You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

创建跨账户IAM角色实现私有托管区与VPC关联遇权限问题

跨账户Route53私有托管区关联VPC权限问题

我正按照AWS官方示例创建IAM跨账户角色,需求是让中心账户(7935xxxxxxxxx)将工作负载账户(6617xxxxxxxx)中的VPC关联到中心账户的私有托管区,且该关联操作要以工作负载账户身份执行,但遇到以下错误:

"An error occurred (AccessDenied) when calling the AssociateVPCWithHostedZone operation: User: arn:aws:sts::6617xxxxxxxxx:assumed-role/AssumeFromCoreRole/cross_acct_lambda is not authorized to perform: route53:AssociateVPCWithHostedZone on resource: arn:aws:ec2:ap-southeast-2:6617xxxxxxxxx:vpc/vpc-0f37262673a5e9762 because no resource-based policy allows the route53:AssociateVPCWithHostedZone action"

我对这个错误信息存疑,因为据我所知Route53并不支持基于资源的策略。

以下是我已经检查过的配置:

  • 工作负载账户中存在允许中心账户角色扮演的角色:
DNSACrossAccountRole:
Type: AWS::IAM::Role
Properties:
  AssumeRolePolicyDocument:
    Version: '2012-10-17'
    Statement:
      - Sid: AssumeRole
        Effect: Allow
        Principal:
          'AWS': !Sub 'arn:aws:iam::${CoreAccountID}:role/DNS-Automation-Factory-${Environment}'
        Action: 'sts:AssumeRole'
  RoleName: AssumeFromCoreRole
  • 中心账户的Lambda执行角色允许工作负载账户扮演该角色,并具备必要操作权限:
DNSAutomationRole:
  Type: AWS::IAM::Role
  Properties:
    ManagedPolicyArns:
    - arn:aws:iam::aws:policy/AWSLambda_FullAccess
    - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole
    AssumeRolePolicyDocument:
      Version: '2012-10-17'
      Statement:
      - Sid: LambdaAssumeRole
        Effect: Allow
        Principal:
          Service: 'lambda.amazonaws.com'
        Action: 'sts:AssumeRole'
    RoleName: !Sub DNS-Automation-Factory-${Environment}
    Policies:
    - PolicyName: 'work-with-private-hosted-zone'
      PolicyDocument:
        Version: '2012-10-17'
        Statement:
        - Effect: Allow
          Action:
          - route53:CreateVPCAssociationAuthorization
          - route53:CreateHostedZone
          - route53:AssociateVPCWithHostedZone
          - ec2:DescribeVpcs
          Resource: '*'
        - Sid: AllowCrossAccountAccess
          Effect: Allow
          Action:
          - 'sts:AssumeRole'
          Resource: arn:aws:iam::6617xxxxxxxxx:role/AssumeFromCoreRole
  • Python客户端代码通过STS扮演角色执行API调用:
def cross_account_client():
    sts_connection = boto3.client('sts')
    acct_b = sts_connection.assume_role(
        RoleArn="arn:aws:iam::6617xxxxxxxxx:role/AssumeFromCoreRole",
        RoleSessionName="cross_acct_lambda"
    )

    ACCESS_KEY = acct_b['Credentials']['AccessKeyId']
    SECRET_KEY = acct_b['Credentials']['SecretAccessKey']
    SESSION_TOKEN = acct_b['Credentials']['SessionToken']

    # create service client using the assumed role credentials, e.g. S3
    client = boto3.client(
        'route53',
        aws_access_key_id=ACCESS_KEY,
        aws_secret_access_key=SECRET_KEY,
        aws_session_token=SESSION_TOKEN,
    )
    return client

调用方式:

r53_cross_account_role_client = cross_account_client()
try:
    logger.info('Calling associate_vpc_with_hosted_zone')
    r53_cross_account_role_client.associate_vpc_with_hosted_zone(
        HostedZoneId=phz_id,
        VPC={
            'VPCRegion': aws_region,
            'VPCId': workload_vpc_id
        }
    )

我肯定遗漏了某些关键点,有没有人遇到过相同问题?


内容的提问来源于stack exchange,提问作者craigcaulfield

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 21:55:30