创建跨账户IAM角色实现私有托管区与VPC关联遇权限问题
跨账户Route53私有托管区关联VPC权限问题
我正按照AWS官方示例创建IAM跨账户角色,需求是让中心账户(7935xxxxxxxxx)将工作负载账户(6617xxxxxxxx)中的VPC关联到中心账户的私有托管区,且该关联操作要以工作负载账户身份执行,但遇到以下错误:
"An error occurred (AccessDenied) when calling the AssociateVPCWithHostedZone operation: User: arn:aws:sts::6617xxxxxxxxx:assumed-role/AssumeFromCoreRole/cross_acct_lambda is not authorized to perform: route53:AssociateVPCWithHostedZone on resource: arn:aws:ec2:ap-southeast-2:6617xxxxxxxxx:vpc/vpc-0f37262673a5e9762 because no resource-based policy allows the route53:AssociateVPCWithHostedZone action"
我对这个错误信息存疑,因为据我所知Route53并不支持基于资源的策略。
以下是我已经检查过的配置:
- 工作负载账户中存在允许中心账户角色扮演的角色:
DNSACrossAccountRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Sid: AssumeRole Effect: Allow Principal: 'AWS': !Sub 'arn:aws:iam::${CoreAccountID}:role/DNS-Automation-Factory-${Environment}' Action: 'sts:AssumeRole' RoleName: AssumeFromCoreRole
- 中心账户的Lambda执行角色允许工作负载账户扮演该角色,并具备必要操作权限:
DNSAutomationRole: Type: AWS::IAM::Role Properties: ManagedPolicyArns: - arn:aws:iam::aws:policy/AWSLambda_FullAccess - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Sid: LambdaAssumeRole Effect: Allow Principal: Service: 'lambda.amazonaws.com' Action: 'sts:AssumeRole' RoleName: !Sub DNS-Automation-Factory-${Environment} Policies: - PolicyName: 'work-with-private-hosted-zone' PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: - route53:CreateVPCAssociationAuthorization - route53:CreateHostedZone - route53:AssociateVPCWithHostedZone - ec2:DescribeVpcs Resource: '*' - Sid: AllowCrossAccountAccess Effect: Allow Action: - 'sts:AssumeRole' Resource: arn:aws:iam::6617xxxxxxxxx:role/AssumeFromCoreRole
- Python客户端代码通过STS扮演角色执行API调用:
def cross_account_client(): sts_connection = boto3.client('sts') acct_b = sts_connection.assume_role( RoleArn="arn:aws:iam::6617xxxxxxxxx:role/AssumeFromCoreRole", RoleSessionName="cross_acct_lambda" ) ACCESS_KEY = acct_b['Credentials']['AccessKeyId'] SECRET_KEY = acct_b['Credentials']['SecretAccessKey'] SESSION_TOKEN = acct_b['Credentials']['SessionToken'] # create service client using the assumed role credentials, e.g. S3 client = boto3.client( 'route53', aws_access_key_id=ACCESS_KEY, aws_secret_access_key=SECRET_KEY, aws_session_token=SESSION_TOKEN, ) return client
调用方式:
r53_cross_account_role_client = cross_account_client() try: logger.info('Calling associate_vpc_with_hosted_zone') r53_cross_account_role_client.associate_vpc_with_hosted_zone( HostedZoneId=phz_id, VPC={ 'VPCRegion': aws_region, 'VPCId': workload_vpc_id } )
我肯定遗漏了某些关键点,有没有人遇到过相同问题?
内容的提问来源于stack exchange,提问作者craigcaulfield
相关产品推荐
相关产品推荐

