You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform在Route53创建A记录遇权限拒绝,求排查方案

Troubleshooting Terraform Route53 A Record Access Denied Error

Hey there, let's break down why you're running into that Access Denied error when trying to create an A record with Terraform. I’ve worked through similar issues with older Terraform versions, so here are the key areas to check:

1. Implicit AWS Provider Credential Handling

Even though you didn’t define a provider "aws" block, Terraform (especially older versions like 0.8.4 and 0.11.3) will still implicitly use the AWS provider when you’re creating AWS resources like aws_route53_record. This means it needs valid AWS credentials to authenticate, but sometimes implicit handling can be finicky.

  • Try adding a minimal explicit provider block: This ensures Terraform uses the credentials you expect (from environment variables, ~/.aws/credentials, or instance profile). For 0.11.x, it looks like this:
    provider "aws" {
      region = "us-east-1" # Replace with your target region
      # Credentials will pull from your default AWS config sources
    }
    
  • Verify credential sources: Make sure the credentials associated with your CLI are set correctly via:
    • Environment variables (AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY)
    • The ~/.aws/credentials file (check that you’re using the right profile if you have multiple)
    • Instance profile (if running on an EC2 instance with an IAM role attached)

2. IAM Permissions for Route53

Your IAM user’s policy might be missing critical actions needed to create Route53 records. The minimum permissions required are:

  • route53:ChangeResourceRecordSets (to create/update the A record)
  • route53:ListHostedZones (to locate your target hosted zone)
  • route53:GetHostedZone (if you’re referencing the zone by name instead of ID)

Double-check your policy to ensure these actions are allowed for your specific hosted zone. Here’s an example policy snippet to validate against:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "route53:ChangeResourceRecordSets",
        "route53:ListHostedZones",
        "route53:GetHostedZone"
      ],
      "Resource": [
        "arn:aws:route53:::hostedzone/YOUR_HOSTED_ZONE_ID",
        "arn:aws:route53:::hostedzone/*" # Use this temporarily for testing
      ]
    }
  ]
}

3. Terraform Version Bugs & Compatibility

Versions 0.8.4 and 0.11.3 are quite old (released in 2017 and 2018 respectively). These versions might have known bugs around credential handling or AWS API compatibility:

  • Try upgrading to the latest patch in the 0.11.x line (0.11.15 is the final release) — this fixes many credential-related issues from earlier 0.11 versions.
  • If possible, test with a newer Terraform version (though note that 0.12+ uses different syntax, so you’d need to adjust your code accordingly).

4. Validate Credentials Directly with AWS CLI

Before assuming it’s a Terraform issue, confirm your credentials work with the AWS CLI directly:

  1. Run aws route53 list-hosted-zones — if this fails with Access Denied, your IAM policy or credentials are the problem.
  2. Try creating an A record manually with the CLI using a change batch file:
    aws route53 change-resource-record-sets --hosted-zone-id YOUR_ZONE_ID --change-batch file://record.json
    
    Where record.json contains:
    {
      "Comment": "Test A record",
      "Changes": [
        {
          "Action": "CREATE",
          "ResourceRecordSet": {
            "Name": "test.yourdomain.com",
            "Type": "A",
            "TTL": 300,
            "ResourceRecords": [{"Value": "192.168.1.1"}]
          }
        }
      ]
    }
    

If these CLI commands work but Terraform doesn’t, the issue is how Terraform is picking up your credentials.

5. Check Your Terraform Resource Configuration

Make sure your aws_route53_record block is correctly formatted for your Terraform version. For 0.11.x, a valid example looks like this:

resource "aws_route53_record" "my_a_record" {
  zone_id = "YOUR_HOSTED_ZONE_ID"
  name    = "test.yourdomain.com"
  type    = "A"
  ttl     = "300"
  records = ["192.168.1.1"]
}

Double-check that the zone_id matches your Route53 hosted zone ID, and the name is correctly formatted (matches the domain in your hosted zone).


内容的提问来源于stack exchange,提问作者efg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:24:21