我正试图按照此处的说明创建IAM策略。
当我尝试添加此策略时
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"route53:ChangeResourceRecordSets"
],
"Resource": [
"arn:aws:route53:::hostedzone/*"
]
},
{
"Effect": "Allow",
"Action": [
"route53:ListHostedZones",
"route53:ListResourceRecordSets"
],
"Resource": [
"*"
]
}
]
}
使用此命令:
aws iam create-role --role-name externaldns --assume-role-policy-document file://external_dns.json
我得到以下错误
An error occurred (MalformedPolicyDocument) when calling the CreateRole operation: Has prohibited field Resource
我希望得到这方面的指导。
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"route53:ChangeResourceRecordSets"
],
"Resource": [
"arn:aws:route53:::hostedzone/*"
],
},
{
"Effect": "Allow",
"Action": [
"route53:ListHostedZones",
"route53:ListResourceRecordSets"
],
"Resource": [
"*"
],
}
]
}
您忘记了"Resource":[],
之后的两个,
字符。