CDK跨账号Event Rule触发CodeCommit失败问题求助
跨账号CDK部署EventRule权限问题
环境配置
- 工具账号:托管Pipeline和EventBus,接收CodeCommit更新通知
- 开发账号:包含CodeCommit仓库和Event Rule,负责向工具账号EventBus发送通知,Dev环境资源部署在此账号
- 生产账号:Prod环境资源部署在此账号
已配置的信任关系
执行以下CDK Bootstrap命令完成账号信任配置:
# 工具账号 npx cdk bootstrap aws://<ToolingAccount>/us-east-1 --no-bootstrap-customer-key --cloudformation-execution-policies 'arn:aws:iam::aws:policy/AdministratorAccess' --verbose --profile <ToolingAccountProfile> # 开发账号 npx cdk bootstrap aws://<DevelopmentAccount>/us-east-1 --no-bootstrap-customer-key --cloudformation-execution-policies arn:aws:iam::aws:policy/AdministratorAccess --trust <ToolingAccount> --profile <ToolingAccountProfile> # 生产账号 npx cdk bootstrap aws://<ProductionAccount>/us-east-1 --no-bootstrap-customer-key --cloudformation-execution-policies 'arn:aws:iam::aws:policy/AdministratorAccess' --trust <ToolingAccount> --profile <ToolingAccountProfile>
已成功部署的资源
已从本地向Dev、Prod环境部署基础设施,并在工具账号中通过CDK创建了EventBus,对应的Stack代码如下:
class LabDemoInfraCornerStonePipelineStack(Stack): def __init__(self, scope: Construct, construct_id: str, config: dict, pipeline_type: str, **kwargs) -> None: super().__init__(scope, construct_id, **kwargs) if pipeline_type == "Dev": infra_event_dev_bus = events.CfnEventBus( self, config['DemoInfraDevPipelineEventBusName'], name=config['DemoInfraDevPipelineEventBusName'] ) events.CfnEventBusPolicy( self, "LabDemoInfraDevCodeCommitEventBusPolicy", event_bus_name=infra_event_dev_bus.attr_name, statement={ "Effect": "Allow", "Principal" : {"AWS" : f"arn:aws:iam::<DevelopmentAccounNo>:root"}, "Action": "events:PutEvents", "Resource": f"arn:aws:events:{self.region}:{self.account}:event-bus/{infra_event_dev_bus.attr_name}" }, statement_id="LabDemoInfraDevCodeCommitEventBusPolicy" )
部署命令:
npx cdk deploy InfraCornerStoneLabDemoPipelineStack --profile <ToolingAccountProfile>
部署开发账号EventRule时的错误
尝试在开发账号中部署以下EventRule(app.py已传入开发账号作为env变量):
class InfraToolingLabDemoPipelineStack(Stack): def __init__(self, scope: Construct, construct_id: str, config: dict, pipeline_type: str, **kwargs) -> None: super().__init__(scope, construct_id, **kwargs) if pipeline_type == "Dev": events.CfnRule( self, config['DemoInfraDevPipelineEventRuleName'], description=f"Sends CodeCommit repository events to the Tooling Pipeline Account {config['DemoInfraDevPipelineEventBusName']} event bus.", event_bus_name=config['DemoInfraDevPipelineEventBusName'], event_pattern= { "detail-type": "CodeCommit Repository State Change", "source": "aws.codecommit", "resources": [f"arn:aws:codecommit:${self.region}:${self.account}:${config['demo_infra_repo']}"] }, state='ENABLED', targets=[ events.CfnRule.TargetProperty( arn=f"arn:aws:events:{self.region}:{config['tooling_account_no']}:event-bus/{config['DemoInfraDevPipelineEventBusName']}", id=config['DemoInfraDevPipelineEventRuleName'] ) ] )
部署命令:
cdk deploy InfraToolingLabDemoPipelineStack --profile <ToolingAccountProfile>
收到错误提示:
InfraToolingLabDemoPipelineStack/LabDemoInfraDevPipelineEnvtRule (LabDemoInfraDevPipelineEnvtRule) User: arn:aws:sts:::assumed-role/cdk-labdemo-cfn-exec-role--us-east-1/AWSCloudFormation is not authorized to perform: events:PutRule on resource: arn:aws:events:us-east-1::rule/LabDemoInfraDevPipelineEnvtBus/InfraToolingLabDemo-LabDemoInfraDevPipelin-BR1BO7R0FJ3D because no resource-based policy allows the events:PutRule action
已尝试的排查操作
- 确认开发账号的
cdk-labarmory-cfn-exec-role-<DevelopmentAccount>-us-east-1角色信任关系正确,且拥有管理员权限:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "cloudformation.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }
- 修改Bootstrap执行方式:最初使用开发账号profile执行开发账号的bootstrap,后来改为用工具账号profile执行,错误略有变化但问题仍存在
- 手动更新工具账号EventBus策略,添加工具账号权限:
修改前策略:
{ "Version": "2012-10-17", "Statement": [{ "Sid": "LabDemoInfraDevCodeCommitEventBusPolicy", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::<DevelopmentAccount>:root" }, "Action": "events:PutEvents", "Resource": "arn:aws:events:us-east-1:<ToolingAccount>:event-bus/LabDemoInfraDevPipelineEnvtBus" }] }
修改后策略:
{ "Version": "2012-10-17", "Statement": [{ "Sid": "LabDemoInfraDevCodeCommitEventBusPolicy", "Effect": "Allow", "Principal": [ { "AWS": "arn:aws:iam::<DevelopmentAccount>:root" }, { "AWS": "arn:aws:iam::<ToolingAccount>:root" }], "Action": "events:PutEvents", "Resource": "arn:aws:events:us-east-1:<ToolingAccount>:event-bus/LabDemoInfraDevPipelineEnvtBus" }] }
- 尝试硬编码账号ID,
--verbose命令显示账号信息正确,但问题未解决
内容的提问来源于stack exchange,提问作者Karthik
相关产品推荐
相关产品推荐

