配置文件中`aws_global`的作用及全局端点URL配置方式咨询
aws_global Config Parameter in ~/.aws/config Hey, let's break down what the aws_global parameter does and show you exactly how to configure it with real examples—since the docs can be a bit vague on the practical side.
What aws_global Actually Does
The aws_global setting lets you force AWS SDKs/CLI to use a global endpoint for specific services that support both regional and global endpoints (like AWS STS and Amazon S3). Instead of using the region-specific endpoint tied to your profile's region value, the tooling will use the global URL you specify for those services.
Concrete Configuration Examples
Here are common use cases with working config snippets you can copy-paste:
Example 1: Global Endpoint for AWS STS
If you want all STS operations (like getting caller identity or assuming roles) to use the global STS endpoint instead of a regional one:
[profile sts-global] region = us-west-2 aws_global = sts=https://sts.amazonaws.com
When you run commands like aws sts get-caller-identity --profile sts-global, the CLI will hit https://sts.amazonaws.com instead of the regional sts.us-west-2.amazonaws.com.
Example 2: Global Endpoint for Amazon S3
For S3, you might use this if you prefer the global endpoint over region-specific ones (useful for certain cross-region operations):
[profile s3-global-access] region = eu-central-1 aws_global = s3=https://s3.amazonaws.com
Note: S3 has some unique endpoint behavior, so double-check that using the global endpoint aligns with your use case (e.g., it works for most object operations but some bucket-level actions might still require regional endpoints).
Example 3: Multiple Services in One Profile
You can specify multiple services in a single aws_global line, separated by commas:
[profile multi-global-services] region = ap-northeast-1 aws_global = sts=https://sts.amazonaws.com,s3=https://s3.amazonaws.com
This profile will use global endpoints for both STS and S3, while using regional endpoints for all other AWS services.
How the Parameter Works Under the Hood
When you set aws_global, the AWS CLI/SDKs will override their default endpoint resolution for the specified services. Normally, they build a regional endpoint using your profile's region value (e.g., sts.<region>.amazonaws.com), but with aws_global, they skip that step and use the exact URL you provide.
Just keep in mind: this only works for services that officially support global endpoints. AWS publishes which services qualify, but STS and S3 are the most common ones you'll use this for.
内容的提问来源于stack exchange,提问作者jingx

