使用Terraform在Route53创建A记录遇权限拒绝,求排查方案
Hey there, let's break down why you're running into that Access Denied error when trying to create an A record with Terraform. I’ve worked through similar issues with older Terraform versions, so here are the key areas to check:
1. Implicit AWS Provider Credential Handling
Even though you didn’t define a provider "aws" block, Terraform (especially older versions like 0.8.4 and 0.11.3) will still implicitly use the AWS provider when you’re creating AWS resources like aws_route53_record. This means it needs valid AWS credentials to authenticate, but sometimes implicit handling can be finicky.
- Try adding a minimal explicit provider block: This ensures Terraform uses the credentials you expect (from environment variables,
~/.aws/credentials, or instance profile). For 0.11.x, it looks like this:provider "aws" { region = "us-east-1" # Replace with your target region # Credentials will pull from your default AWS config sources } - Verify credential sources: Make sure the credentials associated with your CLI are set correctly via:
- Environment variables (
AWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEY) - The
~/.aws/credentialsfile (check that you’re using the right profile if you have multiple) - Instance profile (if running on an EC2 instance with an IAM role attached)
- Environment variables (
2. IAM Permissions for Route53
Your IAM user’s policy might be missing critical actions needed to create Route53 records. The minimum permissions required are:
route53:ChangeResourceRecordSets(to create/update the A record)route53:ListHostedZones(to locate your target hosted zone)route53:GetHostedZone(if you’re referencing the zone by name instead of ID)
Double-check your policy to ensure these actions are allowed for your specific hosted zone. Here’s an example policy snippet to validate against:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "route53:ChangeResourceRecordSets", "route53:ListHostedZones", "route53:GetHostedZone" ], "Resource": [ "arn:aws:route53:::hostedzone/YOUR_HOSTED_ZONE_ID", "arn:aws:route53:::hostedzone/*" # Use this temporarily for testing ] } ] }
3. Terraform Version Bugs & Compatibility
Versions 0.8.4 and 0.11.3 are quite old (released in 2017 and 2018 respectively). These versions might have known bugs around credential handling or AWS API compatibility:
- Try upgrading to the latest patch in the 0.11.x line (0.11.15 is the final release) — this fixes many credential-related issues from earlier 0.11 versions.
- If possible, test with a newer Terraform version (though note that 0.12+ uses different syntax, so you’d need to adjust your code accordingly).
4. Validate Credentials Directly with AWS CLI
Before assuming it’s a Terraform issue, confirm your credentials work with the AWS CLI directly:
- Run
aws route53 list-hosted-zones— if this fails with Access Denied, your IAM policy or credentials are the problem. - Try creating an A record manually with the CLI using a change batch file:
Whereaws route53 change-resource-record-sets --hosted-zone-id YOUR_ZONE_ID --change-batch file://record.jsonrecord.jsoncontains:{ "Comment": "Test A record", "Changes": [ { "Action": "CREATE", "ResourceRecordSet": { "Name": "test.yourdomain.com", "Type": "A", "TTL": 300, "ResourceRecords": [{"Value": "192.168.1.1"}] } } ] }
If these CLI commands work but Terraform doesn’t, the issue is how Terraform is picking up your credentials.
5. Check Your Terraform Resource Configuration
Make sure your aws_route53_record block is correctly formatted for your Terraform version. For 0.11.x, a valid example looks like this:
resource "aws_route53_record" "my_a_record" { zone_id = "YOUR_HOSTED_ZONE_ID" name = "test.yourdomain.com" type = "A" ttl = "300" records = ["192.168.1.1"] }
Double-check that the zone_id matches your Route53 hosted zone ID, and the name is correctly formatted (matches the domain in your hosted zone).
内容的提问来源于stack exchange,提问作者efg

