthorizationToken - ecr:BatchCheckLayerAvailability - ecr:GetDownloadUrlForLayer - ecr:BatchGetImage - logs:CreateLogStream - logs:PutLogEvents Resource: "*" CloudWatchEvECSRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Principal: Service: - events.amazonaws.com Action: - sts:AssumeRole Path: / Policies: - PolicyName: CloudwatchEventsInvECSRunTask PolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Action: 'ecs:RunTask' Resource: !Ref TaskDefinition - Effect: Allow Action: 'iam:PassRole' Resource: !GetAtt TaskExecutionRole.Arn
解决方案
该错误实际由容器镜像配置问题导致:填写的容器拉取镜像名称与ECR中实际存储的镜像名称不一致,修正该差异后任务即可正常运行。
内容的提问来源于stack exchange,提问作者Nakano
相关产品推荐
相关产品推荐

