AWS Route53跨账号子域委托部署遇权限错误求助
Route53跨账号子域授权部署报错排查与解决
问题背景
我有一个托管Route53父域example.com的AWS账号,尝试创建子域beta.example.com和prod.example.com。按照文档要求在子域账号中配置跨账号委托角色后,部署CloudFormation时出现权限错误。
已编写的CDK代码
父域账号CDK代码
this.crossDelegationRole= new Role(this, 'CrossAccountRole', { //角色名称必须可预测 roleName: 'MyDelegationRole', //其他账号 assumedBy: new CompositePrincipal(new AccountPrincipal('Account A#'), new AccountPrincipal('Account B#')), });
子域账号CDK代码
const delegationRoleArn = Stack.of(this).formatArn({ region: '', //IAM在每个分区中是全局的 service: 'iam', account: 'Parent Account #', resource: 'role', resourceName: 'MyDelegationRole', }); const delegationRole = Role.fromRoleArn(this, 'DelegationRole', delegationRoleArn); //创建记录 const x =new CrossAccountZoneDelegationRecord(this, 'delegate', { delegatedZone: this.hostedZone, parentHostedZoneName: 'example.com', //也可使用parentHostedZoneId delegationRole, });
部署报错信息
Received response status [FAILED] from custom resource. Message returned: AccessDenied: User: arn:aws:sts::ParentAccount#:assumed-role/MyDelegationRole/cross-account-zone-delegation-1675020358038 is not authorized to perform: route53:ListHostedZonesByName because no identity-based policy allows the route53:ListHostedZonesByName action at Request.extractError (/var/runtime/node_modules/aws-
自我排查更新
我推测问题出在父账号的委托角色未配置权限,但不确定如何为非公有托管区授权(无法使用parentZone.grantDelegation(crossAccountRole);命令)。
解决方案
你确实遗漏了父账号委托角色的权限配置,具体修复步骤如下:
1. 为父账号的委托角色添加Route53权限
在父域的CDK代码中,为crossDelegationRole手动添加IAM权限策略,授予其操作父托管区的必要权限:
// 父域CDK代码修改:添加权限策略 this.crossDelegationRole = new Role(this, 'CrossAccountRole', { roleName: 'MyDelegationRole', assumedBy: new CompositePrincipal( new AccountPrincipal('Account A#'), new AccountPrincipal('Account B#') ), }); // 为角色添加Route53操作权限 this.crossDelegationRole.addToPolicy(new PolicyStatement({ actions: [ 'route53:ListHostedZonesByName', 'route53:ChangeResourceRecordSets' ], // 替换为你的父托管区ARN,格式为 arn:aws:route53:::hostedzone/你的父托管区ID resources: ['arn:aws:route53:::hostedzone/YOUR_PARENT_ZONE_ID'], }));
权限说明
route53:ListHostedZonesByName:CloudFormation自定义资源需要通过该API定位父托管区;route53:ChangeResourceRecordSets:用于在父托管区添加子域的NS记录,完成授权;- 资源必须指定父托管区的ARN:由于是非公有托管区,无法通过
grantDelegation自动生成权限,必须手动指定具体托管区资源。
2. 优化子域配置(可选)
如果父托管区是非公有的,建议在子域CDK代码中直接使用parentHostedZoneId替代parentHostedZoneName,减少对ListHostedZonesByName操作的依赖,提升部署稳定性。
内容的提问来源于stack exchange,提问作者ReactNewbie123
相关产品推荐
相关产品推荐

