使用AWS CLI创建Spot实例遇权限错误及IamInstanceProfile参数疑问
Let's work through your issue step by step and clear up the confusion around the IamInstanceProfile parameter:
1. Why the UnauthorizedOperation error occurs (and how to fix it)
The fact that you can create Spot instances via the EC2 GUI but not the CLI points directly to a permission mismatch between the credentials your CLI uses and the ones powering your GUI session.
Here's what to check:
- Your CLI command uses
--profile "", meaning it falls back to your default AWS credentials (stored in~/.aws/credentialsor environment variables). The IAM user/role linked to these credentials likely lacks the required permissions forec2:RequestSpotInstancesand related actions likeec2:RunInstances,ec2:CreateTags, etc. - Your GUI session, on the other hand, uses an IAM entity (user/role) that already has the full set of permissions needed for Spot instance creation.
How to verify and fix permissions:
- First, confirm which principal your CLI is using with this command:
aws sts get-caller-identity --profile "" - Next, test if this principal has the necessary permissions with:
aws iam simulate-principal-policy \ --policy-source-arn arn:aws:iam::YOUR_ACCOUNT_ID:user/CLI_USER_NAME \ --action-names ec2:RequestSpotInstances ec2:RunInstances ec2:CreateTags - If the simulation shows denied actions, update the IAM policy attached to your CLI principal to match the permissions that work for your GUI session.
2. Critical syntax errors in your param.json
Even after fixing permissions, your JSON file has two issues that will cause failures:
- Missing comma after the
UserDataline:// Wrong "UserData":"file:://my_script.txt" // Correct "UserData":"file://my_script.txt", - Double colon in
file:://—it should be a single colon (file://) to properly reference your local script file.
3. Is IamInstanceProfile a required parameter?
No, it's not required. You already confirmed this by successfully creating a Spot instance via the GUI without specifying it. This parameter only matters if you want the instance to assume an IAM role at launch—your error has nothing to do with missing this field.
Final Steps to Resolve
- Fix the syntax errors in
param.jsonas noted above. - Ensure your CLI's default credentials are linked to an IAM entity with the same permissions as your GUI session.
- Re-run your CLI command, and it should work as expected.
内容的提问来源于stack exchange,提问作者Ashish Mittal

