You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CDK跨账号Event Rule触发CodeCommit失败问题求助

跨账号CDK部署EventRule权限问题

环境配置

  • 工具账号:托管Pipeline和EventBus,接收CodeCommit更新通知
  • 开发账号:包含CodeCommit仓库和Event Rule,负责向工具账号EventBus发送通知,Dev环境资源部署在此账号
  • 生产账号:Prod环境资源部署在此账号

已配置的信任关系

执行以下CDK Bootstrap命令完成账号信任配置:

# 工具账号
npx cdk bootstrap aws://<ToolingAccount>/us-east-1 --no-bootstrap-customer-key --cloudformation-execution-policies 'arn:aws:iam::aws:policy/AdministratorAccess' --verbose --profile <ToolingAccountProfile>

# 开发账号
npx cdk bootstrap aws://<DevelopmentAccount>/us-east-1 --no-bootstrap-customer-key --cloudformation-execution-policies arn:aws:iam::aws:policy/AdministratorAccess --trust <ToolingAccount> --profile <ToolingAccountProfile>

# 生产账号
npx cdk bootstrap aws://<ProductionAccount>/us-east-1 --no-bootstrap-customer-key --cloudformation-execution-policies 'arn:aws:iam::aws:policy/AdministratorAccess' --trust <ToolingAccount> --profile <ToolingAccountProfile>

已成功部署的资源

已从本地向Dev、Prod环境部署基础设施,并在工具账号中通过CDK创建了EventBus,对应的Stack代码如下:

class LabDemoInfraCornerStonePipelineStack(Stack):
    def __init__(self, scope: Construct, construct_id: str, config: dict, pipeline_type: str, **kwargs) -> None:
        super().__init__(scope, construct_id, **kwargs)
        if pipeline_type == "Dev":
            infra_event_dev_bus = events.CfnEventBus(
                self, 
                config['DemoInfraDevPipelineEventBusName'],
                name=config['DemoInfraDevPipelineEventBusName']
            )

            events.CfnEventBusPolicy(
                self, 
                "LabDemoInfraDevCodeCommitEventBusPolicy",
                event_bus_name=infra_event_dev_bus.attr_name,
                statement={
                    "Effect": "Allow",
                    "Principal" : {"AWS" : f"arn:aws:iam::<DevelopmentAccounNo>:root"},
                    "Action": "events:PutEvents",
                    "Resource": f"arn:aws:events:{self.region}:{self.account}:event-bus/{infra_event_dev_bus.attr_name}"
                },
                statement_id="LabDemoInfraDevCodeCommitEventBusPolicy"
            )

部署命令:

npx cdk deploy InfraCornerStoneLabDemoPipelineStack --profile <ToolingAccountProfile>

部署开发账号EventRule时的错误

尝试在开发账号中部署以下EventRule(app.py已传入开发账号作为env变量):

class InfraToolingLabDemoPipelineStack(Stack):

    def __init__(self, scope: Construct, construct_id: str, config: dict, pipeline_type: str, **kwargs) -> None:
        super().__init__(scope, construct_id,  **kwargs)
        if pipeline_type == "Dev":
            events.CfnRule(
                self, 
                config['DemoInfraDevPipelineEventRuleName'],
                description=f"Sends CodeCommit repository events to the Tooling Pipeline Account {config['DemoInfraDevPipelineEventBusName']} event bus.",
                event_bus_name=config['DemoInfraDevPipelineEventBusName'],
                event_pattern= {
                    "detail-type": "CodeCommit Repository State Change",
                    "source": "aws.codecommit",
                    "resources": [f"arn:aws:codecommit:${self.region}:${self.account}:${config['demo_infra_repo']}"]
                },
                state='ENABLED',
                targets=[
                    events.CfnRule.TargetProperty(
                        arn=f"arn:aws:events:{self.region}:{config['tooling_account_no']}:event-bus/{config['DemoInfraDevPipelineEventBusName']}",
                        id=config['DemoInfraDevPipelineEventRuleName']
                    )
                ]
            )

部署命令:

cdk deploy InfraToolingLabDemoPipelineStack --profile <ToolingAccountProfile>

收到错误提示:

InfraToolingLabDemoPipelineStack/LabDemoInfraDevPipelineEnvtRule (LabDemoInfraDevPipelineEnvtRule) User: arn:aws:sts:::assumed-role/cdk-labdemo-cfn-exec-role--us-east-1/AWSCloudFormation is not authorized to perform: events:PutRule on resource: arn:aws:events:us-east-1::rule/LabDemoInfraDevPipelineEnvtBus/InfraToolingLabDemo-LabDemoInfraDevPipelin-BR1BO7R0FJ3D because no resource-based policy allows the events:PutRule action

已尝试的排查操作

  1. 确认开发账号的cdk-labarmory-cfn-exec-role-<DevelopmentAccount>-us-east-1角色信任关系正确,且拥有管理员权限:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "cloudformation.amazonaws.com"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}
  1. 修改Bootstrap执行方式:最初使用开发账号profile执行开发账号的bootstrap,后来改为用工具账号profile执行,错误略有变化但问题仍存在
  2. 手动更新工具账号EventBus策略,添加工具账号权限:
    修改前策略:
{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "LabDemoInfraDevCodeCommitEventBusPolicy",
    "Effect": "Allow",
    "Principal": 
    {
      "AWS": "arn:aws:iam::<DevelopmentAccount>:root"
    },
    "Action": "events:PutEvents",
    "Resource": "arn:aws:events:us-east-1:<ToolingAccount>:event-bus/LabDemoInfraDevPipelineEnvtBus"
  }]
}

修改后策略:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "LabDemoInfraDevCodeCommitEventBusPolicy",
    "Effect": "Allow",
    "Principal": [
    {
      "AWS": "arn:aws:iam::<DevelopmentAccount>:root"
    },
    {
      "AWS": "arn:aws:iam::<ToolingAccount>:root"
    }],
    "Action": "events:PutEvents",
    "Resource": "arn:aws:events:us-east-1:<ToolingAccount>:event-bus/LabDemoInfraDevPipelineEnvtBus"
  }]
}
  1. 尝试硬编码账号ID,--verbose命令显示账号信息正确,但问题未解决

内容的提问来源于stack exchange,提问作者Karthik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 09:57:21