You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions执行AWS CDK部署时出现凭证未配置错误

问题

之前运行正常的GitHub Action脚本突然执行失败,报错信息如下:

This API will be removed in the next major release.
Warning:  aws-cdk-lib.aws_stepfunctions.StateMachineProps#definition is deprecated.
  use definitionBody: DefinitionBody.fromChainable()
  This API will be removed in the next major release.
 ⏳  Bootstrapping environment aws://***/us-east-1...
 ❌  Environment aws://***/us-east-1 failed bootstrapping: Error: Need to perform AWS calls for account ***, but no credentials have been configured
    at SdkProvider.forEnvironment (/home/runner/work/tester/tester/node_modules/aws-cdk/lib/index.js:593:5639101)
    at async _BootstrapStack.lookup (/home/runner/work/tester/tester/node_modules/aws-cdk/lib/index.js:592:8579)
    at async Bootstrapper.modernBootstrap (/home/runner/work/tester/tester/node_modules/aws-cdk/lib/index.js:593:1084)
    at async /home/runner/work/tester/tester/node_modules/aws-cdk/lib/index.js:650:1671
Need to perform AWS calls for account ***, but no credentials have been configured
Error: Process completed with exit code 1.

执行的YAML脚本:

name: CI/CD

on:
  push:
    branches:
      - main

jobs:
  deploy:
    runs-on: ubuntu-latest

    steps:
      - name: Checkout code
        uses: actions/checkout@v3 # Updated to the latest version

      - name: Set up Node.js
        uses: actions/setup-node@v3 # Updated to the latest version
        with:
          node-version: "20"

      - name: Install dependencies
        run: |
          npm install -g yarn
          yarn

      - name: Deploy to AWS (prod)
        run: |
          cd infrastructure
          yarn
          npx cdk bootstrap --all -c env=prod aws://$PROD_ACCOUNT_ID/us-east-1
          npx cdk deploy -c env=prod --require-approval never --all
        env:
          AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
          AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
          AWS_DEFAULT_REGION: us-east-1
          PROD_ACCOUNT_ID: ${{ secrets.PROD_ACCOUNT_ID }}

已确认:GitHub Secrets近4个月未变更,AWS凭证处于活跃可用状态且未修改。

解决建议
  • 确认环境变量传递有效性:在执行CDK命令前添加环境变量打印(避免泄露敏感信息),验证凭证是否正确传递到子进程:

    cd infrastructure
    yarn
    echo "AWS_ACCESS_KEY_ID exists: $([ -n "$AWS_ACCESS_KEY_ID" ] && echo 'Yes' || echo 'No')"
    echo "PROD_ACCOUNT_ID: $PROD_ACCOUNT_ID"
    npx cdk bootstrap --all -c env=prod aws://$PROD_ACCOUNT_ID/us-east-1
    npx cdk deploy -c env=prod --require-approval never --all
    
  • 调整CDK bootstrap参数:移除--all参数(已指定具体环境,无需引导全部环境),避免逻辑冲突:

    npx cdk bootstrap -c env=prod aws://$PROD_ACCOUNT_ID/us-east-1
    
  • 使用AWS官方凭证配置Action:替换直接设置环境变量的方式,用官方Action确保凭证链正确配置:

    - name: Configure AWS credentials
      uses: aws-actions/configure-aws-credentials@v4
      with:
        aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
        aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
        aws-region: us-east-1
    
    - name: Deploy to AWS (prod)
      run: |
        cd infrastructure
        yarn
        npx cdk bootstrap -c env=prod aws://$PROD_ACCOUNT_ID/us-east-1
        npx cdk deploy -c env=prod --require-approval never --all
      env:
        PROD_ACCOUNT_ID: ${{ secrets.PROD_ACCOUNT_ID }}
    
  • 使用本地CDK版本执行命令:避免全局npx调用与本地依赖版本不一致的问题,改用本地安装的CDK:

    cd infrastructure
    yarn install
    yarn cdk bootstrap -c env=prod aws://$PROD_ACCOUNT_ID/us-east-1
    yarn cdk deploy -c env=prod --require-approval never --all
    
  • 锁定CDK版本:在infrastructure/package.json中指定固定的CDK版本,避免自动升级带来的兼容性问题:

    "devDependencies": {
      "aws-cdk": "2.100.0"
    }
    

内容的提问来源于stack exchange,提问作者Haroldo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 06:05:13