You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform创建自定义IAM角色时,如何配置子网ARN权限?

Hey there! Let's break down the issues in your Terraform IAM role config and fix them step by step.

Core Concept Fix: Trust Policy vs. Permissions Policy

First off, a critical mistake here: the assume_role_policy field in aws_iam_role is for defining trust relationships (who/what can assume this role), not for granting permissions to the role itself. You've mixed permission rules into this section, which will break the role's functionality.

Permissions for the role should be attached separately using either an aws_iam_role_policy resource or an aws_iam_policy_attachment.

Fixing Subnet ARN Configuration

Your subnet ARN setup has a few issues:

  • Variable typo: ${var.aws_regio} is missing an n — it should be ${var.aws_region}
  • Truncated ARN: Your code cuts off mid-ARN, which will cause JSON parsing errors
  • Incomplete resource coverage: For ec2:RunInstances, you'll need more than just subnet ARNs (like AMIs, security groups, and instance resources) to avoid permission errors
Corrected Full Configuration Example

Here's a properly structured version of your config, with all fixes applied:

# Get current AWS account ID dynamically (avoids hardcoding)
data "aws_caller_identity" "current" {}

# Define the IAM role with a valid trust policy
resource "aws_iam_role" "prod_role" {
  name = "test_role"
  # Trust policy: Allow EC2 service to assume this role (adjust based on your use case)
  assume_role_policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Effect = "Allow"
        Principal = {
          Service = "ec2.amazonaws.com"
        }
        Action = "sts:AssumeRole"
      }
    ]
  })
}

# Attach permissions to the role
resource "aws_iam_role_policy" "prod_role_permissions" {
  name   = "prod-role-permissions"
  role   = aws_iam_role.prod_role.id

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Effect   = "Allow"
        Action   = ["ec2:Describe*", "ec2:GetConsole*"]
        Resource = "*"
      },
      {
        Effect = "Allow"
        Action = "ec2:RunInstances"
        Resource = [
          # Correct, complete subnet ARNs
          "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:subnet/${aws_subnet.prod1.id}",
          "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:subnet/${aws_subnet.prod2.id}",
          # Additional required resources for RunInstances
          "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:instance/*",
          "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:image/*",
          "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:security-group/*",
          "arn:aws:ec2:${var.aws_region}:${data.aws_caller_identity.current.account_id}:key-pair/*"
        ]
      }
    ]
  })
}
Key Notes
  • Use jsonencode: It automatically handles JSON formatting and escaping, avoiding the syntax errors common with raw heredoc strings.
  • Trust policy flexibility: If you need a different entity (like an IAM user or another AWS account) to assume this role, replace the Service principal with the appropriate ARN(s).
  • RunInstances permissions: AWS requires permissions for all resources involved in launching an instance, not just subnets. The example above includes the most common required resources.

内容的提问来源于stack exchange,提问作者Ken J

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:25:27