gpt4 book ai didi

amazon-web-services - 在 Cloud Trail 中检测到存储桶的 S3 存储桶策略不正确

转载 作者:行者123 更新时间:2023-12-03 07:35:56 26 4
gpt4 key购买 nike

收到此错误检测到存储桶的 S3 存储桶策略不正确:

(Service: AWSCloudTrail; Status Code: 400; Error Code: InsufficientS3BucketPolicyException; Request ID: ebaf35b8-a38e-4357-a742-af5fa92bbc43)

Parameters:
trailname:
Type: String
s3bucketname:
Type: String
Resources:
myvpctrail:
DependsOn:
- s3bucketpolicy
- creates3bucket
Type: AWS::CloudTrail::Trail
Properties:
IsLogging: true
IsMultiRegionTrail: true
IncludeGlobalServiceEvents: true
S3BucketName: !Ref creates3bucket
creates3bucket:
Type: AWS::S3::Bucket
Properties:
BucketName: !Sub ${s3bucketname}
s3bucketpolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Sub ${s3bucketname}
PolicyDocument:
Version: '2012-10-17'
Statement:
- Sid: 'AWSCloudTrailAclCheck20150319'
Effect: 'Allow'
Principal:
Service: 'cloudtrail.amazonaws.com'
Action: 's3:GetBucketAcl'
Resource:
!Sub 'arn:aws:s3:::${s3bucketname}'
PolicyDocument:
Version: '2012-10-17'
Statement:
- Sid: AWSCloudTrailWrite20150319
Effect: 'Allow'
Principal:
Service: 'cloudtrail.amazonaws.com'
Action: 's3:PutObject'
Resource:
!Sub 'arn:aws:s3:::${s3bucketname}/AWSLogs/${AWS::AccountId}/*'
Condition:
StringEquals:
s3:x-amz-acl: 'bucket-owner-full-control'

Incorrect S3 bucket policy is detected for bucket: (Service: AWSCloudTrail; Status Code: 400; Error Code: InsufficientS3BucketPolicyException; Request ID: ebaf35b8-a38e-4357-a742-af5fa92bbc43)enter code here

最佳答案

您应该非常小心 YAML 中的缩进和属性名称。我相信问题出在 Condition 中,应该是这样的:

        Condition:
StringEquals:
's3:x-amz-acl': bucket-owner-full-control

将此与您的进行比较:

      Condition:
StringEquals:
s3:x-amz-acl: 'bucket-owner-full-control'

关于amazon-web-services - 在 Cloud Trail 中检测到存储桶的 S3 存储桶策略不正确,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/57596125/

26 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com