AWS FileGateway缓存刷新触发AccessDeniedException,求排查
Let's break down what's likely causing your AccessDenied error and how to fix it:
1. Incorrect File Share ARN Format
The most obvious and common culprit here is your misformatted ARN. You're constructing it as:
"arn:aws:storagegateway:"+region+":"+awsId+":"+shareID
But AWS requires the ARN to include the share/ prefix before the share ID. Your current ARN looks like arn:aws:storagegateway:region:account-id:share-id, while the valid format is arn:aws:storagegateway:region:account-id:share/share-id.
Fix this by updating your ARN construction code:
refreshCacheRequest.setFileShareARN("arn:aws:storagegateway:"+region+":"+awsId+":share/"+shareID);
This tiny missing segment often triggers AccessDenied errors because IAM policies strictly validate against the exact resource ARN structure.
2. Verify IAM Policy Resource Matching
Even if you're confident your IAM user has the right permissions, double-check that your policy's resource entry uses the correct ARN format. For example, your policy should include a statement like this:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "storagegateway:RefreshCache", "Resource": "arn:aws:storagegateway:your-region:your-account-id:share/your-share-id" } ] }
If your policy uses the wrong ARN format (without share/), AWS will deny access even if the action is allowed—since the resource doesn't match what the policy expects.
3. Confirm Account ID Alignment
Make sure the awsId value you're using is the AWS account ID where the File Gateway and File Share are hosted. While you mentioned using the IAM access key's account ID, if you're working across accounts (unlikely unless intentional), you'd need additional trust relationships configured. For most standard use cases, the IAM user's account should match the File Gateway's account.
4. Quick Validation Step
Before re-running your code, manually confirm the correct ARN by:
- Navigating to the AWS Storage Gateway console
- Finding your target File Share
- Copying the full ARN from the details panel
- Using this exact ARN in your
setFileShareARNcall to eliminate any typos or formatting mistakes
After fixing the ARN format, your refreshCache call should work as expected (assuming your IAM permissions are correctly configured).
内容的提问来源于stack exchange,提问作者bumi25

