如何使用boto3获取AWS组织内所有账号的主联系人信息
获取AWS组织内所有账号主联系人信息的方法及权限说明
没问题,我来帮你搞定这个需求!AWS确实没有提供直接批量获取组织内所有账号联系人信息的API,但我们可以通过先获取组织内全部账号ID,再逐个调用Account服务的get_contact_information接口的方式实现,下面是具体步骤和权限要求:
实现思路与代码示例
核心逻辑是两步走:
- 用Organizations API拉取组织内所有账号的基础信息(ID、名称、邮箱等)
- 遍历每个账号ID,调用Account服务的接口获取联系人信息,最后合并数据
完整Python代码示例
import boto3 import time def get_all_org_accounts(): """获取组织内所有账号的基础信息""" org_client = boto3.client('organizations') accounts = [] # 处理分页,避免账号数量多的时候漏数据 paginator = org_client.get_paginator('list_accounts') for page in paginator.paginate(): accounts.extend(page['Accounts']) return accounts def get_account_contact_info(account_id): """获取单个账号的主联系人信息""" # Account是全局服务,必须指定一个区域(推荐us-east-1) account_client = boto3.client('account', region_name='us-east-1') try: response = account_client.get_contact_information(AccountId=account_id) return response['ContactInformation'] except Exception as e: print(f"获取账号 {account_id} 联系人信息失败: {str(e)}") return None def get_ou_path(account_id): """可选:获取账号所在的OU完整路径(从根OU到当前OU)""" org_client = boto3.client('organizations') path_segments = [] current_id = account_id while True: parent_response = org_client.list_parents(ChildId=current_id) parents = parent_response['Parents'] if not parents: break parent = parents[0] if parent['Type'] == 'ORGANIZATIONAL_UNIT': ou_details = org_client.describe_organizational_unit(OrganizationalUnitId=parent['Id']) path_segments.append(ou_details['OrganizationalUnit']['Name']) current_id = parent['Id'] else: # 到达根节点,停止遍历 break # 反转得到从根到当前OU的路径 path_segments.reverse() return '/'.join(path_segments) if path_segments else 'Root' def main(): org_accounts = get_all_org_accounts() all_account_data = [] for account in org_accounts: account_id = account['Id'] print(f"正在处理账号: {account_id} ({account['Name']})") # 获取联系人信息 contact_info = get_account_contact_info(account_id) if not contact_info: continue # 获取OU路径(可选) ou_path = get_ou_path(account_id) # 合并所有数据 merged_data = { 'AccountId': account_id, 'AccountName': account['Name'], 'AccountEmail': account['Email'], 'OUPath': ou_path, **contact_info } all_account_data.append(merged_data) # 加一点延迟,避免触发API限流(可选,账号多的时候建议加) time.sleep(0.5) # 这里可以把数据存入文件或数据库 print("\n所有账号联系人信息获取完成!") print(all_account_data) if __name__ == "__main__": main()
所需IAM权限
你需要为运行代码的IAM角色/用户配置以下权限,分为Organizations和Account服务两部分:
权限策略示例
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "organizations:ListAccounts", "organizations:ListParents", "organizations:DescribeOrganizationalUnit" ], "Resource": "*" }, { "Effect": "Allow", "Action": "account:GetContactInformation", "Resource": "arn:aws:account::*:account/*" } ] }
权限说明
- Organizations权限:
organizations:ListAccounts:用于拉取组织内所有账号的基础信息organizations:ListParents+organizations:DescribeOrganizationalUnit:可选,用于获取账号所在的OU路径,如果不需要OU路径可以去掉这两个权限
- Account权限:
account:GetContactInformation:用于获取单个账号的主联系人信息,资源配置为*可以覆盖组织内所有账号
注意事项
- Account服务是全局服务,必须指定区域(推荐用
us-east-1,其他部分区域也支持,但us-east-1兼容性最好) - 如果组织内账号数量较多,记得添加适当的延迟(比如代码中的
time.sleep(0.5)),避免触发AWS的API速率限制 - 确保运行代码的身份(IAM角色/用户)是在组织的管理账号下,或者拥有跨账号访问这些资源的权限
内容的提问来源于stack exchange,提问作者imported
相关产品推荐
相关产品推荐

