无法共享AppSync所有权:AWS新手技术求助
Hey there! I’ve helped a few folks work through this exact scenario—since you’ve already got your AWS Organization set up with full features and added your colleague, let’s walk through the common gaps that might be blocking access to your AppSync service:
1. Ensure IAM Entities Have AppSync-Specific Permissions
Just adding your colleague to the organization doesn’t automatically grant them access to AppSync. You’ll need to attach IAM policies to their user (or a group they’re part of) that explicitly allow AppSync actions.
For example, if you want to give them read-only access to your API, you can create a custom policy like this:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "appsync:ListGraphqlApis", "appsync:GetGraphqlApi", "appsync:GetSchemaCreationStatus" ], "Resource": "arn:aws:appsync:<your-region>:<your-account-id>:apis/<your-api-id>/*" } ] }
If they need full management access, you can use AWS’s managed policy AWSAppSyncFullAccess instead—just make sure it’s attached to their IAM identity.
2. Check Organization Service Control Policies (SCPs)
Even with full organization features enabled, SCPs can override IAM permissions. Head to the AWS Organizations console, navigate to the OU where your colleague’s account lives, and check the attached SCPs.
Look for any policies with "Effect": "Deny" that include AppSync actions (like appsync:*). If you find one, either adjust it to allow the necessary actions or detach it temporarily to test if that’s the blocker.
3. Update Your AppSync API’s Resource Policy
AppSync has its own resource policy that controls cross-account access. If your colleague is in a different account within your organization, you’ll need to explicitly allow their account in this policy.
Go to your AppSync API’s settings in the console, find the Resource policy section, and add a statement like this:
{ "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::<colleague-account-id>:root" }, "Action": "appsync:*", "Resource": "arn:aws:appsync:<your-region>:<your-account-id>:apis/<your-api-id>/*" }
This grants their entire account access to your API—you can narrow it down to specific IAM users/roles if needed by replacing the root ARN with their user/role ARN.
4. Test with Minimal Permissions First
To troubleshoot, start small: grant your colleague just the appsync:ListGraphqlApis permission and have them try listing APIs via the AWS Console or CLI command:
aws appsync list-graphql-apis --region <your-region>
If that works, gradually add more permissions until you reach the level they need. If it fails, double-check the SCPs and resource policy for any denials.
内容的提问来源于stack exchange,提问作者user3618914

