首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >创建自定义运行实例策略出错

创建自定义运行实例策略出错
EN

Stack Overflow用户
提问于 2014-03-05 12:52:09
回答 1查看 291关注 0票数 2

我是AWS的IAM新手。我已经创建了一个策略

代码语言:javascript
复制
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "TheseActionsDontSupportResourceLevelPermissions",
      "Effect": "Allow",
      "Action": "ec2:DescribeImages",
      "Resource": "*"
    },
    {
      "Sid": "TheseActionsSupportResourceLevelPermissions",
      "Effect": "Allow",
      "Action": "ec2:RunInstances",
      "Resource": [
         "arn:aws:ec2:us-east-1:109027:instance/*",
         "arn:aws:ec2:us-east-1:10927:image/*",
         "arn:aws:ec2:us-east-1:109027:security-group/Test_hin",
         "arn:aws:ec2:us-east-1:109027:subnet/subnet-b",
         "arn:aws:ec2:us-east-1:109527:key-pair/*",
         "arn:aws:ec2:us-east-1:10903527:network-interface/vpc-e4",
         "arn:aws:ec2:us-east-1:107:volume/*"
       ]
     }
   ]
}

每当我尝试使用控制台启动一个实例时,它都会提示我没有被授权执行此操作的错误。

谢谢

EN

回答 1

Stack Overflow用户

发布于 2014-03-05 13:17:31

尝试使用key pairnetwork interface资源(看起来您正在尝试启动到VPC)。另外,允许卷资源。

代码语言:javascript
复制
{
    "Version": "2012-10-17",
    "Statement": [
    {
       "Effect": "Allow",
       "Action": "ec2:RunInstances",
       "Resource": [
         "arn:aws:ec2:us-east-1:acct:instance/*",
         "arn:aws:ec2:us-east-1:acct:image/*",
         "arn:aws:ec2:us-east-1:acct:security-group/*",
         "arn:aws:ec2:us-east-1:acct:subnet/*",
         "arn:aws:ec2:us-east-1:acct:key-pair/*",
         "arn:aws:ec2:us-east-1:acct:network-interface/*",
         "arn:aws:ec2:us-east-1:acct:volume/*"
       ]
     }
   ]
}
票数 0
EN
页面原文内容由Stack Overflow提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://stackoverflow.com/questions/22188860

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档