You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

测试网站使用AWS Elastic Transcoder遇403权限拒绝异常求助

Hey there, let's break down this 403 error you're hitting with AWS Elastic Transcoder and Cognito. The error message is pretty explicit, so let's walk through the most likely fixes step by step:

1. Double-Check the IAM Policy for Cognito_Unauth_Role

The core issue here is that your unauthenticated Cognito role doesn't have permission to run elastictranscoder:CreateJob on your specific pipeline. Let's verify the policy attached to Cognito_Unauth_Role:

Your policy needs to explicitly allow the elastictranscoder:CreateJob action for your pipeline's ARN. It should look something like this (replace placeholders with your actual values):

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "elastictranscoder:CreateJob",
      "Resource": "arn:aws:elastictranscoder:us-east-1:YOUR_ACCOUNT_ID:pipeline/YOUR_PIPELINE_ID"
    }
  ]
}
  • Make sure there are no typos in the ARN—even a single incorrect character will trigger a 403.
  • If you need broader access (not recommended for production), you can use a wildcard like arn:aws:elastictranscoder:us-east-1:YOUR_ACCOUNT_ID:pipeline/*, but stick to the specific pipeline if possible.

Sometimes the policy is right, but the identity pool isn't properly connected to the role. Here's how to check:

  • Go to your Cognito Identity Pool settings in the AWS Console
  • Navigate to the Identity providers tab
  • Under Unauthenticated identities, ensure the selected role is Cognito_Unauth_Role
  • If you're using authenticated users, repeat this check for the Authenticated identities section
3. Fix Syntax Issues in Your Code

Looking at your code sample, I spotted curly quotes (‘/“ instead of straight '/")—these can break parameter parsing. Replace them with standard quotes, and double-check your parameter values:

AWS.config.region = 'us-east-1';
AWS.config.credentials = new AWS.CognitoIdentityCredentials({
  IdentityPoolId: "us-east-1:xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxx",
});
var elastictranscoder = new AWS.ElasticTranscoder();
var button = document.getElementById('button');
button.addEventListener('click', function() {
  var params = {
    PipelineId: 'your-pipeline-id', /* required */
    Input: { Key: "your-input-file-key" },
    OutputKeyPrefix: 'your-output-prefix/',
    Outputs: [{
      Key: 'output-file.mp4',
      PresetId: 'your-preset-id',
    }],
  };
  elastictranscoder.createJob(params, function(err, data) {
    if (err) console.log(err, err.stack);
    else console.log(data);
  });
});

Also, ensure the PipelineId matches exactly with the ID in your pipeline ARN, and the Input.Key has no invalid spaces or slashes.

4. Check for Permission Boundaries or Trust Policy Issues
  • Permission Boundaries: If your Cognito_Unauth_Role has a permission boundary attached, it might be overriding your policy. Go to the role's IAM page, check the Permissions boundary section, and confirm it allows elastictranscoder:CreateJob.
  • Trust Policy: Verify the role's trust policy allows Cognito to assume it. It should include this statement:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "Federated": "cognito-identity.amazonaws.com"
          },
          "Action": "sts:AssumeRoleWithWebIdentity",
          "Condition": {
            "StringEquals": {
              "cognito-identity.amazonaws.com:aud": "YOUR_IDENTITY_POOL_ID"
            },
            "ForAnyValue:StringLike": {
              "cognito-identity.amazonaws.com:amr": "unauthenticated"
            }
          }
        }
      ]
    }
    
Quick Test to Narrow Down the Issue

If you're still stuck, try using the AWS CLI to assume the Cognito_Unauth_Role and run CreateJob manually. This will tell you if the problem is in your code or the IAM configuration:

# Assume the role
aws sts assume-role --role-arn "arn:aws:iam::YOUR_ACCOUNT_ID:role/Cognito_Unauth_Role" --role-session-name "test-transcoder"

# Use the returned AccessKeyId, SecretAccessKey, and SessionToken to run CreateJob
aws elastictranscoder create-job --pipeline-id YOUR_PIPELINE_ID --input Key=YOUR_INPUT_KEY --outputs Key=OUTPUT_KEY PresetId=YOUR_PRESET_ID --region us-east-1

Start with the IAM policy check first—it's the most common cause of this exact error. Once that's sorted, the other checks should wrap up any remaining issues.

内容的提问来源于stack exchange,提问作者Carel Fourie

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 06:30:27