AWS CloudFormation生成的IAM凭证无法在CANcloud访问S3桶排查
问题:CloudFormation生成的IAM凭证无法在CANcloud中使用,但手动生成的可以
我用下面的AWS CloudFormation栈创建了S3存储桶、IAM用户,并生成该用户的访问凭证(我知晓明文输出凭证的安全风险)。存储桶创建正常,用TnTDrive能通过该凭证访问S3桶,但用S3浏览器工具CANcloud登录失败,我怀疑是CORS策略的问题;但如果通过AWS控制台给同一个IAM用户手动生成新凭证,却能在CANcloud里正常使用。请问我哪里操作错了?
CloudFormation模板代码
{ "AWSTemplateFormatVersion": "2010-09-09", "Description": "CloudFormation template to create an S3 bucket, IAM users, and policies.", "Parameters": { "BucketName": { "Description": "The name of the S3 bucket", "Type": "String", "AllowedPattern": "^[a-z0-9.-]{3,63}$", "ConstraintDescription": "Bucket name can contain lowercase letters, numbers, hyphens, and periods. It must be between 3 and 63 characters." }, "Region": { "Description": "AWS region where the bucket will be created", "Type": "String", "AllowedValues": [ "us-east-1", "us-east-2", "us-west-1", "us-west-2", "af-south-1", "ap-east-1", "ap-south-2", "ap-southeast-3", "ap-southeast-4", "ap-south-1", "ap-northeast-3", "ap-northeast-2", "ap-southeast-1", "ap-southeast-2", "ap-northeast-1", "ca-central-1", "cn-north-1", "cn-northwest-1", "eu-central-1", "eu-west-1", "eu-west-2", "eu-south-1", "eu-west-3", "eu-north-1", "eu-south-2", "eu-central-2", "sa-east-1", "me-south-1", "me-central-1", "il-central-1", "us-gov-east-1", "us-gov-west-1" ], "Default": "us-east-1", "ConstraintDescription": "Must be a valid AWS region." } }, "Resources": { "AmazonS3FullAccessBucketUser": { "DependsOn": "MyS3Bucket", "Type": "AWS::IAM::User" }, "AmazonS3FullAccessBucketPolicy": { "Type": "AWS::IAM::Policy", "Properties": { "PolicyName": "FullAccessToSpecificBucket", "Users": [ { "Ref": "AmazonS3FullAccessBucketUser" } ], "PolicyDocument": { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:*", "s3-object-lambda:*" ], "Resource": [ { "Fn::Sub": "arn:aws:s3:::${BucketName}" }, { "Fn::Sub": "arn:aws:s3:::${BucketName}/*" } ] } ] } } }, "AmazonS3FullAccessBucketKeys": { "Type": "AWS::IAM::AccessKey", "Properties": { "UserName": { "Ref": "AmazonS3FullAccessBucketUser" } } }, "MyS3Bucket": { "Type": "AWS::S3::Bucket", "Properties": { "BucketName": { "Ref": "BucketName" }, "CorsConfiguration": { "CorsRules": [ { "AllowedHeaders": [ "*" ], "AllowedMethods": [ "GET", "PUT", "POST", "DELETE", "HEAD" ], "AllowedOrigins": [ "*" ] } ] } } } }, "Outputs": { "FullAccessUserAccessKey": { "Description": "Access Key for IAM user with full S3 access", "Value": { "Ref": "AmazonS3FullAccessBucketKeys" } }, "FullAccessUserSecretKey": { "Description": "Secret Key for IAM user with full S3 access", "Value": { "Fn::GetAtt": [ "AmazonS3FullAccessBucketKeys", "SecretAccessKey" ] } }, "BucketEndpoint": { "Description": "Endpoint URL for the created S3 bucket", "Value": { "Fn::Sub": "http://s3.${Region}.amazonaws.com" } } } }
可能的原因及解决方法
- 凭证生效延迟:CloudFormation自动生成的Access Key可能存在短暂的生效延迟,而手动生成的是即时生效的。可以等待5-10分钟后再用CloudFormation生成的凭证尝试登录CANcloud。
- 凭证复制错误:检查CloudFormation输出的Secret Access Key是否完整复制——有些终端或输出界面会对长字符串进行换行或截断,建议直接从AWS控制台的栈输出页面复制完整的密钥。
- IAM策略关联延迟:虽然模板里设置了
DependsOn,但IAM策略绑定到用户可能存在微小延迟。可以登录IAM控制台,确认该用户的权限列表中已经包含FullAccessToSpecificBucket策略。 - 排除CORS因素:既然手动生成的凭证能正常使用,说明CORS策略没问题——CORS主要限制浏览器端的跨域HTTP请求,桌面工具CANcloud不受此约束。
内容的提问来源于stack exchange,提问作者mfcss
相关产品推荐
相关产品推荐

