无法复制 Elasticache 备份

Mad*_*deo 6 amazon-s3 amazon-web-services amazon-elasticache

我已逐步按照这些说明进行操作:https ://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/backups-exporting.html

但是我有以下错误:

An error occurred (InvalidParameterValue) when calling the CopySnapshot operation: Elasticache was unable to validate the authenticated user has access on the S3 bucket ...
Run Code Online (Sandbox Code Playgroud)

该存储桶与备份位于同一区域

这是我的存储桶配置:

{
    "LocationConstraint": "eu-central-1"
}

Run Code Online (Sandbox Code Playgroud)
{
    "Version": "2012-10-17",
    "Id": "xxxxxxxx",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "eu-central-1.elasticache-snapshot.amazonaws.com"
            },
            "Action": [
                "s3:PutObject",
                "s3:GetObject",
                "s3:ListBucket",
                "s3:GetBucketAcl",
                "s3:ListMultipartUploadParts",
                "s3:ListBucketMultipartUploads"
            ],
            "Resource": [
                "arn:aws:s3:::my-bucket-name/*",
                "arn:aws:s3:::my-bucket-name"
            ]
        }
    ]
}

Run Code Online (Sandbox Code Playgroud)

这是快照

{
    "Snapshots": [
        {
            "SnapshotName": "my-snapshot-name",
            "CacheClusterId": "xxxxxxxx-xxx",
            "SnapshotStatus": "available",
            "SnapshotSource": "manual",
            "CacheNodeType": "cache.t2.micro",
            "Engine": "redis",
            "EngineVersion": "5.0.3",
            "NumCacheNodes": 1,
            "PreferredAvailabilityZone": "eu-central-1c",
            "CacheClusterCreateTime": "xxxxxxx",
            "PreferredMaintenanceWindow": "mon:02:30-mon:03:30",
            "Port": 6379,
            "CacheParameterGroupName": "default.redis5.0",
            "CacheSubnetGroupName": "internal",
            "VpcId": "xxxxx",
            "AutoMinorVersionUpgrade": true,
            "SnapshotRetentionLimit": 7,
            "SnapshotWindow": "00:00-02:00",
            "NodeSnapshots": [
                {
                    "CacheNodeId": "0001",
                    "CacheSize": "33 MB",
                    "CacheNodeCreateTime": "xxxxxx",
                    "SnapshotCreateTime": "xxxxxx"
                }
            ],
            "ARN": "arn:aws:elasticache:eu-central-1:000000000:snapshot:my-snapshot-name",
            "DataTiering": "disabled"
        }
    ]
}

Run Code Online (Sandbox Code Playgroud)

更新

显然 AWS 通过添加有关 ACL 的重要信息更新了他们的文档,请查看已接受的答案以获取更多信息。

Nik*_*had 7

这里非常重要的一步是添加 ACL,如文档中所述:

使用以下选项添加受让人 Canonical ID 540804c33a284a299d2547575ce1010f2312ef3da9b3a053c8bc45bf233e4353 :

  • 对象:列表、写入
  • 存储桶 ACL:读、写

在此输入图像描述

我添加了此 ACL 权限,它开始像魅力一样工作。

添加此 ACL 后,我的配置如下所示。 在此输入图像描述 在此输入图像描述

完整参考文档链接:https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/backups-exporting.html#backups-exporting-grant-access