配置跨账号S3访问SageMaker角色失败 报AccessDenied错误
需求
创建SageMaker GroundTruth标注作业,将作业的输入/输出存储路径指向其他AWS账号下的S3存储桶。
前置配置说明
定义账号角色:
- Account_A(账号A):运行SageMaker GroundTruth标注作业的账号
- Account_B(账号B):目标S3存储桶所属账号
已完成的配置如下:
- Account_A侧:创建
AmazonSageMaker-ExecutionRole角色,附加3条策略:- AmazonSageMakerFullAccess托管策略
Account_B_S3_AccessPolicy:用于访问Account_B目标S3存储桶的自定义策略AssumeRolePolicy:允许扮演arn:aws:iam::Account_B:role/Cross-Account-S3-Access-Role的角色扮演策略
- Account_B侧:创建
Cross-Account-S3-Access-Role角色,配置1条权限策略+1条信任关系:S3_AccessPolicy:授予角色自身对Account_B目标S3存储桶的读写权限- 信任关系:将信任主体设置为
arn:aws:iam::Account_A:role/AmazonSageMaker-ExecutionRole
报错现象
使用AmazonSageMaker-ExecutionRole角色创建标注作业时抛出如下权限错误:
AccessDenied: Access Denied - The S3 bucket 'Account_B_S3_bucket_name' you entered in Input dataset location cannot be reached. Either the bucket does not exist, or you do not have permission to access it. If the bucket does not exist, update Input dataset location with a new S3 URI. If the bucket exists, give the IAM entity you are using to create this labeling job permission to read and write to this S3 bucket, and try your request again.
错误提示指向输入数据集位置的Account_B所属S3桶无法访问,判定原因是桶不存在或访问权限不足。
根因分析
核心配置逻辑错误:SageMaker GroundTruth在创建作业的前置S3连通性校验阶段,不会自动触发AssumeRole跨账号角色扮演流程,只会直接使用当前选中的执行角色(即Account_A的AmazonSageMaker-ExecutionRole)身份直接请求目标S3路径做权限校验。之前配置的角色扮演策略在校验阶段完全不会生效,自然会返回访问被拒。
排查修复步骤
按以下顺序逐一排查调整:
- 基础配置校验
- 核对输入的S3 URI拼写,确认桶名、路径无错误,目标桶确实存在于Account_B的对应AWS区域
- 确认Account_B侧没有配置组织SCP、桶级别拒绝规则拦截Account_A的跨账号访问
- 补全Account_A执行角色的直接S3访问权限
不要仅依赖跨账号角色扮演通过校验,直接在AmazonSageMaker-ExecutionRole附加的Account_B_S3_AccessPolicy中添加目标桶的最小必要权限,策略参考如下,替换占位符为实际资源信息:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetBucketLocation", "s3:ListBucket" ], "Resource": "arn:aws:s3:::Account_B_S3_bucket_name" }, { "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject", "s3:DeleteObject" ], "Resource": "arn:aws:s3:::Account_B_S3_bucket_name/*" } ] } - 配置Account_B目标S3桶的跨账号访问策略
仅配置IAM角色权限不足以完成跨账号S3访问,必须在目标桶的桶策略中添加放行规则,允许Account_A的执行角色访问,策略参考如下:{ "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::Account_A:role/AmazonSageMaker-ExecutionRole" }, "Action": [ "s3:GetBucketLocation", "s3:ListBucket", "s3:GetObject", "s3:PutObject", "s3:DeleteObject" ], "Resource": [ "arn:aws:s3:::Account_B_S3_bucket_name", "arn:aws:s3:::Account_B_S3_bucket_name/*" ] } - 补全KMS加密权限(仅桶开启自定义KMS加密时需要)
如果Account_B的目标S3桶使用账号内自定义KMS密钥做默认加密,需要在对应KMS密钥的资源策略中,给Account_A的AmazonSageMaker-ExecutionRole授予kms:Decrypt、kms:GenerateDataKey权限,否则读写加密对象时仍会报权限错误。 - 重试创建作业
之前配置的Account_B侧跨账号角色可以保留,适配作业运行过程中的其他跨账号访问场景,但创建阶段的连通性校验必须保证Account_A的执行角色本身可以直接访问目标S3路径,无法通过角色扮演绕过该逻辑。
内容的提问来源于stack exchange,提问作者Kalmesh Sam

