You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

共享VPC与跨账户端点场景下,AWS Keyspaces无法获取system.peers的问题

解决跨账户共享VPC端点后无法查询AWS Keyspaces system.peers的问题

问题概述

我们有两个AWS账户:111111111111(账户A)和222222222222(账户B)。账户A拥有VPC及Cassandra服务的VPC端点,该VPC已共享至账户B。当前账户B的用户可以连接自身账户内的任意Keyspaces,但执行SELECT * FROM system.peers;时返回空结果;而账户A的同权限用户能正常获取该列表,但无法访问账户B创建的Keyspaces。我们已为账户B用户添加访问账户A system键空间的权限,且VPC端点策略配置为全允许,问题仍未解决。

当前配置

账户B用户权限

{
    "Action": [
        "ec2:DescribeNetworkInterfaces",
        "ec2:DescribeVpcEndpoints"
    ],
    "Resource": "*",
    "Effect": "Allow"
},
{
    "Action": "*",
    "Resource": "*",
    "Effect": "Allow",
    "PolicyName": "AmazonKeyspacesFullAccess"
},
{
    "Action": "cassandra:*",
    "Effect": "Allow",
    "Resource": [
        "arn:aws:cassandra:us-east-1:111111111111:/keyspace/system*"
    ]
}

VPC端点策略(账户A)

{
    "Statement": [
        {
            "Action": "*",
            "Effect": "Allow",
            "Principal": "*",
            "Resource": "*"
        }
    ]
}

解决方案

1. 修正权限资源ARN范围

账户B用户需要同时拥有访问自身账户和账户A的Keyspaces system.peers表的权限,细化到表级别而非仅键空间:

{
    "Action": [
        "cassandra:Select"
    ],
    "Effect": "Allow",
    "Resource": [
        "arn:aws:cassandra:us-east-1:222222222222:/keyspace/system/table/peers",
        "arn:aws:cassandra:us-east-1:111111111111:/keyspace/system/table/peers"
    ]
}

注:仅保留cassandra:Select权限即可,无需全量cassandra:*,遵循最小权限原则。

2. 优化VPC端点策略(可选但更安全)

将原全允许的VPC端点策略限定为仅允许账户B访问,避免过度授权:

{
    "Statement": [
        {
            "Action": "cassandra:*",
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::222222222222:root"
            },
            "Resource": [
                "arn:aws:cassandra:us-east-1:111111111111:/keyspace/system*",
                "arn:aws:cassandra:us-east-1:222222222222:/keyspace/*"
            ]
        }
    ]
}

3. 验证连接方式

确保账户B的客户端是通过共享的VPC端点连接Keyspaces,而非公网端点。示例cqlsh连接命令:

cqlsh <vpc-endpoint-dns> 9142 --ssl --auth-provider "AWSv4AuthProvider" --region us-east-1

4. 确认VPC共享配置

检查账户A的VPC共享配置,确保已将账户B添加为共享目标,且共享资源包含VPC端点所在的子网、安全组等关联资源。

原理说明

AWS Keyspaces的system.peers表数据对应VPC端点的弹性网络接口信息,这些ENI归属账户A。当账户B用户通过共享VPC端点连接时,需要同时具备:

  • 访问自身账户Keyspaces system表的权限
  • 访问账户A Keyspaces system表的权限
  • VPC端点策略允许账户B主体访问对应的Cassandra资源

内容的提问来源于stack exchange,提问作者Юра Гореликов

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 17:14:52