You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Terraform在stag账户创建IAM策略与角色实现跨账号S3访问?

问题与解决方案

背景

我原本手动在stag账号(222222222222)中创建IAM策略和角色,允许root账号(111111111111)devops组的用户列出stag账号下所有S3对象。现在需要用Terraform替代手动流程,但网上多数示例要么在多账号重复创建用户(不符合我的架构),要么在root账号创建策略和角色,导致用户john使用CLI配置role_arn = arn:aws:iam::222222222222:role/devops时出现错误:

An error occurred (AccessDenied) when calling the AssumeRole operation: User: arn:aws:iam::111111111111:user/john is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::222222222222:role/devops

架构配置

  • root账号(111111111111):仅管理IAM用户和组,无其他资源
    • 用户john属于devops组
  • stag账号(222222222222):仅用于S3服务,不管理IAM用户和组
    • 包含多个S3存储桶

需求

允许john执行aws s3 ls命令列出stag账号下所有S3存储桶中的对象。

手动创建的资源(stag账号)

IAM策略(devops-role-permissions)

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "s3:*",
            "Resource": "*"
        }
    ]
}

IAM角色(devops)

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "sts:AssumeRole",
            "Principal": {
                "AWS": "arn:aws:iam::111111111111:root"
            }
        }
    ]
}

现有Root账号Terraform配置

IAM策略(允许devops组切换stag账号角色)

resource "aws_iam_policy" "devops_role_assumption_in_stag_account" {
  name        = "devops-role-assumption-in-stag-account"
  description = "Allows devops group to assume role in stag account."

  policy = jsonencode(
    {
      "Version" : "2012-10-17",
      "Statement" : [
        {
          "Effect" : "Allow",
          "Action" : "sts:AssumeRole",
          "Resource" : "arn:aws:iam::222222222222:role/devops"
        }
      ]
    }
  )
}

组策略关联

resource "aws_iam_group_policy_attachment" "devops_role_assumption_in_stag_account" {
  group      = aws_iam_group.devops.name
  policy_arn = aws_iam_policy.devops_role_assumption_in_stag_account.arn
}

完整Terraform解决方案

1. Stag账号的Terraform配置

需要在stag账号的Terraform配置中创建对应的IAM角色和策略,并完成关联:

# 创建S3权限策略
resource "aws_iam_policy" "devops_role_permissions" {
  name        = "devops-role-permissions"
  description = "Grants full S3 access for devops role"

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Effect   = "Allow"
        Action   = "s3:*"
        Resource = "*"
      }
    ]
  })
}

# 创建允许root账号devops组用户切换的角色
resource "aws_iam_role" "devops" {
  name = "devops"

  assume_role_policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Effect = "Allow"
        Principal = {
          AWS = "arn:aws:iam::111111111111:root"
        }
        Action = "sts:AssumeRole"
      }
    ]
  })
}

# 将策略关联到角色
resource "aws_iam_role_policy_attachment" "devops_role_permissions" {
  role       = aws_iam_role.devops.name
  policy_arn = aws_iam_policy.devops_role_permissions.arn
}

2. 确认Root账号配置

你已有的Root账号Terraform配置无需修改,确保aws_iam_group.devops资源已正确定义(即devops组存在)。

3. CLI配置示例

用户john需要在本地AWS CLI配置文件(~/.aws/config)中添加stag账号的角色配置:

[profile stag]
role_arn = arn:aws:iam::222222222222:role/devops
source_profile = root

其中source_profile是john在root账号的CLI配置文件(~/.aws/credentials)中的配置项名称,包含他的Access Key和Secret Key。

4. 验证命令

执行以下命令验证权限:

aws s3 ls --profile stag

内容的提问来源于stack exchange,提问作者BentCoder

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 02:10:18