【问题标题】:Trying to create an IAM policy with terraform getting a syntax error but cant see it尝试使用 terraform 创建 IAM 策略时出现语法错误但看不到它
【发布时间】:2023-02-02 04:52:55
【问题描述】:

我正在使用多个 data "aws_iam_policy_document" 项目扩展高级用户角色:

data "aws_iam_policy" "policy_poweruser" {
  arn = "arn:aws:iam::aws:policy/PowerUserAccess"
}

data "aws_iam_policy_document" "poweruser_extended_passrole" {
  source_policy_documents = [data.aws_iam_policy.policy_poweruser.policy]
  statement {
    sid       = "passec2basic"
    effect    = "Allow"
    actions   = ["iam:passrole"]
    resources = ["arn:aws:iam::238423423:role/ec2_basic"]
  }
}

data "aws_iam_policy_document" "poweruser_extended_prod" {
  source_policy_documents = [data.aws_iam_policy_document.poweruser_extended_passrole.json]
  statement {
    sid       = "environmentaccess"
    effect    = "Allow"
    actions   = local.gated_actions
    resources = ["*"]
    condition {
      test     = "stringequals"
      variable = "aws:resourcetag/environment"
      values   = ["prod"]
    }
  }
}

terraform plan 的结果是

 + policy      = jsonencode(
            {
              + Statement = [
                  + {
                      + Effect    = "Allow"
                      + NotAction = [
                          + "iam:*",
                          + "organizations:*",
                          + "account:*",
                        ]
                      + Resource  = "*"
                      + Sid       = ""
                    },
                  + {
                      + Action   = [
                          + "iam:CreateServiceLinkedRole",
                          + "iam:DeleteServiceLinkedRole",
                          + "iam:ListRoles",
                          + "organizations:DescribeOrganization",
                          + "account:ListRegions",
                        ]
                      + Effect   = "Allow"
                      + Resource = "*"
                      + Sid      = ""
                    },
                  + {
                      + Action   = "iam:passrole"
                      + Effect   = "Allow"
                      + Resource = "arn:aws:iam::353532242242:role/ec2_basic"
                      + Sid      = "passec2basic"
                    },
                  + {
                      + Action    = [
                          + "ssm:*",
                          + "cloudformation:*",
                        ]
                      + Condition = {
                          + stringequals = {
                              + "aws:resourcetag/environment" = "prod"
                            }
                        }
                      + Effect    = "Allow"
                      + Resource  = "*"
                      + Sid       = "environmentaccess"
                    },
                ]
              + Version   = "2012-10-17"
            }
        )

结果是

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "",
      "Effect": "Allow",
      "NotAction": [
        "iam:*",
        "organizations:*",
        "account:*"
      ],
      "Resource": "*"
    },
    {
      "Sid": "",
      "Effect": "Allow",
      "Action": [
        "iam:CreateServiceLinkedRole",
        "iam:DeleteServiceLinkedRole",
        "iam:ListRoles",
        "organizations:DescribeOrganization",
        "account:ListRegions"
      ],
      "Resource": "*"
    },
    {
      "Sid": "passEc2Basic",
      "Effect": "Allow",
      "Action": "iam:PassRole",
      "Resource": "arn:aws:iam::496396001060:role/ec2_basic"
    },
    {
      "Sid": "environmentAccess",
      "Effect": "Allow",
      "Action": [
        "ssm:*",
        "cloudformation:*"
      ],
      "Resource": "*",
      "Condition": {
        "StringEquals": {
          "aws:ResourceTag/Environment": "prod"
        }
      }
    }
  ]
}

我已经在控制台中检查过它并且它有效。

那么,这个错误是从哪里来的呢?

: error creating IAM Policy foo_user_prod: MalformedPolicyDocument: Syntax errors in policy.

【问题讨论】:

  • 您可以使用添加策略的方式添加资源/数据源吗?但乍一看,这可能是因为您有两次相同的Sid,即"Sid": ""。
  • @MarkoE 添加。多个数据资源的原因是我正在构建不止一个变体策略(非产品有一个不等于)。我还相信空白的 SID 来自我正在采购的 poweruser 角色
  • API报错信息确实不大,但是你有没有试过控制台中的validator?
  • @JoshBeauregard 是的,它可能就是它的来源。您介意为要分配此策略的角色添加代码吗?我想尝试重现它。
  • 你到底在哪里创建foo_user_prod?你还没有显示它的定义。

标签: json terraform amazon-iam terraform-provider-aws


【解决方案1】:

问题来自 data.aws_iam_policy_document.poweruser_extended_prod 定义中的 condition。

Terraform 对其条件使用稍微偏离的语法。 将测试值从stringequals改为ForAnyValue:StringEquals解决了语法错误的问题。

【讨论】:

    猜你喜欢
    • 2017-11-02
    • 2017-07-27
    • 2021-05-13
    • 1970-01-01
    • 2020-09-22
    • 2017-11-26
    • 2018-08-25
    • 2022-01-19
    • 1970-01-01
    相关资源
    最近更新 更多