You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

执行AWS CloudFormation模板遇ROLLBACK_COMPLETE错误求排查建议

Hey there! Let's dig into why your CloudFormation stack is rolling back and fix those issues step by step:

1. Outdated Lambda Runtime (Critical Failure Cause)

AWS has long deprecated Node.js 6.10—you can’t deploy Lambda functions using this runtime anymore. This is almost certainly the primary reason your stack rolls back. You need to switch to a supported LTS version like nodejs18.x (or newer, based on your code compatibility needs).

2. Potential DynamoDB Permission Gap

Your current IAM policy for the Lambda role only allows dynamodb:BatchWriteItem, but if your Lambda code uses dynamodb:PutItem (a common pattern for single-record writes), this will throw a permission error. It’s safer to include both actions to cover all write scenarios.

3. Redundant S3 Bucket Reference in Description

The template description mentions an S3 bucket, but your resource list doesn’t include one. This isn’t a functional error, but it’s confusing and should be updated to match the actual resources your template provisions.

4. Best Practice: Add Policy Version to IAM Policy

Your client IAM policy was missing the required Version field, which is a best practice for IAM policy documents.


Here's the revised template with all fixes applied:

AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Description: "Template to set up Kinesis stream, Lambda function, DynamoDB table and related IAM roles/users for real-time stream processing."
Parameters:
  LambdaS3Bucket:
    Type: String
    Default: awslambda-reference-architectures
    Description: Name of S3 bucket where Lambda function packages are stored.
  LambdaDDBEventProcessorS3Key:
    Type : String
    Default : stream-processing/ddb_eventprocessor.zip
    Description : Name of S3 key for Zip with Stream Processing DynamoDB Event Processor Lambda function package.
  LambdaDDBEventProcessorHandler:
    Type : String
    Default : ddb_eventprocessor.handler
    Description : Name of handler for Stream Processing DynamoDB Event Processor Lambda function.
Resources:
  EventStream:
    Type: 'AWS::Kinesis::Stream'
    Properties:
      ShardCount: 1
  DDBEventProcessor:
    Type: 'AWS::Serverless::Function'
    Properties:
      Description: Stream Processing DDB Event Processor
      Handler: !Ref LambdaDDBEventProcessorHandler
      MemorySize: 128
      Role: !GetAtt
        - EventProcessorExecutionRole
        - Arn
      Timeout: 10
      Runtime: nodejs18.x  # Updated to supported runtime
      CodeUri:
        Bucket: !Ref LambdaS3Bucket
        Key: !Ref LambdaDDBEventProcessorS3Key
      Events:
        Stream:
          Type: Kinesis
          Properties:
            Stream: !GetAtt EventStream.Arn
            StartingPosition: TRIM_HORIZON
            BatchSize: 25
  EventDataTable:
    Type: 'AWS::DynamoDB::Table'
    Properties:
      AttributeDefinitions:
        - AttributeName: Username
          AttributeType: S
        - AttributeName: Id
          AttributeType: S
      KeySchema:
        - AttributeName: Username
          KeyType: HASH
        - AttributeName: Id
          KeyType: RANGE
      ProvisionedThroughput:
        ReadCapacityUnits: '1'
        WriteCapacityUnits: '1'
      TableName: !Join
        - ''
        - - !Ref 'AWS::StackName'
          - '-EventData'
  EventProcessorExecutionRole:
    Type: 'AWS::IAM::Role'
    Properties:
      AssumeRolePolicyDocument:
        Version: 2012-10-17
        Statement:
          - Effect: Allow
            Principal:
              Service:
                - lambda.amazonaws.com
            Action:
              - 'sts:AssumeRole'
      Path: /
      Policies:
        - PolicyName: EventProcessorExecutionPolicy
          PolicyDocument:
            Version: 2012-10-17
            Statement:
              - Effect: Allow
                Action:
                  - 'logs:*'
                Resource: 'arn:aws:logs:*:*:*'
              - Effect: Allow
                Action:
                  - 'dynamodb:BatchWriteItem'
                  - 'dynamodb:PutItem'  # Added to cover single-record writes
                Resource: !Join
                  - ''
                  - - 'arn:aws:dynamodb:'
                    - !Ref 'AWS::Region'
                    - ':'
                    - !Ref 'AWS::AccountId'
                    - ':table/'
                    - !Ref 'AWS::StackName'
                    - '-EventData'
      ManagedPolicyArns:
        - 'arn:aws:iam::aws:policy/service-role/AWSLambdaKinesisExecutionRole'
  streamprocessingclient:
    Type: 'AWS::IAM::User'
  ClientPolicy:
    Type: 'AWS::IAM::Policy'
    Properties:
      PolicyName: StreamProcessingClientPolicy
      PolicyDocument:
        Version: 2012-10-17  # Added missing policy version
        Statement:
          - Effect: Allow
            Action:
              - 'kinesis:Put*'
            Resource: !Join
              - ''
              - - 'arn:aws:kinesis:'
                - !Ref 'AWS::Region'
                - ':'
                - !Ref 'AWS::AccountId'
                - ':stream/'
                - !Ref EventStream
      Users:
        - !Ref streamprocessingclient
  ClientKeys:
    Type: 'AWS::IAM::AccessKey'
    Properties:
      UserName: !Ref streamprocessingclient
Outputs:
  AccessKeyId:
    Value: !Ref ClientKeys
    Description: AWS Access Key Id of stream processing client user
  SecretAccessKey:
    Value: !GetAtt
      - ClientKeys
      - SecretAccessKey
    Description: AWS Secret Key of stream processing client user
  KinesisStream:
    Value: !Ref EventStream
    Description: The Kinesis stream used for ingestion.
  Region:
    Value: !Ref 'AWS::Region'
    Description: The region this template was launched in.

Additional Checks to Confirm

  • Verify your Lambda code package (ddb_eventprocessor.zip) exists in the specified S3 bucket (awslambda-reference-architectures) under the stream-processing/ prefix. If not, update the LambdaS3Bucket and LambdaDDBEventProcessorS3Key parameters to point to your actual package location.
  • Ensure your CloudFormation stack name uses lowercase letters (DynamoDB allows uppercase, but lowercase avoids potential naming conflicts in other AWS services).

内容的提问来源于stack exchange,提问作者Chintamani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:16:23