You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨账号部署CodePipeline遇S3 AccessDenied权限问题求助

跨账号CodePipeline部署S3访问权限错误排查

问题场景

正在执行跨账号部署,已在工具账号中创建CodePipeline,但运行时触发以下权限错误:

The service role or action role doesn’t have the permissions required to access the Amazon S3 bucket named privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck. Update the IAM role permissions, and then try again. Error: Amazon S3:AccessDenied:Access Denied (Service: Amazon S3; Status Code: 403; Error Code: AccessDenied; Request ID: FQ3BP5KY9KDJZ5DX; S3 Extended Request ID: d0Dms19/xoPJBPMwzPPfB0mNXjfYG4CoFZaqN2IvOFt2wivLPj7zNfGx5wosuQMdJ0Q0vxB58Oc=; Proxy: null)

尝试修改IAM权限后问题仍未解决,当前关联的IAM策略如下:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Action": [
                "codepipeline:CreatePipeline",
                "codepipeline:GetPipeline",
                "codepipeline:UpdatePipeline",
                "codepipeline:DeletePipeline",
                "codepipeline:StartPipelineExecution",
                "codepipeline:StopPipelineExecution",
                "iam:ListRoles",
                "cloudformation:DescribeStackResources",
                "cloudformation:DescribeStacks",
                "cloudformation:ListStacks",
                "codecommit:ListRepositories",
                "codecommit:GetBranch",
                "codecommit:GetRepository",
                "codecommit:ListBranches",
                "codecommit:GetCommit",
                "codecommit:GetRepositoryTriggers",
                "codecommit:GitPull",
                "codecommit:UploadArchive",
                "codecommit:CancelUploadArchive",
                "codebuild:BatchGetBuilds",
                "codebuild:StartBuild",
                "cloudformation:CreateStack",
                "cloudformation:DeleteStack",
                "cloudformation:UpdateStack",
                "cloudformation:CreateChangeSet",
                "cloudformation:DeleteChangeSet",
                "cloudformation:DescribeChangeSet",
                "cloudformation:ExecuteChangeSet",
                "cloudformation:SetStackPolicy",
                "cloudformation:ValidateTemplate",
                "iam:PassRole",
                "s3:PutObject",
                "s3:GetBucketPolicy",
                "s3:GetObject",
                "s3:ListBucket",
                "s3:GetBucketLocation",
                "codepipeline:StartPipelineExecution"
            ],
            "Resource": [
                "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck",
                "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck/*",
                "arn:aws:codecommit:us-west-2:009988776655:privacy-events-processor",
                "arn:aws:cloudformation:us-west-2:112233445566:stack/privacy-events-processor-pipeline/fbd3d390-938d-11ef-9870-0a41f2f17491/*",
                "arn:aws:codepipeline:us-west-2:112233445566:privacy-events-processor"
            ],
            "Effect": "Allow"
        },
        {
            "Action": [
                "kms:Decrypt"
            ],
            "Resource": "arn:aws:kms:us-west-2:112233445566:key/a087e598-256a-4c33-893d-315da1a9ee3a",
            "Effect": "Allow"
        },
        {
            "Action": [
                "s3:PutObject",
                "s3:GetBucketPolicy",
                "s3:GetObject",
                "s3:ListBucket"
            ],
            "Resource": [
                "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck/*",
                "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck"
            ],
            "Effect": "Allow"
        },
        {
            "Action": [
                "sts:AssumeRole"
            ],
            "Resource": [
                "arn:aws:iam::009988776655:role/PrivacEventProcessorPipelineCodeCommitRole",
                "arn:aws:iam::009988776655:role/PrivacEventProcessorPipelineCloudFormationRole",
                "arn:aws:iam::112233445566:role/PrivacEventProcessorPipelineCloudFormationRole"
            ],
            "Effect": "Allow"
        }
    ]
}

排查和解决步骤

1. 确认S3桶归属账号,配置跨账号桶权限

  • 先查privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck这个桶属于哪个AWS账号,对比桶ARN里的账号ID和你的工具账号、目标部署账号ID是否一致。
  • 如果桶在目标账号(非工具账号),必须在目标账号的S3桶策略中给工具账号的CodePipeline服务角色开放权限,示例桶策略如下:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::工具账号ID:role/你的CodePipeline服务角色名"
            },
            "Action": [
                "s3:GetObject",
                "s3:PutObject",
                "s3:ListBucket"
            ],
            "Resource": [
                "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck",
                "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck/*"
            ]
        }
    ]
}

2. 检查IAM角色的信任关系是否正确

  • 你的CodePipeline服务角色,必须允许codepipeline.amazonaws.com扮演它,信任策略需配置为:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "codepipeline.amazonaws.com"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}
  • 如果使用了跨账号动作角色(Action Role),要确保该动作角色的信任策略允许工具账号的CodePipeline服务角色进行角色切换。

3. 补充可能缺失的权限

  • 若S3桶启用了KMS加密,当前策略仅配置kms:Decrypt不够,需添加kms:GenerateDataKey权限,对应到你的KMS密钥ARN。
  • CodePipeline可能隐性调用S3:GetBucketVersioning、S3:GetBucketAcl这类权限,如果日志中有相关报错,也需要补充到策略中。

4. 确保权限生效后重试

  • 修改IAM策略后,等待5-10分钟让权限同步生效,再手动触发Pipeline执行。
  • 用IAM的策略模拟工具,验证你的角色确实能对目标S3桶执行所需操作。

内容的提问来源于stack exchange,提问作者hussain hashmi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 14:18:11