执行AWS CloudFormation模板遇ROLLBACK_COMPLETE错误求排查建议
Hey there! Let's dig into why your CloudFormation stack is rolling back and fix those issues step by step:
1. Outdated Lambda Runtime (Critical Failure Cause)
AWS has long deprecated Node.js 6.10—you can’t deploy Lambda functions using this runtime anymore. This is almost certainly the primary reason your stack rolls back. You need to switch to a supported LTS version like nodejs18.x (or newer, based on your code compatibility needs).
2. Potential DynamoDB Permission Gap
Your current IAM policy for the Lambda role only allows dynamodb:BatchWriteItem, but if your Lambda code uses dynamodb:PutItem (a common pattern for single-record writes), this will throw a permission error. It’s safer to include both actions to cover all write scenarios.
3. Redundant S3 Bucket Reference in Description
The template description mentions an S3 bucket, but your resource list doesn’t include one. This isn’t a functional error, but it’s confusing and should be updated to match the actual resources your template provisions.
4. Best Practice: Add Policy Version to IAM Policy
Your client IAM policy was missing the required Version field, which is a best practice for IAM policy documents.
Here's the revised template with all fixes applied:
AWSTemplateFormatVersion: '2010-09-09' Transform: AWS::Serverless-2016-10-31 Description: "Template to set up Kinesis stream, Lambda function, DynamoDB table and related IAM roles/users for real-time stream processing." Parameters: LambdaS3Bucket: Type: String Default: awslambda-reference-architectures Description: Name of S3 bucket where Lambda function packages are stored. LambdaDDBEventProcessorS3Key: Type : String Default : stream-processing/ddb_eventprocessor.zip Description : Name of S3 key for Zip with Stream Processing DynamoDB Event Processor Lambda function package. LambdaDDBEventProcessorHandler: Type : String Default : ddb_eventprocessor.handler Description : Name of handler for Stream Processing DynamoDB Event Processor Lambda function. Resources: EventStream: Type: 'AWS::Kinesis::Stream' Properties: ShardCount: 1 DDBEventProcessor: Type: 'AWS::Serverless::Function' Properties: Description: Stream Processing DDB Event Processor Handler: !Ref LambdaDDBEventProcessorHandler MemorySize: 128 Role: !GetAtt - EventProcessorExecutionRole - Arn Timeout: 10 Runtime: nodejs18.x # Updated to supported runtime CodeUri: Bucket: !Ref LambdaS3Bucket Key: !Ref LambdaDDBEventProcessorS3Key Events: Stream: Type: Kinesis Properties: Stream: !GetAtt EventStream.Arn StartingPosition: TRIM_HORIZON BatchSize: 25 EventDataTable: Type: 'AWS::DynamoDB::Table' Properties: AttributeDefinitions: - AttributeName: Username AttributeType: S - AttributeName: Id AttributeType: S KeySchema: - AttributeName: Username KeyType: HASH - AttributeName: Id KeyType: RANGE ProvisionedThroughput: ReadCapacityUnits: '1' WriteCapacityUnits: '1' TableName: !Join - '' - - !Ref 'AWS::StackName' - '-EventData' EventProcessorExecutionRole: Type: 'AWS::IAM::Role' Properties: AssumeRolePolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Principal: Service: - lambda.amazonaws.com Action: - 'sts:AssumeRole' Path: / Policies: - PolicyName: EventProcessorExecutionPolicy PolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Action: - 'logs:*' Resource: 'arn:aws:logs:*:*:*' - Effect: Allow Action: - 'dynamodb:BatchWriteItem' - 'dynamodb:PutItem' # Added to cover single-record writes Resource: !Join - '' - - 'arn:aws:dynamodb:' - !Ref 'AWS::Region' - ':' - !Ref 'AWS::AccountId' - ':table/' - !Ref 'AWS::StackName' - '-EventData' ManagedPolicyArns: - 'arn:aws:iam::aws:policy/service-role/AWSLambdaKinesisExecutionRole' streamprocessingclient: Type: 'AWS::IAM::User' ClientPolicy: Type: 'AWS::IAM::Policy' Properties: PolicyName: StreamProcessingClientPolicy PolicyDocument: Version: 2012-10-17 # Added missing policy version Statement: - Effect: Allow Action: - 'kinesis:Put*' Resource: !Join - '' - - 'arn:aws:kinesis:' - !Ref 'AWS::Region' - ':' - !Ref 'AWS::AccountId' - ':stream/' - !Ref EventStream Users: - !Ref streamprocessingclient ClientKeys: Type: 'AWS::IAM::AccessKey' Properties: UserName: !Ref streamprocessingclient Outputs: AccessKeyId: Value: !Ref ClientKeys Description: AWS Access Key Id of stream processing client user SecretAccessKey: Value: !GetAtt - ClientKeys - SecretAccessKey Description: AWS Secret Key of stream processing client user KinesisStream: Value: !Ref EventStream Description: The Kinesis stream used for ingestion. Region: Value: !Ref 'AWS::Region' Description: The region this template was launched in.
Additional Checks to Confirm
- Verify your Lambda code package (
ddb_eventprocessor.zip) exists in the specified S3 bucket (awslambda-reference-architectures) under thestream-processing/prefix. If not, update theLambdaS3BucketandLambdaDDBEventProcessorS3Keyparameters to point to your actual package location. - Ensure your CloudFormation stack name uses lowercase letters (DynamoDB allows uppercase, but lowercase avoids potential naming conflicts in other AWS services).
内容的提问来源于stack exchange,提问作者Chintamani

