如何通过CDK跨AWS账户复制SSE-KMS加密的S3 ML模型文件?
跨账户S3复制加密ML模型的权限问题解决建议
问题背景
Dev环境S3存储的ML模型已启用SSE-KMS加密,此前未加密时使用boto3的copy方法可正常跨账户复制到Stage/Prod的S3桶,现在执行复制时抛出AccessDenied错误,已为CDK角色添加KMS权限但问题仍存在。
原可用代码(未加密场景)
boto3.resource("s3").meta.client.copy( {"Bucket": source_bucket_name, "Key": source_file}, destination_bucket_name, source_file, )
报错信息
botocore.exceptions.ClientError: An error occurred (AccessDenied) when calling the UploadPartCopy operation: Access Denied
已尝试的权限配置
{ "Sid": "AllowKMSDecryptFromSourceBucket", "Effect": "Allow", "Action": [ "kms:*" ], "Resource": [ "arn:aws:kms:eu-west-1:source-account-key-arn" ] }, { "Sid": "AllowKMSEncryptToDestinationBucket", "Effect": "Allow", "Action": [ "kms:*" ], "Resource": [ "arn:aws:kms:us-east-2:destination-account-key-arn" ] }
解决建议
1. 修正KMS密钥的跨账户权限策略
仅给CDK角色添加KMS权限是不够的,必须修改源账户和目标账户的KMS密钥策略,允许CDK角色进行对应操作:
- 源账户KMS密钥策略新增规则(允许CDK角色解密源对象):
{ "Sid": "AllowCrossAccountDecrypt", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::目标账户ID:role/CDK执行角色ARN" }, "Action": [ "kms:Decrypt", "kms:DescribeKey" ], "Resource": "*" } - 目标账户KMS密钥策略新增规则(允许CDK角色加密目标对象):
{ "Sid": "AllowCrossAccountEncrypt", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::目标账户ID:role/CDK执行角色ARN" }, "Action": [ "kms:Encrypt", "kms:GenerateDataKey", "kms:DescribeKey" ], "Resource": "*" }
2. 完善CDK角色的S3权限
确保CDK角色拥有完整的S3操作权限:
{ "Sid": "AllowSourceS3Access", "Effect": "Allow", "Action": [ "s3:GetObject", "s3:GetObjectVersion" ], "Resource": "arn:aws:s3:::源桶名称/*" }, { "Sid": "AllowDestinationS3Access", "Effect": "Allow", "Action": [ "s3:PutObject", "s3:PutObjectAcl" ], "Resource": "arn:aws:s3:::目标桶名称/*" }
3. 修改boto3复制代码,显式指定加密配置
在copy操作中明确指定目标对象的SSE-KMS参数,避免默认配置导致的权限冲突:
boto3.resource("s3").meta.client.copy( {"Bucket": source_bucket_name, "Key": source_file}, destination_bucket_name, source_file, ExtraArgs={ "ServerSideEncryption": "aws:kms", "SSEKMSKeyId": "目标账户KMS密钥ARN" } )
4. 验证CDK执行身份
确认CDK运行时使用的角色是你配置了权限的角色,可通过以下命令检查当前身份:
aws sts get-caller-identity
内容的提问来源于stack exchange,提问作者Sazzad
相关产品推荐
相关产品推荐

