如何用Terraform在stag账户创建IAM策略与角色实现跨账号S3访问?
问题与解决方案
背景
我原本手动在stag账号(222222222222)中创建IAM策略和角色,允许root账号(111111111111)devops组的用户列出stag账号下所有S3对象。现在需要用Terraform替代手动流程,但网上多数示例要么在多账号重复创建用户(不符合我的架构),要么在root账号创建策略和角色,导致用户john使用CLI配置role_arn = arn:aws:iam::222222222222:role/devops时出现错误:
An error occurred (AccessDenied) when calling the AssumeRole operation: User: arn:aws:iam::111111111111:user/john is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::222222222222:role/devops
架构配置
- root账号(111111111111):仅管理IAM用户和组,无其他资源
- 用户john属于devops组
- stag账号(222222222222):仅用于S3服务,不管理IAM用户和组
- 包含多个S3存储桶
需求
允许john执行aws s3 ls命令列出stag账号下所有S3存储桶中的对象。
手动创建的资源(stag账号)
IAM策略(devops-role-permissions)
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:*", "Resource": "*" } ] }
IAM角色(devops)
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "sts:AssumeRole", "Principal": { "AWS": "arn:aws:iam::111111111111:root" } } ] }
现有Root账号Terraform配置
IAM策略(允许devops组切换stag账号角色)
resource "aws_iam_policy" "devops_role_assumption_in_stag_account" { name = "devops-role-assumption-in-stag-account" description = "Allows devops group to assume role in stag account." policy = jsonencode( { "Version" : "2012-10-17", "Statement" : [ { "Effect" : "Allow", "Action" : "sts:AssumeRole", "Resource" : "arn:aws:iam::222222222222:role/devops" } ] } ) }
组策略关联
resource "aws_iam_group_policy_attachment" "devops_role_assumption_in_stag_account" { group = aws_iam_group.devops.name policy_arn = aws_iam_policy.devops_role_assumption_in_stag_account.arn }
完整Terraform解决方案
1. Stag账号的Terraform配置
需要在stag账号的Terraform配置中创建对应的IAM角色和策略,并完成关联:
# 创建S3权限策略 resource "aws_iam_policy" "devops_role_permissions" { name = "devops-role-permissions" description = "Grants full S3 access for devops role" policy = jsonencode({ Version = "2012-10-17" Statement = [ { Effect = "Allow" Action = "s3:*" Resource = "*" } ] }) } # 创建允许root账号devops组用户切换的角色 resource "aws_iam_role" "devops" { name = "devops" assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Effect = "Allow" Principal = { AWS = "arn:aws:iam::111111111111:root" } Action = "sts:AssumeRole" } ] }) } # 将策略关联到角色 resource "aws_iam_role_policy_attachment" "devops_role_permissions" { role = aws_iam_role.devops.name policy_arn = aws_iam_policy.devops_role_permissions.arn }
2. 确认Root账号配置
你已有的Root账号Terraform配置无需修改,确保aws_iam_group.devops资源已正确定义(即devops组存在)。
3. CLI配置示例
用户john需要在本地AWS CLI配置文件(~/.aws/config)中添加stag账号的角色配置:
[profile stag] role_arn = arn:aws:iam::222222222222:role/devops source_profile = root
其中source_profile是john在root账号的CLI配置文件(~/.aws/credentials)中的配置项名称,包含他的Access Key和Secret Key。
4. 验证命令
执行以下命令验证权限:
aws s3 ls --profile stag
内容的提问来源于stack exchange,提问作者BentCoder
相关产品推荐
相关产品推荐

