今天被要求设置ALB 的访问日志,结果设置的时候,总是报错,结果查了文档:
https://docs.amazonaws.cn/elasticloadbalancing/latest/application/load-balancer-access-logs.html
发现s3 的权限设置要加下面这么一段:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::elb-account-id:root"
},
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::