gpt4 book ai didi

amazon-web-services - Terraform - 启用访问负载平衡器日志 InvalidConfigurationRequest : Access Denied for bucket

转载 作者:行者123 更新时间:2023-12-05 02:04:51 34 4
gpt4 key购买 nike

我正在使用 Terraform 配置 ELB,并希望在 S3 存储桶中为 ELB 启用访问日志。当我尝试应用资源时,出现以下错误 - InvalidConfiguration: Access Denied for bucket:

下面是我的 TF 资源,其中包含使用 IAM 策略文档创建的 S3 存储桶策略。

resource "aws_lb" "this" {
name = var.name
load_balancer_type = "application"

access_logs {
bucket = aws_s3_bucket.this.bucket
prefix = var.name
enabled = true
}
}

resource "aws_s3_bucket" "this" {
bucket = "${var.bucket_name}"
acl = "log-delivery-write"
force_destroy = true

}

resource "aws_s3_bucket_policy" "this" {
bucket = "aws_s3_bucket.this.id"
policy = "${data.aws_iam_policy_document.s3_bucket_lb_write.json}"
}


data "aws_iam_policy_document" "s3_bucket_lb_write" {
policy_id = "s3_bucket_lb_logs"

statement {
actions = [
"s3:PutObject",
]
effect = "Allow"
resources = [
"${aws_s3_bucket.this.arn}/*",
]

principals {
identifiers = ["${data.aws_elb_service_account.main.arn}"]
type = "AWS"
}
}

statement {
actions = [
"s3:PutObject"
]
effect = "Allow"
resources = ["${aws_s3_bucket.this.arn}/*"]
principals {
identifiers = ["delivery.logs.amazonaws.com"]
type = "Service"
}
}


statement {
actions = [
"s3:GetBucketAcl"
]
effect = "Allow"
resources = ["${aws_s3_bucket.this.arn}"]
principals {
identifiers = ["delivery.logs.amazonaws.com"]
type = "Service"
}
}
}

output "bucket_name" {
value = "${aws_s3_bucket.this.bucket}"
}

出现以下错误

Error: Error putting S3 policy: NoSuchBucket: The specified bucket does not exist
status code: 404, request id: 5932CFE816059A8D, host id: j5ZBQ2ptHXivx+fu7ai5jbM8PSQR2tCFo4IAvcLkuocxk8rn/r0TG/6YbfRloBFR2WSy8UE7K8Q=

Error: Failure configuring LB attributes: InvalidConfigurationRequest: Access Denied for bucket: test-logs-bucket-xyz. Please check S3bucket permission
status code: 400, request id: ee101cc2-5518-42c8-9542-90dd7bb05e3c

地形版本Terraform v0.12.23

  • provider.aws v3.6.0

最佳答案

错误在:

resource "aws_s3_bucket_policy" "this" {
bucket = "aws_s3_bucket.this.id"
policy = "${data.aws_iam_policy_document.s3_bucket_lb_write.json}"
}

应该是:

resource "aws_s3_bucket_policy" "this" {
bucket = aws_s3_bucket.this.id
policy = data.aws_iam_policy_document.s3_bucket_lb_write.json
}

原始版本 (bucket = "aws_s3_bucket.this.id") 只会尝试查找字面上称为“aws_s3_bucket.this.id”的存储桶。

关于amazon-web-services - Terraform - 启用访问负载平衡器日志 InvalidConfigurationRequest : Access Denied for bucket,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/64001362/

34 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com