You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CloudFormation生成的IAM凭证无法在CANcloud访问S3桶排查

问题:CloudFormation生成的IAM凭证无法在CANcloud中使用,但手动生成的可以

我用下面的AWS CloudFormation栈创建了S3存储桶、IAM用户,并生成该用户的访问凭证(我知晓明文输出凭证的安全风险)。存储桶创建正常,用TnTDrive能通过该凭证访问S3桶,但用S3浏览器工具CANcloud登录失败,我怀疑是CORS策略的问题;但如果通过AWS控制台给同一个IAM用户手动生成新凭证,却能在CANcloud里正常使用。请问我哪里操作错了?

CloudFormation模板代码

{
    "AWSTemplateFormatVersion": "2010-09-09",
    "Description": "CloudFormation template to create an S3 bucket, IAM users, and policies.",
    "Parameters": {
        "BucketName": {
            "Description": "The name of the S3 bucket",
            "Type": "String",
            "AllowedPattern": "^[a-z0-9.-]{3,63}$",
            "ConstraintDescription": "Bucket name can contain lowercase letters, numbers, hyphens, and periods. It must be between 3 and 63 characters."
        },
        "Region": {
            "Description": "AWS region where the bucket will be created",
            "Type": "String",
            "AllowedValues": [
                "us-east-1",
                "us-east-2",
                "us-west-1",
                "us-west-2",
                "af-south-1",
                "ap-east-1",
                "ap-south-2",
                "ap-southeast-3",
                "ap-southeast-4",
                "ap-south-1",
                "ap-northeast-3",
                "ap-northeast-2",
                "ap-southeast-1",
                "ap-southeast-2",
                "ap-northeast-1",
                "ca-central-1",
                "cn-north-1",
                "cn-northwest-1",
                "eu-central-1",
                "eu-west-1",
                "eu-west-2",
                "eu-south-1",
                "eu-west-3",
                "eu-north-1",
                "eu-south-2",
                "eu-central-2",
                "sa-east-1",
                "me-south-1",
                "me-central-1",
                "il-central-1",
                "us-gov-east-1",
                "us-gov-west-1"
            ],
            "Default": "us-east-1",
            "ConstraintDescription": "Must be a valid AWS region."
        }
    },
    "Resources": {
        "AmazonS3FullAccessBucketUser": {
            "DependsOn": "MyS3Bucket",
            "Type": "AWS::IAM::User"
        },
        "AmazonS3FullAccessBucketPolicy": {
            "Type": "AWS::IAM::Policy",
            "Properties": {
                "PolicyName": "FullAccessToSpecificBucket",
                "Users": [
                    {
                        "Ref": "AmazonS3FullAccessBucketUser"
                    }
                ],
                "PolicyDocument": {
                    "Version": "2012-10-17",
                    "Statement": [
                        {
                            "Effect": "Allow",
                            "Action": [
                                "s3:*",
                                "s3-object-lambda:*"
                            ],
                            "Resource": [
                                {
                                    "Fn::Sub": "arn:aws:s3:::${BucketName}"
                                },
                                {
                                    "Fn::Sub": "arn:aws:s3:::${BucketName}/*"
                                }
                            ]
                        }
                    ]
                }
            }
        },
        "AmazonS3FullAccessBucketKeys": {
            "Type": "AWS::IAM::AccessKey",
            "Properties": {
                "UserName": {
                    "Ref": "AmazonS3FullAccessBucketUser"
                }
            }
        },
        "MyS3Bucket": {
            "Type": "AWS::S3::Bucket",
            "Properties": {
                "BucketName": {
                    "Ref": "BucketName"
                },
                "CorsConfiguration": {
                    "CorsRules": [
                        {
                            "AllowedHeaders": [
                                "*"
                            ],
                            "AllowedMethods": [
                                "GET",
                                "PUT",
                                "POST",
                                "DELETE",
                                "HEAD"
                            ],
                            "AllowedOrigins": [
                                "*"
                            ]
                        }
                    ]
                }
            }
        }
    },
    "Outputs": {
        "FullAccessUserAccessKey": {
            "Description": "Access Key for IAM user with full S3 access",
            "Value": {
                "Ref": "AmazonS3FullAccessBucketKeys"
            }
        },
        "FullAccessUserSecretKey": {
            "Description": "Secret Key for IAM user with full S3 access",
            "Value": {
                "Fn::GetAtt": [
                    "AmazonS3FullAccessBucketKeys",
                    "SecretAccessKey"
                ]
            }
        },
        "BucketEndpoint": {
            "Description": "Endpoint URL for the created S3 bucket",
            "Value": {
                "Fn::Sub": "http://s3.${Region}.amazonaws.com"
            }
        }
    }
}

可能的原因及解决方法

  • 凭证生效延迟:CloudFormation自动生成的Access Key可能存在短暂的生效延迟,而手动生成的是即时生效的。可以等待5-10分钟后再用CloudFormation生成的凭证尝试登录CANcloud。
  • 凭证复制错误:检查CloudFormation输出的Secret Access Key是否完整复制——有些终端或输出界面会对长字符串进行换行或截断,建议直接从AWS控制台的栈输出页面复制完整的密钥。
  • IAM策略关联延迟:虽然模板里设置了DependsOn,但IAM策略绑定到用户可能存在微小延迟。可以登录IAM控制台,确认该用户的权限列表中已经包含FullAccessToSpecificBucket策略。
  • 排除CORS因素:既然手动生成的凭证能正常使用,说明CORS策略没问题——CORS主要限制浏览器端的跨域HTTP请求,桌面工具CANcloud不受此约束。

内容的提问来源于stack exchange,提问作者mfcss

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 14:19:54