【发布时间】:2017-11-02 17:09:17
【问题描述】:
我正在尝试通过AWS CLI 创建托管策略:
POLICY='
{
"Version":"2012-10-17",
"Statement":
[{
"Effect":"Allow",
"Action":
[
"cloudformation:*"
],
"Resource":"*"
},
{
"Effect":"Deny",
"Action":
[
"cloudformation:UpdateStack",
"cloudformation:DeleteStack"
],
"Resource": "'${arn}'"
}]
}'
# Create policy if not already created
[ $(aws iam list-policies | grep -ce CloudFormation-policy-${StackName}) -eq 0 ] && (aws iam create-policy --policy-name CloudFormation-policy-${StackName} --policy-document "'${POLICY}'")
当我运行脚本时出现此错误:
An error occurred (MalformedPolicyDocument) when calling the CreatePolicy operation: Syntax errors in policy.
我不知道错误在哪里。 有什么想法吗?
【问题讨论】:
-
您是否尝试从 CLI 运行它?您是否在 AWS 控制台中验证了这一点?我的猜测是这个问题是由于单引号和双引号引起的。
-
是的,它来自 CLI。当我做
echo "'${POLICY}'"时,我会用简单的引号得到 json -
您的 CLI 在哪个操作系统上运行? Windows、Linux 还是 Mac?
-
Linux ubuntu 16
-
在您花时间进行调试之前,如果您可以访问 AWS 控制台,我建议您尝试使用它创建一个策略并确保它在那里通过验证,确认 json 是正确的。一旦 JSON 验证完成,对于命令行 json 参数,我建议使用这种方法(文件中的参数)docs.aws.amazon.com/cli/latest/userguide/…
标签: json shell amazon-web-services amazon-cloudformation amazon-iam