You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Serverless部署CloudTrail遇S3桶策略错误:PolicyDocument需为对象

Fixing the S3 Bucket Policy Error for AWS CloudTrail in Serverless

Let's break down the issue you're facing and fix it step by step.

The Root Cause

The error Value of property PolicyDocument must be an object pops up because you set PolicyDocument directly to an array of statements, but AWS requires it to be an object that includes a Version field and a Statement array (where your permission rules live).

Corrected CloudFormation Code

Here's the fixed version of your CloudTrailBucketPolicy resource, with proper formatting and the exact permissions CloudTrail needs:

CloudTrailBucketPolicy:
  Type: AWS::S3::BucketPolicy
  Properties:
    Bucket: !Ref CloudTrailBucket  # Links the policy to your actual bucket resource
    PolicyDocument:
      Version: "2012-10-17"  # Required standard policy version
      Statement:
        - Sid: AllowCloudTrailBucketAclAccess
          Effect: Allow
          Principal:
            Service: cloudtrail.amazonaws.com
          Action: "s3:GetBucketAcl"
          Resource: !Sub "arn:aws:s3:::${CloudTrailBucket}"
        - Sid: AllowCloudTrailLogDelivery
          Effect: Allow
          Principal:
            Service: cloudtrail.amazonaws.com
          Action: "s3:PutObject"
          Resource: !Sub "arn:aws:s3:::${CloudTrailBucket}/*"
          Condition:
            StringEquals:
              s3:x-amz-acl: "bucket-owner-full-control"  # Ensures your account owns the log files

Key Fixes & Best Practices

  • Proper Policy Structure: Wrapped your permission rules inside a Statement array, nested under the PolicyDocument object (along with the mandatory Version field).
  • Dynamic Bucket References: Used !Ref and !Sub to pull your bucket's name dynamically instead of hardcoding it—this guarantees the ARN matches the bucket created by your Serverless stack.
  • Restricted Principal: Changed the first statement's principal from * to cloudtrail.amazonaws.com to avoid overly broad access (a critical security best practice).
  • Ownership Condition: Added the s3:x-amz-acl condition to ensure your AWS account retains full control over the log files CloudTrail writes—this often prevents additional permission errors down the line.
  • Explicit Bucket Link: Added the Bucket field to directly associate the policy with your CloudTrailBucket resource.

Quick Additional Check

For better reliability, ensure your CloudTrailBucket has versioning enabled (recommended for CloudTrail logs):

CloudTrailBucket:
  Type: AWS::S3::Bucket
  Properties:
    VersioningConfiguration:
      Status: Enabled

内容的提问来源于stack exchange,提问作者AnonymousAlias

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 07:44:18