EKS中Helm部署的Fluent Bit DaemonSet跨AWS账号访问Kinesis Firehose授权异常求助
Let's break down your issue and work through the most likely fixes for that InvalidIdentityToken error you're seeing.
Key Error Breakdown
First, let's highlight the critical error from your Fluent Bit logs:
No OpenIDConnect provider found in your account for https://oidc.eks.eu-west-1.amazonaws.com/id/AAAAAAAAAAAAAAAAAA
This message is coming from the target AWS account (xxxxxxxxxx) where your kinesis-write role resides, not your EKS cluster's account (yyyyyyyyy). Even if you have the OIDC provider set up in your EKS account, the target account needs to trust that provider explicitly by importing it into its own IAM system.
Step 1: Import the EKS OIDC Provider into the Target IAM Account (xxxxxxxxxx)
This is the most common root cause for cross-account OIDC auth failures. Here's how to fix it:
- Log into the AWS console for account
xxxxxxxxxx - Navigate to IAM → Identity Providers
- Click Add Provider and select OpenID Connect
- For the Provider URL, enter the exact URL from the error:
https://oidc.eks.eu-west-1.amazonaws.com/id/AAAAAAAAAAAAAAAAAA - Click Get thumbprint to fetch the valid certificate thumbprint for the OIDC endpoint
- Leave the Audience field blank (you can add
sts.amazonaws.comif needed for extra validation) - Click Add provider to complete the setup
Step 2: Verify the Role Trust Relationship
Double-check your kinesis-write role's trust policy to ensure it's correctly configured:
- Confirm the
Principal.FederatedARN points to your EKS account's OIDC provider:arn:aws:iam::yyyyyyyyy:oidc-provider/oidc.eks.eu-west-1.amazonaws.com/id/AAAAAAAAAAAAAAAAAA - Ensure the
Condition.StringEqualsmatches your Fluent Bit ServiceAccount exactly:oidc.eks.eu-west-1.amazonaws.com/id/AAAAAAAAAAAAAAAAAA:sub: "system:serviceaccount:newrelic:fluent-bit"
Your existing trust policy looks correct, but it won't function until the target account recognizes the OIDC provider.
Step 3: Validate the IAM Permission Policy
Check that your policy has the correct region in the Kinesis Firehose ARN. Your current policy uses region as a placeholder—replace it with eu-west-1 to match the region in your logs:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "firehose:PutRecord", "firehose:PutRecordBatch" ], "Resource": "arn:aws:firehose:eu-west-1:xxxxxxxxxx:deliverystream/kinesis-backend" } ] }
Step 4: Confirm Fluent Bit ServiceAccount Configuration
Your ServiceAccount annotation looks correct, but just to be thorough:
- Run
kubectl -n newrelic describe sa fluent-bitagain to confirm theeks.amazonaws.com/role-arnis still set toarn:aws:iam::xxxxxxxxxx:role/kinesis-write - Ensure there are no typos in the role ARN or namespace
After completing these steps, restart your Fluent Bit DaemonSet to pick up the changes:
kubectl rollout restart daemonset fluent-bit -n newrelic
Check the logs again—this should resolve the InvalidIdentityToken error and allow Fluent Bit to send data to your cross-account Kinesis Firehose.
内容的提问来源于stack exchange,提问作者Stefano Lazzaro

