You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过CDK跨AWS账户复制SSE-KMS加密的S3 ML模型文件?

跨账户S3复制加密ML模型的权限问题解决建议

问题背景

Dev环境S3存储的ML模型已启用SSE-KMS加密,此前未加密时使用boto3的copy方法可正常跨账户复制到Stage/Prod的S3桶,现在执行复制时抛出AccessDenied错误,已为CDK角色添加KMS权限但问题仍存在。

原可用代码(未加密场景)

boto3.resource("s3").meta.client.copy(
    {"Bucket": source_bucket_name, "Key": source_file},
    destination_bucket_name,
    source_file,
)

报错信息

botocore.exceptions.ClientError: An error occurred (AccessDenied) when calling the UploadPartCopy operation: Access Denied

已尝试的权限配置

{
    "Sid": "AllowKMSDecryptFromSourceBucket",
    "Effect": "Allow",
    "Action": [
        "kms:*"
    ],
    "Resource": [
        "arn:aws:kms:eu-west-1:source-account-key-arn"
    ]
},
{
    "Sid": "AllowKMSEncryptToDestinationBucket",
    "Effect": "Allow",
    "Action": [
        "kms:*"
    ],
    "Resource": [
        "arn:aws:kms:us-east-2:destination-account-key-arn"
    ]
}

解决建议

1. 修正KMS密钥的跨账户权限策略

仅给CDK角色添加KMS权限是不够的,必须修改源账户和目标账户的KMS密钥策略,允许CDK角色进行对应操作:

  • 源账户KMS密钥策略新增规则(允许CDK角色解密源对象):
    {
        "Sid": "AllowCrossAccountDecrypt",
        "Effect": "Allow",
        "Principal": {
            "AWS": "arn:aws:iam::目标账户ID:role/CDK执行角色ARN"
        },
        "Action": [
            "kms:Decrypt",
            "kms:DescribeKey"
        ],
        "Resource": "*"
    }
    
  • 目标账户KMS密钥策略新增规则(允许CDK角色加密目标对象):
    {
        "Sid": "AllowCrossAccountEncrypt",
        "Effect": "Allow",
        "Principal": {
            "AWS": "arn:aws:iam::目标账户ID:role/CDK执行角色ARN"
        },
        "Action": [
            "kms:Encrypt",
            "kms:GenerateDataKey",
            "kms:DescribeKey"
        ],
        "Resource": "*"
    }
    

2. 完善CDK角色的S3权限

确保CDK角色拥有完整的S3操作权限:

{
    "Sid": "AllowSourceS3Access",
    "Effect": "Allow",
    "Action": [
        "s3:GetObject",
        "s3:GetObjectVersion"
    ],
    "Resource": "arn:aws:s3:::源桶名称/*"
},
{
    "Sid": "AllowDestinationS3Access",
    "Effect": "Allow",
    "Action": [
        "s3:PutObject",
        "s3:PutObjectAcl"
    ],
    "Resource": "arn:aws:s3:::目标桶名称/*"
}

3. 修改boto3复制代码,显式指定加密配置

在copy操作中明确指定目标对象的SSE-KMS参数,避免默认配置导致的权限冲突:

boto3.resource("s3").meta.client.copy(
    {"Bucket": source_bucket_name, "Key": source_file},
    destination_bucket_name,
    source_file,
    ExtraArgs={
        "ServerSideEncryption": "aws:kms",
        "SSEKMSKeyId": "目标账户KMS密钥ARN"
    }
)

4. 验证CDK执行身份

确认CDK运行时使用的角色是你配置了权限的角色,可通过以下命令检查当前身份:

aws sts get-caller-identity

内容的提问来源于stack exchange,提问作者Sazzad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 06:47:27