AWS SAM模板无法创建Jwt Authorizer,关联路由也无法生成
修复AWS SAM中JWT授权器未创建及路由生成失败问题
问题根源分析
你的SAM模板存在两处关键配置错误,导致JWT授权器无法创建、路由生成失败:
- Audience配置错误:
JwtConfiguration.Audience中填写了Issuer地址,实际应该是Clerk提供的客户端ID(格式类似clerk_client_xxxxxx),而非Issuer的URL。 - IdentitySource不符合JWT标准传递方式:当前从查询参数
param获取身份信息,而JWT通常通过Authorization请求头以Bearer <token>格式传递,需修正身份源路径。
修复后的完整SAM模板
AWSTemplateFormatVersion: '2010-09-09' Transform: AWS::Serverless::2016-10-31 Parameters: EnvironmentStackName: Type: String AllowedValues: - dev - prod # 添加Clerk客户端ID参数,方便不同环境配置 ClerkClientId: Type: String Resources: DeviceManagementHttpApi: Type: AWS::Serverless::HttpApi Properties: Name: !Sub "${EnvironmentStackName}-device-management" StageName: "api" Auth: Authorizers: JwtAuthorizer: # 修正为标准JWT传递的请求头 IdentitySource: "$request.header.Authorization" JwtConfiguration: # 使用正确的Clerk客户端ID作为Audience Audience: - !Ref ClerkClientId Issuer: "https://issuer.clerk.accounts.dev" # 可选:设置默认授权器,避免每个路由重复配置 DefaultAuthorizer: JwtAuthorizer GetAllLocationsLambda: Type: AWS::Serverless::Function Properties: FunctionName: !Sub "${EnvironmentStackName}-lambda-locations-get-all" Handler: app.lambda_handler Runtime: python3.12 CodeUri: src/locations/get-all/ MemorySize: 128 Timeout: 10 Role: !GetAtt DeviceApiLambdaExecutionRole.Arn Environment: Variables: STACK_NAME: !Ref EnvironmentStackName Events: GetAllLocationsHttpApiEvent: Type: HttpApi Properties: PayloadFormatVersion: "2.0" Path: /locations Method: GET ApiId: !Ref DeviceManagementHttpApi # 若已设置DefaultAuthorizer,此处可省略Auth配置 # Auth: # Authorizer: JwtAuthorizer # 补充缺失的IAM角色定义(原模板中引用但未定义) DeviceApiLambdaExecutionRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: lambda.amazonaws.com Action: sts:AssumeRole ManagedPolicyArns: - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole
额外说明
- 新增
ClerkClientId参数,便于在不同环境(dev/prod)配置对应的Clerk客户端ID,提升模板灵活性。 - 补充了原模板中引用但未定义的
DeviceApiLambdaExecutionRole角色,避免部署时出现资源缺失错误。 - 可选配置
DefaultAuthorizer后,路由无需重复指定授权器,简化配置。
内容的提问来源于stack exchange,提问作者Eduard Grinberg
相关产品推荐
相关产品推荐

