You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已绑定IAM角色仍无法从S3拉取脚本到AWS Workspace求助

问题:AWS Workspace绑定IAM角色后仍无法拉取S3脚本

无法将S3存储桶中的脚本拉取到AWS Workspace。出于安全考虑,临时Access Key和Secret Key不宜提供给公司支持团队使用,因此已为Workspace绑定具备S3脚本读取权限的IAM角色,但执行脚本时仍收到以下错误:

D:\Script Test\newfile3.ps1 : Failed to download file from S3: The AWS Access Key Id you provided does not exist in our records.
+ CategoryInfo          : NotSpecified: (:) [Write-Error], WriteErrorException
+ FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,newfile3.ps1

所用脚本

# Import the AWS PowerShell module 
Import-Module AWSPowerShell -Force


# Define the S3 bucket and object key 
$bucketName = "bucket-name" 
$objectKey = "new ad account/fd new ad account V4.ps1" 

# Define the local file path where you want to save the downloaded code 
$localFilePath = "D:\Script Test" # Replace with your desired local file path 

# Download the code from S3 
try {
    Read-S3Object -SecretKey $secretKey -AccessKey $accessKey -Region us-west-2 -BucketName $bucketName -Key $objectKey -File $localFilePath -ErrorAction Stop
    Write-Host "File downloaded successfully from S3."
} 
catch {
    Write-Error "Failed to download file from S3: $_"
    exit 1
}

# Execute the downloaded code 
try {
    & $localFilePath
    Write-Host "Script executed successfully."
} 
catch {
    Write-Error "Failed to execute script: $_"
    exit 1
}

exit 0

绑定到Workspace的IAM角色策略

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "s3:GetObject",
            "Resource": "arn:aws:s3:::your-bucket-name/*"
        }
    ]
}

S3桶策略

{
    "Version": "2012-10-17",
    "Id": "Policy1711030019865",
    "Statement": [
        {
            "Sid": "AllowWorkspaceToGetObject",
            "Effect": "Allow",
            "Principal": {
                "Service": "workspaces.amazonaws.com"
            },
            "Action": "s3:GetObject",
            "Resource": "arn:aws:s3:::your-bucket-name/*"
        }
    ]
}

解决方案

1. 移除脚本中的硬编码密钥参数

脚本中Read-S3Object命令指定了-AccessKey和-SecretKey参数,这会强制使用指定密钥而非IAM角色的临时凭证,直接导致错误。必须删除这两个参数,让AWS PowerShell模块自动从Workspace绑定的IAM角色获取凭证:

# 修改后的下载命令
Read-S3Object -Region us-west-2 -BucketName $bucketName -Key $objectKey -File $localFilePath -ErrorAction Stop

2. 修正本地文件路径

$localFilePath当前仅指定了目录,而Read-S3Object的-File参数需要完整的文件名,否则会导致下载失败。修改路径为:

$localFilePath = "D:\Script Test\fd new ad account V4.ps1"

3. 验证IAM角色信任关系

确保绑定到Workspace的IAM角色信任策略允许workspaces.amazonaws.com担任角色,信任策略示例:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "workspaces.amazonaws.com"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}

4. 优化桶策略(可选)

当前桶策略允许所有Workspace服务访问,建议指定具体IAM角色ARN作为主体,缩小权限范围:

{
    "Version": "2012-10-17",
    "Id": "Policy1711030019865",
    "Statement": [
        {
            "Sid": "AllowWorkspaceRoleToGetObject",
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::你的AWS账号ID:role/绑定到Workspace的角色名称"
            },
            "Action": "s3:GetObject",
            "Resource": "arn:aws:s3:::your-bucket-name/*"
        }
    ]
}

5. 测试角色凭证有效性

在Workspace中执行以下命令,验证IAM角色是否能正常获取S3权限:

# 检查当前凭证
Get-AWSCredentials

# 测试S3桶读取权限
Test-S3BucketPermission -BucketName bucket-name -Permission Read

修改后的完整脚本

# Import the AWS PowerShell module 
Import-Module AWSPowerShell -Force

# Define the S3 bucket and object key 
$bucketName = "bucket-name" 
$objectKey = "new ad account/fd new ad account V4.ps1" 

# Define the local file path where you want to save the downloaded code 
$localFilePath = "D:\Script Test\fd new ad account V4.ps1" 

# Download the code from S3 
try {
    Read-S3Object -Region us-west-2 -BucketName $bucketName -Key $objectKey -File $localFilePath -ErrorAction Stop
    Write-Host "File downloaded successfully from S3."
} 
catch {
    Write-Error "Failed to download file from S3: $_"
    exit 1
}

# Execute the downloaded code 
try {
    & $localFilePath
    Write-Host "Script executed successfully."
} 
catch {
    Write-Error "Failed to execute script: $_"
    exit 1
}

exit 0

内容的提问来源于stack exchange,提问作者Mac Nyekan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 00:53:24