跨账号导出CloudWatch日志到S3权限配置正确性咨询
跨账号CloudWatch日志导出S3权限配置排查
问题背景
执行跨账号CloudWatch日志导出到S3的CLI命令时,触发权限错误:
"An error occurred (InvalidParameterException) when calling the CreateExportTask operation: Please ensure that the export role and the destination bucket have all the required permissions as per the documentation."
当前配置详情
目标账号S3桶权限策略
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "logs.us-west-2.amazonaws.com" }, "Action": "s3:GetBucketAcl", "Resource": "arn:aws:s3:::cloudwatch-exportlogs1", "Condition": { "StringEquals": { "aws:SourceAccount": "477912222803" }, "ArnLike": { "aws:SourceArn": "arn:aws:logs:us-west-2:477912222803:log-group:/aws/lambda/applicationLambda:*" } } }, { "Effect": "Allow", "Principal": { "Service": "logs.us-west-2.amazonaws.com" }, "Action": "s3:PutObject", "Resource": "arn:aws:s3:::cloudwatch-exportlogs1/*", "Condition": { "StringEquals": { "s3:x-amz-acl": "bucket-owner-full-control", "aws:SourceAccount": "477912222803" }, "ArnLike": { "aws:SourceArn": "arn:aws:logs:us-west-2:477912222803:log-group:/aws/lambda/applicationLambda:*" } } }, { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::477912222803:role/CloudWatchLogsExportToS3" }, "Action": "s3:PutObject", "Resource": "arn:aws:s3:::cloudwatch-exportlogs1/*", "Condition": { "StringEquals": { "s3:x-amz-acl": "bucket-owner-full-control" } } } ] }
源账号IAM角色信任策略
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "logs.us-west-2.amazonaws.com" }, "Action": "sts:AssumeRole" }, { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::DESTINATIONID:role/<rolename>" }, "Action": "sts:AssumeRole" } ] }
源账号IAM角色权限策略
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "logs:CreateExportTask", "logs:DescribeExportTasks", "logs:DescribeLogGroups", "logs:DescribeLogStreams", "logs:CancelExportTask" ], "Resource": "*" } ] }
目标账号IAM角色信任策略
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::<Source ID>:role/<role_name>" }, "Action": "sts:AssumeRole" }, { "Effect": "Allow", "Principal": { "Service": "logs.us-west-2.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }
目标账号IAM角色权限策略
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "logs:CreateExportTask", "logs:CancelExportTask", "logs:DescribeExportTasks", "logs:DescribeLogGroups", "logs:DescribeLogStreams" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "s3:PutObject", "s3:PutObjectAcl", "s3:GetBucketAcl" ], "Resource": [ "arn:aws:s3:::cloudwatch-exportlogs1", "arn:aws:s3:::cloudwatch-exportlogs1/*" ] } ] }
执行的CLI命令
aws logs create-export-task --task-name "my-log-group-09-23-2024" --log-group-name "/aws/lambda/applicationLambda" --from 1727046409000 --to 1727129846000 --destination "cloudwatch-exportlogs1" --destination-prefix "export-task-output" --region us-west-2
权限配置问题分析及修正
当前配置存在4个关键问题,逐一修正如下:
S3桶策略缺少目标账号角色权限
跨账号导出时,CloudWatch会通过目标账号角色操作S3桶,当前策略仅允许源账号角色和CloudWatch服务主体,需添加目标账号角色的权限条目:{ "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::DESTINATIONID:role/<rolename>" }, "Action": [ "s3:GetBucketAcl", "s3:PutObject" ], "Resource": [ "arn:aws:s3:::cloudwatch-exportlogs1", "arn:aws:s3:::cloudwatch-exportlogs1/*" ], "Condition": { "StringEquals": { "s3:x-amz-acl": "bucket-owner-full-control" } } }源账号角色信任策略冗余
源账号角色无需允许目标账号角色sts:AssumeRole,跨账号导出是目标账号角色调用源账号CloudWatch资源,反向信任无意义,修正后的信任策略:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "logs.us-west-2.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }CLI命令未指定导出角色
跨账号导出必须通过--role-arn参数指定目标账号的导出角色ARN,否则CloudWatch无法获取S3操作权限,修正后的命令:aws logs create-export-task --task-name "my-log-group-09-23-2024" --log-group-name "/aws/lambda/applicationLambda" --from 1727046409000 --to 1727129846000 --destination "cloudwatch-exportlogs1" --destination-prefix "export-task-output" --role-arn "arn:aws:iam::DESTINATIONID:role/<rolename>" --region us-west-2目标账号角色信任策略占位符未替换
将信任策略中的<Source ID>替换为实际源账号ID(477912222803),<role_name>替换为源账号实际角色名称,避免占位符导致权限验证失败。
验证步骤
- 确认所有占位符(DESTINATIONID、
、<role_name>)均替换为实际值 - 重新应用所有修改后的策略
- 执行修正后的CLI命令发起导出任务
内容的提问来源于stack exchange,提问作者Murali
相关产品推荐
相关产品推荐

