CDK Diff报错‘需执行AWS调用但未配置凭证’,角色配置正常仍异常
问题:CDK Diff 凭证配置异常(1Password管理凭证+AWS角色切换)
问题背景
尝试通过1Password管理的凭证执行npx cdk diff部署CDK堆栈,需切换至admin@ontology-dev角色完成操作。AWS控制台可正常通过该角色访问资源,但CDK始终抛出凭证未配置错误。
环境配置
- 凭证由1Password管理:默认AWS Profile通过
credential_process调用自定义1password.sh脚本获取凭证。
配置详情
~/.aws/config
[default] region = eu-west-1 duration_seconds = 10800 mfa_serial = arn:aws:iam::<my-iam-account-id>:mfa/toseef.ahmed output = json [profile admin@dev-profile] role_arn = arn:aws:iam::<dev-account-id>:role/DevAdmin-CAM source_profile = default region = eu-west-1 duration_seconds = 10800
~/.aws/credentials
[default] credential_process = bash -c '$HOME/.aws/1password.sh'
1password.sh 脚本
#!/usr/bin/env bash # Define 1Password parameters ACCOUNT="myAccount" VAULT="myValut" ACCESS_ITEM="AWS-Access-Key" # Retrieve access key, secret key, and OTP from 1Password ACCESS_KEY=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/Access Key ID") SECRET=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/Secret Access Key") OTP=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/one-time password?attribute=otp") export ACCESS_KEY export SECRET
测试验证
- 执行
aws sts get-caller-identity --profile admin@<dev-profile>可正常返回身份信息 - 执行
aws s3 ls s3://<my-bucket name>/可正常列出桶内文件
CDK 执行错误
运行npx cdk diff -c account=dev -c environment=development --verbose时,报错:
Need to perform AWS calls for account <target-account-id>, but no credentials have been configured
Verbose 输出片段:
[17:08:38] Resolving default credentials Could not assume arn:aws:iam::<account-id>:role/cdk-hnb659fds-lookup-role-<dev-account-id>-eu-west-1, proceeding anyway. [19:55:48] Reading cached notices from /Users/toseef.ahmed/.cdk/cache/notices.json Need to perform AWS calls for account <dev-account-id>, but no credentials have been configured
解决方案
1. 修复1Password脚本输出格式
AWS的credential_process要求脚本必须输出标准JSON格式,当前脚本仅导出环境变量,不符合要求。修改1password.sh如下:
#!/usr/bin/env bash ACCOUNT="myAccount" VAULT="myValut" ACCESS_ITEM="AWS-Access-Key" ACCESS_KEY=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/Access Key ID") SECRET=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/Secret Access Key") OTP=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/one-time password?attribute=otp") # 输出AWS要求的JSON格式 cat <<EOF { "Version": 1, "AccessKeyId": "$ACCESS_KEY", "SecretAccessKey": "$SECRET", "SessionToken": "", "Expiration": "$(date -u +"%Y-%m-%dT%H:%M:%SZ")" } EOF
注:若使用临时凭证,需补充
SessionToken和正确的Expiration时间;长期密钥则SessionToken留空即可。
2. 指定CDK使用目标AWS Profile
CDK默认使用default Profile,需明确指定切换到admin@dev-profile:
- 方式一:命令行直接指定参数
npx cdk diff -c account=dev -c environment=development --profile admin@dev-profile --verbose - 方式二:设置环境变量
export AWS_PROFILE=admin@dev-profile npx cdk diff -c account=dev -c environment=development --verbose
3. 检查CDK Lookup角色权限
错误日志显示无法假设cdk-hnb659fds-lookup-role-<dev-account-id>-eu-west-1,需确保DevAdmin-CAM角色拥有AssumeRole权限,允许切换至该CDK自动创建的Lookup角色;或提前手动创建该角色并配置必要权限。
4. 验证凭证流程
修改脚本后,先验证AWS CLI能否正常读取凭证:
aws sts get-caller-identity --profile default
确认返回正确身份后,再测试角色切换:
aws sts get-caller-identity --profile admin@dev-profile
全部验证通过后再运行CDK命令。
内容的提问来源于stack exchange,提问作者Toseef_Ahmed
相关产品推荐
相关产品推荐

