You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudFormation模板创建含内联策略的IAM角色报错:PolicyDocument不能为空

解决CloudFormation创建IAM角色时内联策略报错“Property PolicyDocument cannot be empty.”的问题

这个报错我之前也碰到过,核心原因就是你的内联策略里PolicyDocument要么是空结构,要么格式错误导致CloudFormation识别不到有效内容。下面是几个常见的排查和修复方向:

1. 直接检查PolicyDocument是否为空

最常见的情况就是不小心把PolicyDocument写成了空对象,或者完全没给它加内容。比如这种错误写法:

Resources:
  MyIAMRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service: ec2.amazonaws.com
            Action: sts:AssumeRole
      Policies:
        - PolicyName: MyBrokenInlinePolicy
          PolicyDocument: {} # 这里是空对象,直接触发报错

修复的话,给PolicyDocument加上完整的IAM策略内容就行:

Resources:
  MyIAMRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service: ec2.amazonaws.com
            Action: sts:AssumeRole
      Policies:
        - PolicyName: MyWorkingInlinePolicy
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Effect: Allow
                Action: s3:ListBucket
                Resource: arn:aws:s3:::my-target-bucket

2. 排查YAML缩进问题(针对YAML模板)

YAML对缩进极其敏感,如果PolicyDocument下面的Version、Statement缩进层级不对,CloudFormation会认为PolicyDocument没有子内容,等同于空。比如这种错误缩进:

Policies:
  - PolicyName: MyMisIndentedPolicy
    PolicyDocument:
Version: '2012-10-17' # 这里缩进和PolicyDocument平级了,不属于它的内容
Statement:
  - Effect: Allow
    Action: s3:GetObject

修复后要确保Version和Statement都缩进在PolicyDocument的范围内,比如上面的代码要改成:

Policies:
  - PolicyName: MyFixedPolicy
    PolicyDocument:
      Version: '2012-10-17'
      Statement:
        - Effect: Allow
          Action: s3:GetObject
          Resource: arn:aws:s3:::my-target-bucket/*

3. 检查是否引用了空的参数/映射

如果你是通过!Ref或者!FindInMap来引用PolicyDocument的内容,要确保被引用的参数/映射不是空值。比如这种错误场景:

Parameters:
  MyPolicyContent:
    Type: String
    Default: '' # 空字符串,导致引用后PolicyDocument为空
Resources:
  MyIAMRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument: ...
      Policies:
        - PolicyName: MyReferencedPolicy
          PolicyDocument: !Ref MyPolicyContent

这种情况要给参数赋值有效的JSON格式策略内容,或者直接在模板里写死PolicyDocument。

4. 确认内联策略的语法结构

别把托管策略和内联策略的写法搞混了:托管策略用ManagedPolicyArns列表放ARN,而内联策略必须放在Policies列表里,每个元素必须同时包含PolicyName和PolicyDocument两个属性,缺一个或者格式不对都会出问题。

先从这几个方向排查,大部分情况下都能解决问题。如果还是搞不定,可以把你的模板片段贴出来,我再帮你细瞅。

内容的提问来源于stack exchange,提问作者nad87563

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:03:59