You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CDK Diff报错‘需执行AWS调用但未配置凭证’,角色配置正常仍异常

问题:CDK Diff 凭证配置异常(1Password管理凭证+AWS角色切换)

问题背景

尝试通过1Password管理的凭证执行npx cdk diff部署CDK堆栈,需切换至admin@ontology-dev角色完成操作。AWS控制台可正常通过该角色访问资源,但CDK始终抛出凭证未配置错误。

环境配置

  • 凭证由1Password管理:默认AWS Profile通过credential_process调用自定义1password.sh脚本获取凭证。

配置详情

~/.aws/config

[default]
region = eu-west-1
duration_seconds = 10800
mfa_serial = arn:aws:iam::<my-iam-account-id>:mfa/toseef.ahmed
output = json

[profile admin@dev-profile]
role_arn = arn:aws:iam::<dev-account-id>:role/DevAdmin-CAM
source_profile = default
region = eu-west-1
duration_seconds = 10800

~/.aws/credentials

[default]
credential_process = bash -c '$HOME/.aws/1password.sh'

1password.sh 脚本

#!/usr/bin/env bash

# Define 1Password parameters
ACCOUNT="myAccount"
VAULT="myValut"
ACCESS_ITEM="AWS-Access-Key"

# Retrieve access key, secret key, and OTP from 1Password
ACCESS_KEY=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/Access Key ID")
SECRET=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/Secret Access Key") 
OTP=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/one-time password?attribute=otp")

export ACCESS_KEY
export SECRET

测试验证

  • 执行aws sts get-caller-identity --profile admin@<dev-profile>可正常返回身份信息
  • 执行aws s3 ls s3://<my-bucket name>/可正常列出桶内文件

CDK 执行错误

运行npx cdk diff -c account=dev -c environment=development --verbose时,报错:

Need to perform AWS calls for account <target-account-id>, but no credentials have been configured

Verbose 输出片段:

[17:08:38] Resolving default credentials
Could not assume arn:aws:iam::<account-id>:role/cdk-hnb659fds-lookup-role-<dev-account-id>-eu-west-1, proceeding anyway.
[19:55:48] Reading cached notices from /Users/toseef.ahmed/.cdk/cache/notices.json
Need to perform AWS calls for account <dev-account-id>, but no credentials have been configured

解决方案

1. 修复1Password脚本输出格式

AWS的credential_process要求脚本必须输出标准JSON格式,当前脚本仅导出环境变量,不符合要求。修改1password.sh如下:

#!/usr/bin/env bash

ACCOUNT="myAccount"
VAULT="myValut"
ACCESS_ITEM="AWS-Access-Key"

ACCESS_KEY=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/Access Key ID")
SECRET=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/Secret Access Key")
OTP=$(op read --account $ACCOUNT "op://$VAULT/$ACCESS_ITEM/one-time password?attribute=otp")

# 输出AWS要求的JSON格式
cat <<EOF
{
  "Version": 1,
  "AccessKeyId": "$ACCESS_KEY",
  "SecretAccessKey": "$SECRET",
  "SessionToken": "",
  "Expiration": "$(date -u +"%Y-%m-%dT%H:%M:%SZ")"
}
EOF

注:若使用临时凭证,需补充SessionToken和正确的Expiration时间;长期密钥则SessionToken留空即可。

2. 指定CDK使用目标AWS Profile

CDK默认使用default Profile,需明确指定切换到admin@dev-profile:

  • 方式一:命令行直接指定参数
    npx cdk diff -c account=dev -c environment=development --profile admin@dev-profile --verbose
    
  • 方式二:设置环境变量
    export AWS_PROFILE=admin@dev-profile
    npx cdk diff -c account=dev -c environment=development --verbose
    

3. 检查CDK Lookup角色权限

错误日志显示无法假设cdk-hnb659fds-lookup-role-<dev-account-id>-eu-west-1,需确保DevAdmin-CAM角色拥有AssumeRole权限,允许切换至该CDK自动创建的Lookup角色;或提前手动创建该角色并配置必要权限。

4. 验证凭证流程

修改脚本后,先验证AWS CLI能否正常读取凭证:

aws sts get-caller-identity --profile default

确认返回正确身份后,再测试角色切换:

aws sts get-caller-identity --profile admin@dev-profile

全部验证通过后再运行CDK命令。

内容的提问来源于stack exchange,提问作者Toseef_Ahmed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 14:52:32