You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何仅对前缀为important-的S3桶应用AWS Config规则s3-bucket-logging-enabled

问题描述

我拥有数百个S3存储桶,其中仅有少数重要存储桶,这些桶的命名均以important-为前缀,示例如下:

example-s3-bucket-1
example-s3-bucket-2
important-s3-bucket-1
example-s3-bucket-3
important-s3-bucket-2
...

我希望仅对以important-开头的存储桶运行AWS的s3-bucket-logging-enabled Config规则,忽略其他所有存储桶。该规则详情如下:

# s3-bucket-logging-enabled Config Rule
Description:
Checks if logging is enabled for your S3 buckets. The rule is NON_COMPLIANT if logging is not enabled.

Enabled evaluation mode:
DETECTIVE 

Detective evaluation trigger type:
Oversized configuration changes
Configuration changes

Scope of changes:
Resources

Resource types:
S3 Bucket

Parameters:
targetBucket - Target S3 bucket for storing server access logs.
targetPrefix - Prefix of the S3 bucket for storing server access logs.
解决方案

控制台配置步骤

    1. 登录AWS Config控制台,找到s3-bucket-logging-enabled规则,点击「编辑规则」。
    1. 在「范围」设置区域:
      • 确认已勾选「包括特定资源类型」,并选中「AWS::S3::Bucket」。
      • 展开「资源过滤器」,点击「添加过滤器」:
        • 选择「资源名称」作为过滤属性;
        • 匹配条件选择「开头为」;
        • 输入过滤值important-。
    1. 检查规则参数targetBucket和targetPrefix是否已正确配置为日志存储桶及前缀,若未配置则补充完整。
    1. 保存规则配置。

AWS CLI配置方式

如果习惯用命令行,可执行以下命令(替换占位符为实际值):

aws configservice put-config-rule \
  --config-rule-name s3-bucket-logging-enabled \
  --source '{"Owner":"AWS","SourceIdentifier":"S3_BUCKET_LOGGING_ENABLED"}' \
  --scope '{"ComplianceResourceTypes":["AWS::S3::Bucket"],"ComplianceResourceNameFilters":["important-*"]}' \
  --parameters '{"targetBucket":{"Value":"your-target-log-bucket"},"targetPrefix":{"Value":"s3-access-logs/"}}'

配置完成后,AWS Config将仅针对名称以important-开头的S3存储桶执行s3-bucket-logging-enabled规则的合规性检查,其余存储桶会被排除在评估范围外。

内容的提问来源于stack exchange,提问作者NOAA Cloud Dev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 20:47:05