指定default profile执行AWS STS命令正常,无profile时令牌过期
执行aws --profile default sts get-caller-identity可正常返回身份信息,但直接执行aws sts get-caller-identity时触发错误:
An error occurred (ExpiredToken) when calling the GetCallerIdentity operation: The security token included in the request is expired
已确认完成AWS SSO配置与机器授权,且用户/系统环境中无AWS_前缀的环境变量。
以下是排查和解决步骤:
检查默认profile配置
打开~/.aws/config文件,确认[default]段已正确关联AWS SSO会话,配置示例如下:[default] sso_start_url = https://your-sso-url.awsapps.com/start sso_region = us-east-1 sso_account_id = 123456789012 sso_role_name = YourRoleName若配置无误,执行
aws sso login --profile default重新刷新会话令牌,确保令牌处于有效期内。清理旧凭证文件
查看~/.aws/credentials文件,若其中存在[default]段(包含aws_access_key_id和aws_secret_access_key),这些过期的静态凭证会和SSO配置冲突——不带profile参数时,AWS CLI会优先读取该文件中的默认凭证。直接删除该[default]条目即可。验证默认profile优先级
执行aws configure list查看当前默认使用的凭证信息,确认输出的profile为default且令牌未过期。若显示的不是配置的SSO profile,可临时设置环境变量export AWS_PROFILE=default强制使用该profile,或调整config文件确保default为正确的SSO配置。
内容的提问来源于stack exchange,提问作者raah

