使用Terraform创建自定义IAM角色时,如何配置子网ARN权限?
Hey there! Let's break down the issues in your Terraform IAM role config and fix them step by step.
Core Concept Fix: Trust Policy vs. Permissions Policy
First off, a critical mistake here: the assume_role_policy field in aws_iam_role is for defining trust relationships (who/what can assume this role), not for granting permissions to the role itself. You've mixed permission rules into this section, which will break the role's functionality.
Permissions for the role should be attached separately using either an aws_iam_role_policy resource or an aws_iam_policy_attachment.
Fixing Subnet ARN Configuration
Your subnet ARN setup has a few issues:
- Variable typo:
${var.aws_regio}is missing ann— it should be${var.aws_region} - Truncated ARN: Your code cuts off mid-ARN, which will cause JSON parsing errors
- Incomplete resource coverage: For
ec2:RunInstances, you'll need more than just subnet ARNs (like AMIs, security groups, and instance resources) to avoid permission errors
Corrected Full Configuration Example
Here's a properly structured version of your config, with all fixes applied:
# Get current AWS account ID dynamically (avoids hardcoding) data "aws_caller_identity" "current" {} # Define the IAM role with a valid trust policy resource "aws_iam_role" "prod_role" { name = "test_role" # Trust policy: Allow EC2 service to assume this role (adjust based on your use case) assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Effect = "Allow" Principal = { Service = "ec2.amazonaws.com" } Action = "sts:AssumeRole" } ] }) } # Attach permissions to the role resource "aws_iam_role_policy" "prod_role_permissions" { name = "prod-role-permissions" role = aws_iam_role.prod_role.id policy = jsonencode({ Version = "2012-10-17" Statement = [ { Effect = "Allow" Action = ["ec2:Describe*", "ec2:GetConsole*"] Resource = "*" }, { Effect = "Allow" Action = "ec2:RunInstances" Resource = [ # Correct, complete subnet ARNs "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:subnet/${aws_subnet.prod1.id}", "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:subnet/${aws_subnet.prod2.id}", # Additional required resources for RunInstances "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:instance/*", "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:image/*", "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:security-group/*", "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:key-pair/*" ] } ] }) }
Key Notes
- Use
jsonencode: It automatically handles JSON formatting and escaping, avoiding the syntax errors common with raw heredoc strings. - Trust policy flexibility: If you need a different entity (like an IAM user or another AWS account) to assume this role, replace the
Serviceprincipal with the appropriate ARN(s). - RunInstances permissions: AWS requires permissions for all resources involved in launching an instance, not just subnets. The example above includes the most common required resources.
内容的提问来源于stack exchange,提问作者Ken J
相关产品推荐
相关产品推荐

