You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CLI无法找到已存在的credentials.sh文件问题求助

问题:AWS CLI credential_process 提示找不到已存在的脚本文件

问题背景

在GCP Cloud Run环境中配置AWS CLI,采用AWS STS assume-role功能做身份验证,通过Docker构建镜像时遇到异常:明明credentials.sh文件存在且权限正确,但执行aws configure list时却提示文件找不到。

相关配置文件

Dockerfile

FROM node:20-alpine

# Install necessary packages and dependencies
USER root
RUN apk update && \
    apk add --no-cache jq curl unzip && \
    apk add --no-cache aws-cli

RUN aws --version

RUN pwd
COPY package*.json ./
COPY credentials.sh /opt/bin/credentials.sh

# Ensure the script has the correct line endings and is executable
RUN dos2unix /opt/bin/credentials.sh && chmod 755 /opt/bin/credentials.sh

RUN mkdir -p ~/.aws
RUN mkdir -p /root/.aws/
COPY config ~/.aws/config
COPY config /root/.aws/config

RUN ls -la /opt/bin
RUN cat /opt/bin/credentials.sh

# Run the script directly to ensure it executes
RUN /opt/bin/credentials.sh

RUN aws configure list

ENTRYPOINT ["node", "index.js"]

~/.aws/config

[default]
credential_process = /opt/bin/credentials.sh

报错信息

[23/23] RUN aws configure list:
0.730 
0.730 [Errno 2] No such file or directory: '/opt/bin/credentials.sh'

文件存在验证

构建过程中ls -la /opt/bin输出确认文件存在且权限正确:

#25 [19/23] RUN ls -la /opt/bin
#25 0.188 total 20
#25 0.189 drwxr-xr-x    1 root     root          4096 May 31 14:25 .
#25 0.189 drwxr-xr-x    1 root     root          4096 May 31 14:25 ..
#25 0.189 -rwxr-xr-x    1 root     root           714 May 31 14:24 credentials.sh

原因分析

核心问题在于Alpine Linux默认未安装bash,如果credentials.sh脚本的开头使用了#!/bin/bash作为shebang(解释器指定),当AWS CLI调用该脚本时,系统找不到/bin/bash,会返回“文件不存在”的错误(这是Linux系统的常见误导性报错,实际是找不到脚本依赖的解释器,而非脚本本身)。

另外,直接执行/opt/bin/credentials.sh时能成功,是因为当前shell(Docker构建时的root shell是ash)会尝试用自身解释器去执行脚本,忽略了shebang的错误。

解决方法

方案1:修改脚本的shebang为兼容Alpine的解释器

编辑credentials.sh,将开头的#!/bin/bash改为#!/bin/sh(Alpine自带的ash完全兼容sh语法):

#!/bin/sh
# 剩余脚本内容...

方案2:在Dockerfile中安装bash

在apk add的命令中添加bash包,确保系统存在/bin/bash:
修改Dockerfile中的安装命令:

RUN apk update && \
    apk add --no-cache jq curl unzip bash && \
    apk add --no-cache aws-cli

验证修改

重新构建镜像,aws configure list将能正常调用credentials.sh完成凭证处理,不再报错。

内容的提问来源于stack exchange,提问作者AnandShiva

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 03:43:23