You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

创建含IAM策略的CloudFormation栈时遇InsufficientCapabilitiesException错误

Fixing InsufficientCapabilitiesException for Named IAM Resources in CloudFormation

I’ve run into this exact issue before—let’s get it sorted out quickly.

The Root Cause

When your CloudFormation template creates named IAM resources (like IAM users, roles, or policies that have an explicit Name property defined), AWS requires you to explicitly acknowledge the associated risk with the CAPABILITY_NAMED_IAM capability. The CAPABILITY_IAM flag you used only covers unnamed IAM resources (where CloudFormation generates a unique auto-name for the resource).

The Fix

Update your create-stack command to use CAPABILITY_NAMED_IAM instead of (or in addition to) CAPABILITY_IAM:

aws cloudformation create-stack --stack-name iam-stack --template-body file://./iam.yml --capabilities CAPABILITY_NAMED_IAM --profile dev

If your template includes both named and unnamed IAM resources, you can specify both capabilities together:

aws cloudformation create-stack --stack-name iam-stack --template-body file://./iam.yml --capabilities CAPABILITY_IAM CAPABILITY_NAMED_IAM --profile dev

Quick Recap of IAM Capabilities

  • CAPABILITY_IAM: Grants permission to create IAM resources with auto-generated names (lower risk, no chance of conflicting with existing resources)
  • CAPABILITY_NAMED_IAM: Grants permission to create IAM resources with custom names (higher risk, as names could clash with existing resources or expose sensitive permissions)

内容的提问来源于stack exchange,提问作者David Webster

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:06:29