You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署API Gateway至Dev环境遇CloudWatch日志角色ARN配置错误

问题描述

尝试将API Gateway部署至Dev环境时,持续收到CloudWatch日志相关错误,无法找到正确的权限配置方式,希望通过模板或CLI添加正确的权限与策略。

报错信息

Resource handler returned message: "CloudWatch
Logs role ARN must be set in account settings to
enable logging (Service: ApiGateway, Status
Code: 400, Request ID:
ac7ee97a-255b-4be9-8352-66b762f87c5d)"
(RequestToken:
88b15f37-2b1c-cfa2-43d7-5ca7b8572b63,
HandlerErrorCode: InvalidRequest)

现有template.yaml内容

AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Description: >
  gofiber-sam-v1
  
  Sample SAM Template for gofiber-sam-v1

Globals:
  Function:
    Timeout: 60
Parameters:
  DeploymentStage:
    Type: String
    Default: dev
    AllowedValues:
      - dev
      - v1
    Description: Deployment Stage

Resources:
  CloudWatchLogGroup:
    Type: AWS::Logs::LogGroup
    Properties:
      LogGroupName: /aws/lambda/GoFiberApp
      RetentionInDays: 30

  GoFiberAppRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service:
                - lambda.amazonaws.com
            Action: sts:AssumeRole

  GoFiberAppPolicy:
    Type: AWS::IAM::Policy
    Properties:
      PolicyName: GoFiberAppPolicy
      Roles:
        - !Ref GoFiberAppRole
      PolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Action:
              - s3:PutObject
              - s3:GetObject
            Resource: "*"
          - Effect: Allow
            Action:
              - logs:CreateLogGroup
              - logs:CreateLogStream
              - logs:PutLogEvents
            Resource: arn:aws:logs:*:*:log-group:/aws/lambda/GoFiberApp:*
  GoFiberApp:
    Type: AWS::Serverless::Function
    Metadata:
      Name: "GoFiber Sam API Handler"
    Properties:
      CodeUri: ./
      Handler: main
      Runtime: go1.x
      Role: !GetAtt GoFiberAppRole.Arn
      Architectures:
        - x86_64
      Events:
        ProxyEvent:
          Type: Api
          Properties:
            Path: /{proxy+}
            Method: ANY
            RestApiId: !Ref ApiGatewayRestApi
  

  ApiGatewayRestApi:
    Type: AWS::Serverless::Api
    Metadata:
      Name: "AdPrompt API (is2p5yk9v3)"
    Properties:
      StageName: dev
      Auth:
        ApiKeyRequired: true
      MethodSettings:
      - HttpMethod: "*"
        LoggingLevel: INFO
        ResourcePath: "/*"
      AccessLogSetting:
        DestinationArn: !GetAtt CloudWatchLogGroup.Arn
        Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","httpMethod":"$context.httpMethod","routeKey":"$context.routeKey","status":"$context.status","responseLength":"$context.responseLength"}'

  ApiGatewayRestApiRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service:
                - apigateway.amazonaws.com
            Action: sts:AssumeRole

  ApiGatewayDeployment:
    Type: AWS::ApiGateway::Deployment
    Properties:
      RestApiId: !Ref ApiGatewayRestApi

  DevStage:
    Type: AWS::ApiGateway::Stage
    Condition: IsDev
    Properties:
      StageName: dev
      Description: Dev Stage
      RestApiId: !Ref ApiGatewayRestApi
      DeploymentId: !Ref ApiGatewayDeployment
  V1Stage:
    Type: AWS::ApiGateway::Stage
    Condition: IsV1
    Properties:
      StageName: v1
      Description: Prod Stage
      RestApiId: !Ref ApiGatewayRestApi
      DeploymentId: !Ref ApiGatewayDeployment

Conditions:
  IsDev: !Equals [!Ref DeploymentStage, 'dev']
  IsV1: !Equals [!Ref DeploymentStage, 'v1']

Outputs:
  GoFiberAPI:
    Description: "API Gateway endpoint URL AdPrompt API"
    Value: !Sub "https://${ApiGatewayRestApi}.execute-api.${AWS::Region}.amazonaws.com/${DeploymentStage}"
    Export:
      Name: "GoFiberAPI"
  ApiGatewayRestApi:
    Description: "RESTful API"
    Value: !Ref ApiGatewayRestApi
  ApiGatewayRestApiIamRole:
    Description: "IAM role for GoFiber API Gateway"
    Value: !GetAtt ApiGatewayRestApiRole.Arn
解决方案

这个错误的核心是账户级别未配置API Gateway的CloudWatch日志角色,同时你的ApiGatewayRestApiRole缺少写入CloudWatch日志的权限。以下是具体修复步骤:

1. 给ApiGatewayRestApiRole添加日志权限

现有模板中ApiGatewayRestApiRole只有信任策略,没有权限策略。需要添加IAM Policy,允许API Gateway向指定CloudWatch Log Group写入日志:
在Resources节点下新增以下资源:

ApiGatewayRestApiPolicy:
  Type: AWS::IAM::Policy
  Properties:
    PolicyName: ApiGatewayRestApiLogPolicy
    Roles:
      - !Ref ApiGatewayRestApiRole
    PolicyDocument:
      Version: '2012-10-17'
      Statement:
        - Effect: Allow
          Action:
            - logs:CreateLogStream
            - logs:PutLogEvents
          Resource: !GetAtt CloudWatchLogGroup.Arn

2. 配置账户级别的API Gateway日志角色

通过模板添加AWS::ApiGateway::Account资源,将ApiGatewayRestApiRole设为账户默认的CloudWatch日志角色:
在Resources节点下新增以下资源:

ApiGatewayAccount:
  Type: AWS::ApiGateway::Account
  Properties:
    CloudWatchLogsRoleArn: !GetAtt ApiGatewayRestApiRole.Arn

3. (可选)通过CLI快速配置

若不想修改模板,可直接用AWS CLI设置账户级别的日志角色:

aws apigateway update-account --patch-operations op='replace',path='/cloudwatchRoleArn',value='arn:aws:iam::你的账户ID:role/ApiGatewayRestApiRole'

内容的提问来源于stack exchange,提问作者Joel Hager

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 22:44:58