You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法共享AppSync所有权:AWS新手技术求助

Fixing AppSync Access Sharing Issues in AWS Organizations

Hey there! I’ve helped a few folks work through this exact scenario—since you’ve already got your AWS Organization set up with full features and added your colleague, let’s walk through the common gaps that might be blocking access to your AppSync service:

1. Ensure IAM Entities Have AppSync-Specific Permissions

Just adding your colleague to the organization doesn’t automatically grant them access to AppSync. You’ll need to attach IAM policies to their user (or a group they’re part of) that explicitly allow AppSync actions.

For example, if you want to give them read-only access to your API, you can create a custom policy like this:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "appsync:ListGraphqlApis",
        "appsync:GetGraphqlApi",
        "appsync:GetSchemaCreationStatus"
      ],
      "Resource": "arn:aws:appsync:<your-region>:<your-account-id>:apis/<your-api-id>/*"
    }
  ]
}

If they need full management access, you can use AWS’s managed policy AWSAppSyncFullAccess instead—just make sure it’s attached to their IAM identity.

2. Check Organization Service Control Policies (SCPs)

Even with full organization features enabled, SCPs can override IAM permissions. Head to the AWS Organizations console, navigate to the OU where your colleague’s account lives, and check the attached SCPs.

Look for any policies with "Effect": "Deny" that include AppSync actions (like appsync:*). If you find one, either adjust it to allow the necessary actions or detach it temporarily to test if that’s the blocker.

3. Update Your AppSync API’s Resource Policy

AppSync has its own resource policy that controls cross-account access. If your colleague is in a different account within your organization, you’ll need to explicitly allow their account in this policy.

Go to your AppSync API’s settings in the console, find the Resource policy section, and add a statement like this:

{
  "Effect": "Allow",
  "Principal": {
    "AWS": "arn:aws:iam::<colleague-account-id>:root"
  },
  "Action": "appsync:*",
  "Resource": "arn:aws:appsync:<your-region>:<your-account-id>:apis/<your-api-id>/*"
}

This grants their entire account access to your API—you can narrow it down to specific IAM users/roles if needed by replacing the root ARN with their user/role ARN.

4. Test with Minimal Permissions First

To troubleshoot, start small: grant your colleague just the appsync:ListGraphqlApis permission and have them try listing APIs via the AWS Console or CLI command:

aws appsync list-graphql-apis --region <your-region>

If that works, gradually add more permissions until you reach the level they need. If it fails, double-check the SCPs and resource policy for any denials.


内容的提问来源于stack exchange,提问作者user3618914

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 08:18:27