配置正确Bucket Policy仍出现跨账号S3访问拒绝问题
S3跨账号访问配置异常:Account B指定IAM用户访问被拒绝
我正在配置S3存储桶的跨账号访问权限,允许AWS Account A和Account B的特定IAM用户访问该存储桶。已配置Bucket Policy,授权两个账号的指定用户执行s3:GetObject等操作,但Account A的用户能正常访问,Account B的用户尝试列出或访问对象时收到AccessDenied错误。
当前配置的Bucket Policy
{ "Version": "2012-10-17", "Statement": [ { "Sid": "Deny-all-unauthorized-access", "Effect": "Deny", "NotPrincipal": { "AWS": [ "arn:aws:iam::AccountA-Id:user/AccountA-user1", "arn:aws:iam::AccountA-Id:user/AccountA-user2", "arn:aws:iam::AccountA-Id:user/AccountA-user3", "arn:aws:iam::AccountB-Id:user/AccountB-user1" ] }, "Action": "s3:*", "Resource": [ "arn:aws:s3:::occ-infra-s3-bucket", "arn:aws:s3:::occ-infra-s3-bucket/*" ] }, { "Sid": "Allow-actions", "Effect": "Allow", "Principal": { "AWS": [ "arn:aws:iam::AccountA-Id:user/AccountA-user1", "arn:aws:iam::AccountA-Id:user/AccountA-user2", "arn:aws:iam::AccountA-Id:user/AccountA-user3", "arn:aws:iam::AccountB-Id:user/AccountB-user1" ] }, "Action": [ "s3:GetObject", "s3:PutObject", "s3:PutObjectAcl", "s3:ListBucket" ], "Resource": [ "arn:aws:s3:::myBucket", "arn:aws:s3:::myBucket/*" ] } ] }
错误信息
Account B用户执行ListObjectsV2操作时收到的错误:
An error occurred (AccessDenied) when calling the ListObjectsV2 operation: Access Denied
CloudTrail日志对比
- Account A用户的日志条目,
userIdentity正确识别为IAM用户:
"userIdentity": { "type": "IAMUser", "principalId": "AIDAQB7XESH6TMDGHIUEI", "arn": "arn:aws:iam::AccountA-Id:user/AccountA-user1", "accountId": "AccountA-Id", "accessKeyId": "AKIAQB7JHUY87K7JHJ6X", "userName": "AccountA-user1" }
- Account B用户的日志条目,
userIdentity显示为AWSAccount,未正确识别为IAM用户:
"userIdentity": { "type": "AWSAccount", "principalId": "AIDATACUJHYGDFERMLSJ7", "accountId": "AccountB-Id" }
测试与排查
移除Bucket Policy中的Deny语句后,Account B用户可正常访问,说明问题出在Deny规则的NotPrincipal条件——AWS未正确识别Account B的外部IAM用户,导致其被Deny规则拦截。
已通过执行aws sts get-caller-identity确认Account B用户认证正常,返回结果符合预期:
{ "UserId": "AIDATACUJHYGDFERMLSJ7", "Account": "AccountB-Id", "Arn": "arn:aws:iam::AccountB-Id:user/AccountB-user1" }
内容的提问来源于stack exchange,提问作者Ahmed SALIHI
相关产品推荐
相关产品推荐

