订阅Amazon SNS主题时遇到权限错误
Hey there, let's work through fixing this SNS authorization error you're facing. That "Not Authorized to publish internal endpoints" message usually comes from configuration mismatches or permission gaps—here's a step-by-step breakdown to resolve it:
1. Check Topic Visibility vs. Endpoint Type
This error often pops up when you try to subscribe a VPC-internal endpoint (like an EC2 instance's private IP, VPC endpoint service, or internal HTTP endpoint) to a public SNS topic. Public SNS topics can't send messages to private, VPC-restricted endpoints.
- Fix options:
- Convert your SNS topic to a VPC-specific topic: When creating or editing the topic, associate it with your target VPC (select the VPC and subnets during setup).
- Switch to a public-accessible endpoint: Use a public IP, a Lambda function (which SNS can reach by default), or an SQS queue configured for public access (if applicable).
2. Verify IAM Permissions & Topic Access Policy
Make sure the IAM entity (user/role) you're using to subscribe has the right permissions, and that the SNS topic's access policy allows subscriptions to your target endpoint.
- Ensure your IAM policy includes the
sns:Subscribeaction for the target topic. - Update the SNS topic's access policy to explicitly allow subscriptions and publishing to your endpoint. Here's an example policy snippet (adjust ARNs and endpoint values to match your setup):
{ "Version": "2008-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::123456789012:user/your-iam-user" }, "Action": [ "sns:Subscribe", "sns:Publish" ], "Resource": "arn:aws:sns:us-east-1:123456789012:your-sns-topic", "Condition": { "StringEquals": { "sns:Endpoint": "your-target-endpoint-value" } } } ] }
3. Validate VPC Endpoint Configuration (For Internal Endpoints)
If you're using a VPC-internal endpoint, double-check your SNS VPC endpoint setup:
- Confirm you've created an SNS VPC endpoint in your target VPC, and it's associated with the correct subnets.
- Ensure the VPC endpoint's policy allows
sns:Subscribeand related actions. - Verify your VPC's security groups and network ACLs allow inbound/outbound traffic between SNS and your endpoint (typically ports 80/443 for HTTP/HTTPS endpoints).
4. Confirm Endpoint Accessibility
For HTTP/HTTPS endpoints, make sure SNS can reach the endpoint:
- If it's an internal endpoint, ensure it's in the same VPC as the SNS VPC topic, or connected via VPC peering.
- Check that security groups attached to the endpoint allow incoming traffic from the SNS service or your VPC's CIDR range.
Start with checking the topic's VPC association first—this is the most frequent cause of this specific error.
内容的提问来源于stack exchange,提问作者user1625988

