You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS中Helm部署的Fluent Bit DaemonSet跨AWS账号访问Kinesis Firehose授权异常求助

Troubleshooting Fluent Bit Cross-Account Kinesis Firehose Authentication Failure

Let's break down your issue and work through the most likely fixes for that InvalidIdentityToken error you're seeing.

Key Error Breakdown

First, let's highlight the critical error from your Fluent Bit logs:

No OpenIDConnect provider found in your account for https://oidc.eks.eu-west-1.amazonaws.com/id/AAAAAAAAAAAAAAAAAA

This message is coming from the target AWS account (xxxxxxxxxx) where your kinesis-write role resides, not your EKS cluster's account (yyyyyyyyy). Even if you have the OIDC provider set up in your EKS account, the target account needs to trust that provider explicitly by importing it into its own IAM system.


Step 1: Import the EKS OIDC Provider into the Target IAM Account (xxxxxxxxxx)

This is the most common root cause for cross-account OIDC auth failures. Here's how to fix it:

  • Log into the AWS console for account xxxxxxxxxx
  • Navigate to IAM → Identity Providers
  • Click Add Provider and select OpenID Connect
  • For the Provider URL, enter the exact URL from the error: https://oidc.eks.eu-west-1.amazonaws.com/id/AAAAAAAAAAAAAAAAAA
  • Click Get thumbprint to fetch the valid certificate thumbprint for the OIDC endpoint
  • Leave the Audience field blank (you can add sts.amazonaws.com if needed for extra validation)
  • Click Add provider to complete the setup

Step 2: Verify the Role Trust Relationship

Double-check your kinesis-write role's trust policy to ensure it's correctly configured:

  • Confirm the Principal.Federated ARN points to your EKS account's OIDC provider: arn:aws:iam::yyyyyyyyy:oidc-provider/oidc.eks.eu-west-1.amazonaws.com/id/AAAAAAAAAAAAAAAAAA
  • Ensure the Condition.StringEquals matches your Fluent Bit ServiceAccount exactly: oidc.eks.eu-west-1.amazonaws.com/id/AAAAAAAAAAAAAAAAAA:sub: "system:serviceaccount:newrelic:fluent-bit"

Your existing trust policy looks correct, but it won't function until the target account recognizes the OIDC provider.

Step 3: Validate the IAM Permission Policy

Check that your policy has the correct region in the Kinesis Firehose ARN. Your current policy uses region as a placeholder—replace it with eu-west-1 to match the region in your logs:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "VisualEditor0",
      "Effect": "Allow",
      "Action": [
        "firehose:PutRecord",
        "firehose:PutRecordBatch"
      ],
      "Resource": "arn:aws:firehose:eu-west-1:xxxxxxxxxx:deliverystream/kinesis-backend"
    }
  ]
}

Step 4: Confirm Fluent Bit ServiceAccount Configuration

Your ServiceAccount annotation looks correct, but just to be thorough:

  • Run kubectl -n newrelic describe sa fluent-bit again to confirm the eks.amazonaws.com/role-arn is still set to arn:aws:iam::xxxxxxxxxx:role/kinesis-write
  • Ensure there are no typos in the role ARN or namespace

After completing these steps, restart your Fluent Bit DaemonSet to pick up the changes:

kubectl rollout restart daemonset fluent-bit -n newrelic

Check the logs again—this should resolve the InvalidIdentityToken error and allow Fluent Bit to send data to your cross-account Kinesis Firehose.

内容的提问来源于stack exchange,提问作者Stefano Lazzaro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 01:12:27