You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS CDK配置CloudWatch跨账号监控时Sink创建失败排查

问题描述

尝试使用AWS CDK配置CloudWatch跨账号监控,根据CloudFormation文档,只需创建Sink和Link两种资源即可实现,但配置后无法正常工作。

代码示例

const monitoringAccountPolicyDocument = new PolicyDocument({
      statements: [
        new PolicyStatement({
          effect: Effect.ALLOW,
          actions: ["oam:*"],
          resources: ["*"],
          principals: sharingAccountsPrincipals,  // array of AccountPrincipals with list of sharing accounts IDs
          conditions: [
            {
              "ForAllValues:StringEquals": {
                "oam:ResourceTypes": [
                  "AWS::CloudWatch::Metric",
                  "AWS::Logs::LogGroup",
                  "AWS::XRay::Trace",
                ],
              },
            },
          ],
        }),
      ],
    });


    const monitoringAccountSink = new CfnSink(this, "MonitoringAccountSink", {
      name: "MonitoringAccountSink",
      policy: monitoringAccountPolicyDocument,
    });

    const sharingAccountsLinks = sharingAccounts.map((account) => {
      const accountName = account.accountName;
      const accountLink = new CfnLink(
        this,
        `SharingAccountLink-${accountName}`,
        {
          resourceTypes: ["AWS::Logs::LogGroup", "AWS::XRay::Trace, AWS::CloudWatch::Metric"],
          sinkIdentifier: monitoringAccountSink.ref,
          labelTemplate: "$AccountName",
        }
      );
    });

错误信息

Resource handler returned message: "Invalid request provided: AWS::Oam::Sink"

原本预期会自动创建Sink、Link及所需的IAM角色,但CloudFormation在创建Sink时抛出上述错误。请问可能的原因是什么?是否需要对监控账号添加更多配置?是否遗漏了IAM设置?用于部署的角色拥有管理员权限。


问题排查与解决方案

1. Sink策略格式错误

AWS OAM Sink的Policy要求传入JSON字符串,但你直接传入了PolicyDocument对象。CDK的CfnSink资源不支持直接传入PolicyDocument实例,需要将其转换为JSON字符串:

const monitoringAccountSink = new CfnSink(this, "MonitoringAccountSink", {
  name: "MonitoringAccountSink",
  policy: monitoringAccountPolicyDocument.toJSON(), // 转换为JSON字符串
});

2. Link资源类型格式错误

在CfnLink的resourceTypes数组中,"AWS::XRay::Trace, AWS::CloudWatch::Metric"是错误的字符串格式,应该拆分为两个独立的数组元素:

resourceTypes: ["AWS::Logs::LogGroup", "AWS::XRay::Trace", "AWS::CloudWatch::Metric"],

3. 资源部署位置错误

Link资源必须在共享账号中创建,而不是监控账号。你的代码当前在监控账号栈中创建所有Link,这会导致权限错误——Link需要由共享账号发起创建,关联到监控账号的Sink。

4. 额外检查项

  • 确认监控账号和共享账号都已启用CloudWatch Observability Access Manager(OAM)服务,该服务默认启用,若手动关闭过需重新开启。
  • 确保使用的CDK版本支持AWS OAM资源,建议升级到最新稳定版,避免版本兼容问题。

内容的提问来源于stack exchange,提问作者Anna Slastnikova

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 08:12:13