You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨账号导出CloudWatch日志到S3权限配置正确性咨询

跨账号CloudWatch日志导出S3权限配置排查

问题背景

执行跨账号CloudWatch日志导出到S3的CLI命令时,触发权限错误:

"An error occurred (InvalidParameterException) when calling the CreateExportTask operation: Please ensure that the export role and the destination bucket have all the required permissions as per the documentation."

当前配置详情

目标账号S3桶权限策略

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "logs.us-west-2.amazonaws.com"
            },
            "Action": "s3:GetBucketAcl",
            "Resource": "arn:aws:s3:::cloudwatch-exportlogs1",
            "Condition": {
                "StringEquals": {
                    "aws:SourceAccount": "477912222803"
                },
                "ArnLike": {
                    "aws:SourceArn": "arn:aws:logs:us-west-2:477912222803:log-group:/aws/lambda/applicationLambda:*"
                }
            }
        },
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "logs.us-west-2.amazonaws.com"
            },
            "Action": "s3:PutObject",
            "Resource": "arn:aws:s3:::cloudwatch-exportlogs1/*",
            "Condition": {
                "StringEquals": {
                    "s3:x-amz-acl": "bucket-owner-full-control",
                    "aws:SourceAccount": "477912222803"
                },
                "ArnLike": {
                    "aws:SourceArn": "arn:aws:logs:us-west-2:477912222803:log-group:/aws/lambda/applicationLambda:*"
                }
            }
        },
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::477912222803:role/CloudWatchLogsExportToS3"
            },
            "Action": "s3:PutObject",
            "Resource": "arn:aws:s3:::cloudwatch-exportlogs1/*",
            "Condition": {
                "StringEquals": {
                    "s3:x-amz-acl": "bucket-owner-full-control"
                }
            }
        }
    ]
}

源账号IAM角色信任策略

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "logs.us-west-2.amazonaws.com"
            },
            "Action": "sts:AssumeRole"
        },
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::DESTINATIONID:role/<rolename>"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}

源账号IAM角色权限策略

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "logs:CreateExportTask",
                "logs:DescribeExportTasks",
                "logs:DescribeLogGroups",
                "logs:DescribeLogStreams",
                "logs:CancelExportTask"
            ],
            "Resource": "*"
        }
    ]
}

目标账号IAM角色信任策略

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::<Source ID>:role/<role_name>"
            },
            "Action": "sts:AssumeRole"
        },
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "logs.us-west-2.amazonaws.com"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}

目标账号IAM角色权限策略

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "logs:CreateExportTask",
                "logs:CancelExportTask",
                "logs:DescribeExportTasks",
                "logs:DescribeLogGroups",
                "logs:DescribeLogStreams"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "s3:PutObject",
                "s3:PutObjectAcl",
                "s3:GetBucketAcl"
            ],
            "Resource": [
                "arn:aws:s3:::cloudwatch-exportlogs1",
                "arn:aws:s3:::cloudwatch-exportlogs1/*"
            ]
        }
    ]
}

执行的CLI命令

aws logs create-export-task --task-name "my-log-group-09-23-2024" --log-group-name "/aws/lambda/applicationLambda" --from 1727046409000 --to 1727129846000 --destination "cloudwatch-exportlogs1" --destination-prefix "export-task-output" --region us-west-2

权限配置问题分析及修正

当前配置存在4个关键问题,逐一修正如下:

  1. S3桶策略缺少目标账号角色权限
    跨账号导出时,CloudWatch会通过目标账号角色操作S3桶,当前策略仅允许源账号角色和CloudWatch服务主体,需添加目标账号角色的权限条目:

    {
        "Effect": "Allow",
        "Principal": {
            "AWS": "arn:aws:iam::DESTINATIONID:role/<rolename>"
        },
        "Action": [
            "s3:GetBucketAcl",
            "s3:PutObject"
        ],
        "Resource": [
            "arn:aws:s3:::cloudwatch-exportlogs1",
            "arn:aws:s3:::cloudwatch-exportlogs1/*"
        ],
        "Condition": {
            "StringEquals": {
                "s3:x-amz-acl": "bucket-owner-full-control"
            }
        }
    }
    
  2. 源账号角色信任策略冗余
    源账号角色无需允许目标账号角色sts:AssumeRole,跨账号导出是目标账号角色调用源账号CloudWatch资源,反向信任无意义,修正后的信任策略:

    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Principal": {
                    "Service": "logs.us-west-2.amazonaws.com"
                },
                "Action": "sts:AssumeRole"
            }
        ]
    }
    
  3. CLI命令未指定导出角色
    跨账号导出必须通过--role-arn参数指定目标账号的导出角色ARN,否则CloudWatch无法获取S3操作权限,修正后的命令:

    aws logs create-export-task --task-name "my-log-group-09-23-2024" --log-group-name "/aws/lambda/applicationLambda" --from 1727046409000 --to 1727129846000 --destination "cloudwatch-exportlogs1" --destination-prefix "export-task-output" --role-arn "arn:aws:iam::DESTINATIONID:role/<rolename>" --region us-west-2
    
  4. 目标账号角色信任策略占位符未替换
    将信任策略中的<Source ID>替换为实际源账号ID(477912222803),<role_name>替换为源账号实际角色名称,避免占位符导致权限验证失败。

验证步骤

  • 确认所有占位符(DESTINATIONID、、<role_name>)均替换为实际值
  • 重新应用所有修改后的策略
  • 执行修正后的CLI命令发起导出任务

内容的提问来源于stack exchange,提问作者Murali

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 00:27:09