借助IAM Identity Center实现跨账户Route 53编辑权限问题排查
解决跨账户IAM Identity Center访问Route53托管区的权限问题
1. 修正Route53托管区ARN格式
你的内联策略中,托管区ARN存在格式错误:
- 错误格式:
arn:aws:route53:::hostedzone/<zoneid>(多了一个冒号,缺少托管区所属账户A的ID) - 正确格式:
arn:aws:route53::<account-a-id>:hostedzone/<zoneid>
将策略中的ARN替换为包含账户A ID的正确格式,示例如下:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "route53:GetHostedZone", "route53:ChangeResourceRecordSets", "route53:ListResourceRecordSets" ], "Resource": [ "arn:aws:route53::<account-a-id>:hostedzone/<zoneid>" ] } ] }
2. 配置账户A的Route53托管区资源策略
托管区属于账户A,仅账户B的权限允许无法完成跨账户访问,需要在账户A中为该托管区添加资源策略,允许账户B的Identity Center身份访问:
- 登录账户A的AWS控制台,进入目标Route53托管区详情页
- 切换到「权限」标签,点击「编辑」
- 添加以下资源策略(替换占位符):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:sts::<account-b-id>:assumed-role/AWSReservedSSO_AdministratorAccess_<etc>/<identity-center-user>" }, "Action": [ "route53:GetHostedZone", "route53:ChangeResourceRecordSets", "route53:ListResourceRecordSets" ], "Resource": "arn:aws:route53::<account-a-id>:hostedzone/<zoneid>" } ] }
若需允许账户B内所有Identity Center用户访问,可将Principal改为"AWS": "arn:aws:iam::<account-b-id>:root"
3. 验证身份切换逻辑(可选)
如果采用Assume Role方式访问账户A的托管区,需确保:
- 账户A中创建的角色信任策略包含账户B的Identity Center用户/角色ARN,示例:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:sts::<account-b-id>:assumed-role/AWSReservedSSO_AdministratorAccess_<etc>/<identity-center-user>" }, "Action": "sts:AssumeRole" } ] }
- 该角色已配置访问Route53托管区的权限
- 在CLI中通过
aws sts assume-role切换角色,或在profile配置中指定role_arn参数
4. 刷新Identity Center权限缓存
IAM Identity Center的权限变更可能存在缓存延迟,执行以下操作确保权限生效:
- 退出当前Identity Center会话后重新登录
- 执行
aws sso logout --profile staging后重新登录
完成以上步骤后,重新测试命令:
aws route53 get-hosted-zone --profile staging --id <zoneid>
内容的提问来源于stack exchange,提问作者mattcooney
相关产品推荐
相关产品推荐

