已绑定IAM角色仍无法从S3拉取脚本到AWS Workspace求助
问题:AWS Workspace绑定IAM角色后仍无法拉取S3脚本
无法将S3存储桶中的脚本拉取到AWS Workspace。出于安全考虑,临时Access Key和Secret Key不宜提供给公司支持团队使用,因此已为Workspace绑定具备S3脚本读取权限的IAM角色,但执行脚本时仍收到以下错误:
D:\Script Test\newfile3.ps1 : Failed to download file from S3: The AWS Access Key Id you provided does not exist in our records. + CategoryInfo : NotSpecified: (:) [Write-Error], WriteErrorException + FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,newfile3.ps1
所用脚本
# Import the AWS PowerShell module Import-Module AWSPowerShell -Force # Define the S3 bucket and object key $bucketName = "bucket-name" $objectKey = "new ad account/fd new ad account V4.ps1" # Define the local file path where you want to save the downloaded code $localFilePath = "D:\Script Test" # Replace with your desired local file path # Download the code from S3 try { Read-S3Object -SecretKey $secretKey -AccessKey $accessKey -Region us-west-2 -BucketName $bucketName -Key $objectKey -File $localFilePath -ErrorAction Stop Write-Host "File downloaded successfully from S3." } catch { Write-Error "Failed to download file from S3: $_" exit 1 } # Execute the downloaded code try { & $localFilePath Write-Host "Script executed successfully." } catch { Write-Error "Failed to execute script: $_" exit 1 } exit 0
绑定到Workspace的IAM角色策略
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::your-bucket-name/*" } ] }
S3桶策略
{ "Version": "2012-10-17", "Id": "Policy1711030019865", "Statement": [ { "Sid": "AllowWorkspaceToGetObject", "Effect": "Allow", "Principal": { "Service": "workspaces.amazonaws.com" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::your-bucket-name/*" } ] }
解决方案
1. 移除脚本中的硬编码密钥参数
脚本中Read-S3Object命令指定了-AccessKey和-SecretKey参数,这会强制使用指定密钥而非IAM角色的临时凭证,直接导致错误。必须删除这两个参数,让AWS PowerShell模块自动从Workspace绑定的IAM角色获取凭证:
# 修改后的下载命令 Read-S3Object -Region us-west-2 -BucketName $bucketName -Key $objectKey -File $localFilePath -ErrorAction Stop
2. 修正本地文件路径
$localFilePath当前仅指定了目录,而Read-S3Object的-File参数需要完整的文件名,否则会导致下载失败。修改路径为:
$localFilePath = "D:\Script Test\fd new ad account V4.ps1"
3. 验证IAM角色信任关系
确保绑定到Workspace的IAM角色信任策略允许workspaces.amazonaws.com担任角色,信任策略示例:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "workspaces.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }
4. 优化桶策略(可选)
当前桶策略允许所有Workspace服务访问,建议指定具体IAM角色ARN作为主体,缩小权限范围:
{ "Version": "2012-10-17", "Id": "Policy1711030019865", "Statement": [ { "Sid": "AllowWorkspaceRoleToGetObject", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::你的AWS账号ID:role/绑定到Workspace的角色名称" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::your-bucket-name/*" } ] }
5. 测试角色凭证有效性
在Workspace中执行以下命令,验证IAM角色是否能正常获取S3权限:
# 检查当前凭证 Get-AWSCredentials # 测试S3桶读取权限 Test-S3BucketPermission -BucketName bucket-name -Permission Read
修改后的完整脚本
# Import the AWS PowerShell module Import-Module AWSPowerShell -Force # Define the S3 bucket and object key $bucketName = "bucket-name" $objectKey = "new ad account/fd new ad account V4.ps1" # Define the local file path where you want to save the downloaded code $localFilePath = "D:\Script Test\fd new ad account V4.ps1" # Download the code from S3 try { Read-S3Object -Region us-west-2 -BucketName $bucketName -Key $objectKey -File $localFilePath -ErrorAction Stop Write-Host "File downloaded successfully from S3." } catch { Write-Error "Failed to download file from S3: $_" exit 1 } # Execute the downloaded code try { & $localFilePath Write-Host "Script executed successfully." } catch { Write-Error "Failed to execute script: $_" exit 1 } exit 0
内容的提问来源于stack exchange,提问作者Mac Nyekan
相关产品推荐
相关产品推荐

