You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudFormation部署ECS Fargate定时任务报RunTask权限错误如何解决

备注:问题已解决,解决方案位于提问末尾。

问题描述

通过CloudFormation部署ECS Fargate资源,创建了一个每50分钟运行一次的定时任务,配置无误且已成功同步到AWS控制台,但出现调用失败问题,CloudTrail中报错信息为:

"User: arn:aws:sts::XXX:assumed-role/CloudWatchBackupEventRoleSA/0b3175d7b79e37638d901f6fbd132647 is not authorized to perform: ecs:RunTask on resource: arn:aws:ecs:sa-east-1:XXX:task-definition/family-metrics:10"

以下是使用的TaskDefinition、TaskExecutionRole、CloudWatchEvECSRole(该角色已配置RunTask、PassRole等操作权限)的资源配置代码:

资源配置代码
TaskDefinition:
    Type: AWS::ECS::TaskDefinition
    # DependsOn: Listener
    Properties:
      RequiresCompatibilities:
        - FARGATE
      ExecutionRoleArn: !Ref TaskExecutionRole
      TaskRoleArn: !Ref TaskExecutionRole
      Cpu: !Ref ContainerCpu
      Memory: !Ref ContainerMemory
      ContainerDefinitions:
        - Name: !Sub ${ContainerName}
          Image: !Sub '${ImageName}'
          PortMappings:
            - ContainerPort: !Ref ExposedPortInDockerfile
          Cpu: !Ref ContainerCpu
          Memory: !Ref ContainerMemory
          MemoryReservation: !Ref ContainerMemoryReservation
          Essential: true
          LogConfiguration:
            LogDriver: awslogs
            Options:
              awslogs-region: !Sub "${AWS::Region}"
              awslogs-group: !Sub "${Feature}-${Micro}"
              awslogs-stream-prefix: !Sub "${Feature}-${Micro}"
      Family: !Sub "family-${Feature}-${Micro}"
      NetworkMode: awsvpc
    DependsOn: CloudWatchLogGroup

TaskExecutionRole:
    Type: "AWS::IAM::Role"
    Properties:
      AssumeRolePolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: "Allow"
            Principal:
              Service:
                - ecs-tasks.amazonaws.com
            Action: "sts:AssumeRole"
      Policies:
      - PolicyName: policy-name
        PolicyDocument:
          Version: "2012-10-17"
          Statement:
            - Effect: "Allow"
              Action:
                - ecr:GetAuthorizationToken
                - ecr:BatchCheckLayerAvailability
                - ecr:GetDownloadUrlForLayer
                - ecr:BatchGetImage
                - logs:CreateLogStream
                - logs:PutLogEvents
              Resource: "*"

CloudWatchEvECSRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: 2012-10-17
        Statement:
          - Effect: Allow
            Principal:
              Service:
                - events.amazonaws.com
            Action:
              - sts:AssumeRole
      Path: /
      Policies:
      - PolicyName: CloudwatchEventsInvECSRunTask
        PolicyDocument:
          Version: 2012-10-17
          Statement:
            - Effect: Allow
              Action: 'ecs:RunTask'
              Resource: !Ref TaskDefinition
            - Effect: Allow
              Action: 'iam:PassRole'
              Resource: !GetAtt TaskExecutionRole.Arn
解决方案

该错误实际由容器镜像配置问题导致:填写的容器拉取镜像名称与ECR中实际存储的镜像名称不一致,修正该差异后任务即可正常运行。


内容的提问来源于stack exchange,提问作者Nakano

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 10:45:03