升级Serverless至v1.44.0后部署失败:EnterpriseLogAccessIamRole策略报错
解决Serverless v1.44.0 + Enterprise Plugin部署时的IAM策略错误
你遇到的问题是@serverless/enterprise-plugin自动创建的EnterpriseLogAccessIamRole角色缺少必要的资源定义,导致AWS IAM返回MalformedPolicyDocument错误。这个问题通常源于旧版插件与Serverless框架v1.44.0的兼容性问题,下面是几个可行的解决方案:
方案1:升级Enterprise Plugin到最新版本
旧版本的@serverless/enterprise-plugin在配合Serverless v1.44.0生成日志访问IAM策略时,可能没有正确填充Resource字段。升级插件是最彻底的解决方式:
执行以下命令更新插件:
npm update @serverless/enterprise-plugin # 若使用yarn则执行 yarn upgrade @serverless/enterprise-plugin
更新完成后重新运行serverless deploy,应该就能正常创建User Pool及相关资源了。
方案2:临时禁用插件的日志收集功能
如果你暂时不需要插件的日志收集能力,可以在serverless.yml中添加配置关闭该功能,这样插件就不会创建那个有问题的IAM角色:
custom: stage: ${opt:stage, self:provider.stage} cognito: app: userPool: ${self:service}-app-user-pool-${self:custom.stage} identityPool: AppIdentityPoolDev # 添加以下配置关闭日志收集 enterprise: collectLambdaLogs: false
方案3:手动补充IAM策略的资源定义
如果升级插件无效,你可以手动在resources部分为该角色补充策略,明确指定允许访问的资源:
resources: Resources: AppUserPool: Type: AWS::Cognito::UserPool Properties: UserPoolName: ${self:custom.cognito.app.userPool} UsernameAttributes: - email AutoVerifiedAttributes: - email MobileAppClient: Type: AWS::Cognito::UserPoolClient Properties: ClientName: ${self:service}-mobile-app-client-${self:custom.stage} UserPoolId: Ref: AppUserPool GenerateSecret: true # 手动添加日志访问策略 EnterpriseLogAccessIamRolePolicy: Type: AWS::IAM::Policy Properties: PolicyName: EnterpriseLogAccessPolicy Roles: - Ref: EnterpriseLogAccessIamRole PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: - logs:CreateLogGroup - logs:CreateLogStream - logs:PutLogEvents Resource: "arn:aws:logs:*:*:*"
这个策略允许角色访问所有CloudWatch日志资源,符合插件的预期需求,能够解决策略文档格式错误的问题。
建议优先尝试方案1,若仍有问题再考虑方案2或3。
内容的提问来源于stack exchange,提问作者Nelson.b.austin
相关产品推荐
相关产品推荐

