Serverless部署CloudTrail遇S3桶策略错误:PolicyDocument需为对象
Fixing the S3 Bucket Policy Error for AWS CloudTrail in Serverless
Let's break down the issue you're facing and fix it step by step.
The Root Cause
The error Value of property PolicyDocument must be an object pops up because you set PolicyDocument directly to an array of statements, but AWS requires it to be an object that includes a Version field and a Statement array (where your permission rules live).
Corrected CloudFormation Code
Here's the fixed version of your CloudTrailBucketPolicy resource, with proper formatting and the exact permissions CloudTrail needs:
CloudTrailBucketPolicy: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref CloudTrailBucket # Links the policy to your actual bucket resource PolicyDocument: Version: "2012-10-17" # Required standard policy version Statement: - Sid: AllowCloudTrailBucketAclAccess Effect: Allow Principal: Service: cloudtrail.amazonaws.com Action: "s3:GetBucketAcl" Resource: !Sub "arn:aws:s3:::${CloudTrailBucket}" - Sid: AllowCloudTrailLogDelivery Effect: Allow Principal: Service: cloudtrail.amazonaws.com Action: "s3:PutObject" Resource: !Sub "arn:aws:s3:::${CloudTrailBucket}/*" Condition: StringEquals: s3:x-amz-acl: "bucket-owner-full-control" # Ensures your account owns the log files
Key Fixes & Best Practices
- Proper Policy Structure: Wrapped your permission rules inside a
Statementarray, nested under thePolicyDocumentobject (along with the mandatoryVersionfield). - Dynamic Bucket References: Used
!Refand!Subto pull your bucket's name dynamically instead of hardcoding it—this guarantees the ARN matches the bucket created by your Serverless stack. - Restricted Principal: Changed the first statement's principal from
*tocloudtrail.amazonaws.comto avoid overly broad access (a critical security best practice). - Ownership Condition: Added the
s3:x-amz-aclcondition to ensure your AWS account retains full control over the log files CloudTrail writes—this often prevents additional permission errors down the line. - Explicit Bucket Link: Added the
Bucketfield to directly associate the policy with yourCloudTrailBucketresource.
Quick Additional Check
For better reliability, ensure your CloudTrailBucket has versioning enabled (recommended for CloudTrail logs):
CloudTrailBucket: Type: AWS::S3::Bucket Properties: VersioningConfiguration: Status: Enabled
内容的提问来源于stack exchange,提问作者AnonymousAlias
相关产品推荐
相关产品推荐

