使用aws ec2 wait命令所需的IAM权限是什么?
aws ec2 wait Commands Great question! The confusion here comes from the fact that there are no dedicated "wait" permissions in AWS IAM. Instead, aws ec2 wait commands work by repeatedly polling the corresponding EC2 API operations until the desired state is reached.
For your specific case with aws ec2 wait instance-running, the command relies entirely on the ec2:DescribeInstances permission. That's why you won't see any "wait" entries in the IAM permission list or the CLI docs—because it's just using the existing describe action under the hood.
To fix the authorization error, you need to grant your IAM entity (user/role) the ec2:DescribeInstances permission. Here's a minimal example IAM policy snippet that would allow this:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "ec2:DescribeInstances", "Resource": "*" } ] }
As a general rule, every aws ec2 wait command maps to one or more EC2 "Describe" actions. For example:
aws ec2 wait volume-availableusesec2:DescribeVolumesaws ec2 wait snapshot-completedusesec2:DescribeSnapshotsaws ec2 wait instance-terminatedalso usesec2:DescribeInstances
So whenever you're unsure about which permission a wait command needs, just check what underlying describe operation it's polling—those are the permissions you need to grant.
内容的提问来源于stack exchange,提问作者Vao Tsun

