gpt4 book ai didi

amazon-s3 - s3 存储桶策略中的无效条件

转载 作者:行者123 更新时间:2023-12-03 07:32:02 25 4
gpt4 key购买 nike

我正在创建一个cloudformation堆栈,其中模板创建云跟踪,然后创建S3存储桶,并将所有日志推送到S3存储桶。

我尝试创建 Cloud Trail、s3 存储桶,并尝试将 s3 存储桶策略附加到该存储桶

Parameters:
loggroupname:
Type: String
trailname:
Type: String
s3bucketname:
Type: String
Resources:
createloggroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: !Sub ${loggroupname}
creates3bucket:
Type: AWS::S3::Bucket
Properties:
BucketName: !Sub ${s3bucketname}
s3bucketpolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Sub ${s3bucketname}
PolicyDocument:
Version: '2012-10-17'
Statement:
- Sid: 'AWSCloudTrailAclCheck20150319'
Effect: 'Allow'
Principal:
Service: 'cloudtrail.amazonaws.com'
Action: 's3:GetBucketAcl'
Resource:
!Sub 'arn:aws:s3:::${s3bucketname}'
PolicyDocument:
Version: '2012-10-17'
Statement:
- Sid: AWSCloudTrailWrite20150319
Effect: 'Allow'
Principal:
Service: 'cloudtrail.amazonaws.com'
Action: 's3:PutObject'
Resource:
!Sub 'arn:aws:s3:::${s3bucketname}/AWSLogs/${AWS::AccountId}/*'
Condition:
StringsEquals:
s3:x-amz-acl: 'bucket-owner-full-control'
myvpctrail:
DependsOn:
- s3bucketpolicy
Type: AWS::CloudTrail::Trail
Properties:
IsLogging: true
IsMultiRegionTrail: true
IncludeGlobalServiceEvents: true
S3BucketName: !Ref creates3bucket

无效条件类型:StringsEquals(服务:Amazon S3;状态代码:400;错误代码:MalformedPolicy;请求 ID:F7439B111E82A3FA;S3 扩展请求 ID:IGU1L7BB77WcrhPtmydd5j6viQdMK0vqA3Qo4RTS209FAvjT3q6wBIsyabdt5B7pBFvdr 2MT+sM=)

最佳答案

简单的错字。

这是StringEquals而不是StringsEquals。

来源:https://docs.aws.amazon.com/AmazonS3/latest/dev/amazon-s3-policy-keys.html

关于amazon-s3 - s3 存储桶策略中的无效条件,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/57582616/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com