跨账号部署CodePipeline遇S3 AccessDenied权限问题求助
跨账号CodePipeline部署S3访问权限错误排查
问题场景
正在执行跨账号部署,已在工具账号中创建CodePipeline,但运行时触发以下权限错误:
The service role or action role doesn’t have the permissions required to access the Amazon S3 bucket named privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck. Update the IAM role permissions, and then try again. Error: Amazon S3:AccessDenied:Access Denied (Service: Amazon S3; Status Code: 403; Error Code: AccessDenied; Request ID: FQ3BP5KY9KDJZ5DX; S3 Extended Request ID: d0Dms19/xoPJBPMwzPPfB0mNXjfYG4CoFZaqN2IvOFt2wivLPj7zNfGx5wosuQMdJ0Q0vxB58Oc=; Proxy: null)
尝试修改IAM权限后问题仍未解决,当前关联的IAM策略如下:
{ "Version": "2012-10-17", "Statement": [ { "Action": [ "codepipeline:CreatePipeline", "codepipeline:GetPipeline", "codepipeline:UpdatePipeline", "codepipeline:DeletePipeline", "codepipeline:StartPipelineExecution", "codepipeline:StopPipelineExecution", "iam:ListRoles", "cloudformation:DescribeStackResources", "cloudformation:DescribeStacks", "cloudformation:ListStacks", "codecommit:ListRepositories", "codecommit:GetBranch", "codecommit:GetRepository", "codecommit:ListBranches", "codecommit:GetCommit", "codecommit:GetRepositoryTriggers", "codecommit:GitPull", "codecommit:UploadArchive", "codecommit:CancelUploadArchive", "codebuild:BatchGetBuilds", "codebuild:StartBuild", "cloudformation:CreateStack", "cloudformation:DeleteStack", "cloudformation:UpdateStack", "cloudformation:CreateChangeSet", "cloudformation:DeleteChangeSet", "cloudformation:DescribeChangeSet", "cloudformation:ExecuteChangeSet", "cloudformation:SetStackPolicy", "cloudformation:ValidateTemplate", "iam:PassRole", "s3:PutObject", "s3:GetBucketPolicy", "s3:GetObject", "s3:ListBucket", "s3:GetBucketLocation", "codepipeline:StartPipelineExecution" ], "Resource": [ "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck", "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck/*", "arn:aws:codecommit:us-west-2:009988776655:privacy-events-processor", "arn:aws:cloudformation:us-west-2:112233445566:stack/privacy-events-processor-pipeline/fbd3d390-938d-11ef-9870-0a41f2f17491/*", "arn:aws:codepipeline:us-west-2:112233445566:privacy-events-processor" ], "Effect": "Allow" }, { "Action": [ "kms:Decrypt" ], "Resource": "arn:aws:kms:us-west-2:112233445566:key/a087e598-256a-4c33-893d-315da1a9ee3a", "Effect": "Allow" }, { "Action": [ "s3:PutObject", "s3:GetBucketPolicy", "s3:GetObject", "s3:ListBucket" ], "Resource": [ "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck/*", "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck" ], "Effect": "Allow" }, { "Action": [ "sts:AssumeRole" ], "Resource": [ "arn:aws:iam::009988776655:role/PrivacEventProcessorPipelineCodeCommitRole", "arn:aws:iam::009988776655:role/PrivacEventProcessorPipelineCloudFormationRole", "arn:aws:iam::112233445566:role/PrivacEventProcessorPipelineCloudFormationRole" ], "Effect": "Allow" } ] }
排查和解决步骤
1. 确认S3桶归属账号,配置跨账号桶权限
- 先查
privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck这个桶属于哪个AWS账号,对比桶ARN里的账号ID和你的工具账号、目标部署账号ID是否一致。 - 如果桶在目标账号(非工具账号),必须在目标账号的S3桶策略中给工具账号的CodePipeline服务角色开放权限,示例桶策略如下:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::工具账号ID:role/你的CodePipeline服务角色名" }, "Action": [ "s3:GetObject", "s3:PutObject", "s3:ListBucket" ], "Resource": [ "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck", "arn:aws:s3:::privacy-event-processor-pipeline-km-artifactbucket-ejnoeedwqgck/*" ] } ] }
2. 检查IAM角色的信任关系是否正确
- 你的CodePipeline服务角色,必须允许
codepipeline.amazonaws.com扮演它,信任策略需配置为:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "codepipeline.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }
- 如果使用了跨账号动作角色(Action Role),要确保该动作角色的信任策略允许工具账号的CodePipeline服务角色进行角色切换。
3. 补充可能缺失的权限
- 若S3桶启用了KMS加密,当前策略仅配置
kms:Decrypt不够,需添加kms:GenerateDataKey权限,对应到你的KMS密钥ARN。 - CodePipeline可能隐性调用
S3:GetBucketVersioning、S3:GetBucketAcl这类权限,如果日志中有相关报错,也需要补充到策略中。
4. 确保权限生效后重试
- 修改IAM策略后,等待5-10分钟让权限同步生效,再手动触发Pipeline执行。
- 用IAM的策略模拟工具,验证你的角色确实能对目标S3桶执行所需操作。
内容的提问来源于stack exchange,提问作者hussain hashmi
相关产品推荐
相关产品推荐

