部署API Gateway至Dev环境遇CloudWatch日志角色ARN配置错误
尝试将API Gateway部署至Dev环境时,持续收到CloudWatch日志相关错误,无法找到正确的权限配置方式,希望通过模板或CLI添加正确的权限与策略。
报错信息
Resource handler returned message: "CloudWatch
Logs role ARN must be set in account settings to
enable logging (Service: ApiGateway, Status
Code: 400, Request ID:
ac7ee97a-255b-4be9-8352-66b762f87c5d)"
(RequestToken:
88b15f37-2b1c-cfa2-43d7-5ca7b8572b63,
HandlerErrorCode: InvalidRequest)
现有template.yaml内容
AWSTemplateFormatVersion: '2010-09-09' Transform: AWS::Serverless-2016-10-31 Description: > gofiber-sam-v1 Sample SAM Template for gofiber-sam-v1 Globals: Function: Timeout: 60 Parameters: DeploymentStage: Type: String Default: dev AllowedValues: - dev - v1 Description: Deployment Stage Resources: CloudWatchLogGroup: Type: AWS::Logs::LogGroup Properties: LogGroupName: /aws/lambda/GoFiberApp RetentionInDays: 30 GoFiberAppRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: - lambda.amazonaws.com Action: sts:AssumeRole GoFiberAppPolicy: Type: AWS::IAM::Policy Properties: PolicyName: GoFiberAppPolicy Roles: - !Ref GoFiberAppRole PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: - s3:PutObject - s3:GetObject Resource: "*" - Effect: Allow Action: - logs:CreateLogGroup - logs:CreateLogStream - logs:PutLogEvents Resource: arn:aws:logs:*:*:log-group:/aws/lambda/GoFiberApp:* GoFiberApp: Type: AWS::Serverless::Function Metadata: Name: "GoFiber Sam API Handler" Properties: CodeUri: ./ Handler: main Runtime: go1.x Role: !GetAtt GoFiberAppRole.Arn Architectures: - x86_64 Events: ProxyEvent: Type: Api Properties: Path: /{proxy+} Method: ANY RestApiId: !Ref ApiGatewayRestApi ApiGatewayRestApi: Type: AWS::Serverless::Api Metadata: Name: "AdPrompt API (is2p5yk9v3)" Properties: StageName: dev Auth: ApiKeyRequired: true MethodSettings: - HttpMethod: "*" LoggingLevel: INFO ResourcePath: "/*" AccessLogSetting: DestinationArn: !GetAtt CloudWatchLogGroup.Arn Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","httpMethod":"$context.httpMethod","routeKey":"$context.routeKey","status":"$context.status","responseLength":"$context.responseLength"}' ApiGatewayRestApiRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: - apigateway.amazonaws.com Action: sts:AssumeRole ApiGatewayDeployment: Type: AWS::ApiGateway::Deployment Properties: RestApiId: !Ref ApiGatewayRestApi DevStage: Type: AWS::ApiGateway::Stage Condition: IsDev Properties: StageName: dev Description: Dev Stage RestApiId: !Ref ApiGatewayRestApi DeploymentId: !Ref ApiGatewayDeployment V1Stage: Type: AWS::ApiGateway::Stage Condition: IsV1 Properties: StageName: v1 Description: Prod Stage RestApiId: !Ref ApiGatewayRestApi DeploymentId: !Ref ApiGatewayDeployment Conditions: IsDev: !Equals [!Ref DeploymentStage, 'dev'] IsV1: !Equals [!Ref DeploymentStage, 'v1'] Outputs: GoFiberAPI: Description: "API Gateway endpoint URL AdPrompt API" Value: !Sub "https://${ApiGatewayRestApi}.execute-api.${AWS::Region}.amazonaws.com/${DeploymentStage}" Export: Name: "GoFiberAPI" ApiGatewayRestApi: Description: "RESTful API" Value: !Ref ApiGatewayRestApi ApiGatewayRestApiIamRole: Description: "IAM role for GoFiber API Gateway" Value: !GetAtt ApiGatewayRestApiRole.Arn
这个错误的核心是账户级别未配置API Gateway的CloudWatch日志角色,同时你的ApiGatewayRestApiRole缺少写入CloudWatch日志的权限。以下是具体修复步骤:
1. 给ApiGatewayRestApiRole添加日志权限
现有模板中ApiGatewayRestApiRole只有信任策略,没有权限策略。需要添加IAM Policy,允许API Gateway向指定CloudWatch Log Group写入日志:
在Resources节点下新增以下资源:
ApiGatewayRestApiPolicy: Type: AWS::IAM::Policy Properties: PolicyName: ApiGatewayRestApiLogPolicy Roles: - !Ref ApiGatewayRestApiRole PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: - logs:CreateLogStream - logs:PutLogEvents Resource: !GetAtt CloudWatchLogGroup.Arn
2. 配置账户级别的API Gateway日志角色
通过模板添加AWS::ApiGateway::Account资源,将ApiGatewayRestApiRole设为账户默认的CloudWatch日志角色:
在Resources节点下新增以下资源:
ApiGatewayAccount: Type: AWS::ApiGateway::Account Properties: CloudWatchLogsRoleArn: !GetAtt ApiGatewayRestApiRole.Arn
3. (可选)通过CLI快速配置
若不想修改模板,可直接用AWS CLI设置账户级别的日志角色:
aws apigateway update-account --patch-operations op='replace',path='/cloudwatchRoleArn',value='arn:aws:iam::你的账户ID:role/ApiGatewayRestApiRole'
内容的提问来源于stack exchange,提问作者Joel Hager

