You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

借助IAM Identity Center实现跨账户Route 53编辑权限问题排查

解决跨账户IAM Identity Center访问Route53托管区的权限问题

1. 修正Route53托管区ARN格式

你的内联策略中,托管区ARN存在格式错误:

  • 错误格式:arn:aws:route53:::hostedzone/<zoneid>(多了一个冒号,缺少托管区所属账户A的ID)
  • 正确格式:arn:aws:route53::<account-a-id>:hostedzone/<zoneid>

将策略中的ARN替换为包含账户A ID的正确格式,示例如下:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "route53:GetHostedZone",
                "route53:ChangeResourceRecordSets",
                "route53:ListResourceRecordSets"
            ],
            "Resource": [
                "arn:aws:route53::<account-a-id>:hostedzone/<zoneid>"
            ]
        }
    ]
}

2. 配置账户A的Route53托管区资源策略

托管区属于账户A,仅账户B的权限允许无法完成跨账户访问,需要在账户A中为该托管区添加资源策略,允许账户B的Identity Center身份访问:

  1. 登录账户A的AWS控制台,进入目标Route53托管区详情页
  2. 切换到「权限」标签,点击「编辑」
  3. 添加以下资源策略(替换占位符):
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:sts::<account-b-id>:assumed-role/AWSReservedSSO_AdministratorAccess_<etc>/<identity-center-user>"
            },
            "Action": [
                "route53:GetHostedZone",
                "route53:ChangeResourceRecordSets",
                "route53:ListResourceRecordSets"
            ],
            "Resource": "arn:aws:route53::<account-a-id>:hostedzone/<zoneid>"
        }
    ]
}

若需允许账户B内所有Identity Center用户访问,可将Principal改为"AWS": "arn:aws:iam::<account-b-id>:root"

3. 验证身份切换逻辑(可选)

如果采用Assume Role方式访问账户A的托管区,需确保:

  • 账户A中创建的角色信任策略包含账户B的Identity Center用户/角色ARN,示例:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:sts::<account-b-id>:assumed-role/AWSReservedSSO_AdministratorAccess_<etc>/<identity-center-user>"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}
  • 该角色已配置访问Route53托管区的权限
  • 在CLI中通过aws sts assume-role切换角色,或在profile配置中指定role_arn参数

4. 刷新Identity Center权限缓存

IAM Identity Center的权限变更可能存在缓存延迟,执行以下操作确保权限生效:

  • 退出当前Identity Center会话后重新登录
  • 执行aws sso logout --profile staging后重新登录

完成以上步骤后,重新测试命令:

aws route53 get-hosted-zone --profile staging --id <zoneid>

内容的提问来源于stack exchange,提问作者mattcooney

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 20:15:08