gpt4 book ai didi

amazon-web-services - 无法将服务角色策略附加到客户角色。 (服务: AmazonIdentityManagement; Status Code: 400; Error Code: PolicyNotAttachable

转载 作者:行者123 更新时间:2023-12-03 07:39:32 24 4
gpt4 key购买 nike

我正在尝试使用 AWS 托管权限创建具有使用 cloudformation 角色的角色,但出现错误:无法将服务角色策略附加到客户角色。 (服务:AmazonIdentityManagement;状态代码:400;错误代码:PolicyNotAttachable。如有任何帮助,我们将不胜感激

代码片段:

  AutoscalingRole:
Type: AWS::IAM::Role
Properties:
AssumeRolePolicyDocument:
Statement:
- Effect: Allow
Principal:
Service: [application-autoscaling.amazonaws.com]
Action: ['sts:AssumeRole']
ManagedPolicyArns:
- 'arn:aws:iam::aws:policy/aws-service-role/AutoScalingServiceRolePolicy'
ECSRole:
Type: AWS::IAM::Role
Properties:
AssumeRolePolicyDocument:
Version: 2008-10-17
Statement:
- Sid: ''
Effect: Allow
Principal:
Service: ecs.amazonaws.com
Action: 'sts:AssumeRole'
ManagedPolicyArns:
- 'arn:aws:iam::aws:policy/aws-service-role/AmazonEC2ContainerServiceRole'

ECSTaskExecutionRole:
Type: AWS::IAM::Role
Properties:
AssumeRolePolicyDocument:
Statement:
- Effect: Allow
Principal:
Service: [ecs-tasks.amazonaws.com]
Action: ['sts:AssumeRole']
ManagedPolicyArns:
- 'arn:aws:iam::aws:policy/aws-service-role/AmazonECSServiceRolePolicy'

最佳答案

您似乎为管理策略提供了错误的 ARN。我在 aws 控制台中查找了这些内容,得到了:

arn:aws:iam::aws:policy/service-role/AmazonEC2ContainerServiceRole

而不是你的:

arn:aws:iam::aws:policy/aws-service-role/AmazonECSServiceRolePolicy

只需进入 AWS 控制台中的 IAM 策略面板并一一找到它们,每个策略都提供了 arn。

关于amazon-web-services - 无法将服务角色策略附加到客户角色。 (服务: AmazonIdentityManagement; Status Code: 400; Error Code: PolicyNotAttachable,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/73135950/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com