You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Route53跨账号子域委托部署遇权限错误求助

Route53跨账号子域授权部署报错排查与解决

问题背景

我有一个托管Route53父域example.com的AWS账号,尝试创建子域beta.example.com和prod.example.com。按照文档要求在子域账号中配置跨账号委托角色后,部署CloudFormation时出现权限错误。

已编写的CDK代码

父域账号CDK代码

this.crossDelegationRole= new Role(this, 'CrossAccountRole', {
    //角色名称必须可预测
    roleName: 'MyDelegationRole',
    //其他账号
    assumedBy: new CompositePrincipal(new AccountPrincipal('Account A#'), new AccountPrincipal('Account B#')),
});

子域账号CDK代码

const delegationRoleArn = Stack.of(this).formatArn({
    region: '', //IAM在每个分区中是全局的
    service: 'iam',
    account: 'Parent Account #',
    resource: 'role',
    resourceName: 'MyDelegationRole',
});
const delegationRole = Role.fromRoleArn(this, 'DelegationRole', delegationRoleArn);
    
//创建记录
const x =new CrossAccountZoneDelegationRecord(this, 'delegate', {
    delegatedZone: this.hostedZone,
    parentHostedZoneName: 'example.com', //也可使用parentHostedZoneId
    delegationRole,
});

部署报错信息

Received response status [FAILED] from custom resource. Message returned: AccessDenied: User: arn:aws:sts::ParentAccount#:assumed-role/MyDelegationRole/cross-account-zone-delegation-1675020358038 is not authorized to perform: route53:ListHostedZonesByName because no identity-based policy allows the route53:ListHostedZonesByName action at Request.extractError (/var/runtime/node_modules/aws-

自我排查更新

我推测问题出在父账号的委托角色未配置权限,但不确定如何为非公有托管区授权(无法使用parentZone.grantDelegation(crossAccountRole);命令)。

解决方案

你确实遗漏了父账号委托角色的权限配置,具体修复步骤如下:

1. 为父账号的委托角色添加Route53权限

在父域的CDK代码中,为crossDelegationRole手动添加IAM权限策略,授予其操作父托管区的必要权限:

// 父域CDK代码修改:添加权限策略
this.crossDelegationRole = new Role(this, 'CrossAccountRole', {
    roleName: 'MyDelegationRole',
    assumedBy: new CompositePrincipal(
        new AccountPrincipal('Account A#'),
        new AccountPrincipal('Account B#')
    ),
});

// 为角色添加Route53操作权限
this.crossDelegationRole.addToPolicy(new PolicyStatement({
    actions: [
        'route53:ListHostedZonesByName',
        'route53:ChangeResourceRecordSets'
    ],
    // 替换为你的父托管区ARN,格式为 arn:aws:route53:::hostedzone/你的父托管区ID
    resources: ['arn:aws:route53:::hostedzone/YOUR_PARENT_ZONE_ID'],
}));

权限说明

  • route53:ListHostedZonesByName:CloudFormation自定义资源需要通过该API定位父托管区;
  • route53:ChangeResourceRecordSets:用于在父托管区添加子域的NS记录,完成授权;
  • 资源必须指定父托管区的ARN:由于是非公有托管区,无法通过grantDelegation自动生成权限,必须手动指定具体托管区资源。

2. 优化子域配置(可选)

如果父托管区是非公有的,建议在子域CDK代码中直接使用parentHostedZoneId替代parentHostedZoneName,减少对ListHostedZonesByName操作的依赖,提升部署稳定性。

内容的提问来源于stack exchange,提问作者ReactNewbie123

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 21:41:11