如何解决本地连接AWS Secrets Manager时出现的超时错误?
Fixing AWS Secrets Manager Timeout Error (ETIMEDOUT/ENETUNREACH)
1. Verify Network Connectivity
Your error confirms the SDK can’t establish a connection to secretsmanager.us-east-1.amazonaws.com. First, check if your local machine can reach this endpoint:
- Run this command in your terminal:
curl -v https://secretsmanager.us-east-1.amazonaws.com
If this times out or fails, you have a network issue:
- Disable any active VPN or firewall temporarily to test connectivity.
- Contact your network admin if you’re behind a corporate firewall—ensure outbound traffic to AWS Secrets Manager in
us-east-1is allowed.
2. Configure Proxy Settings (if applicable)
If you’re working behind a proxy, add proxy configuration to your AWS SDK setup:
const AWS = require('aws-sdk'); const HttpsProxyAgent = require('https-proxy-agent'); AWS.config.update({ accessKeyId: process.env.AWS_ACCESSKEY, secretAccessKey: process.env.AWS_SECRETKEY, region: 'us-east-1', httpOptions: { agent: new HttpsProxyAgent('http://your-proxy-address:port') } });
Install the required package first:
npm install https-proxy-agent
3. Validate Credentials and Environment Variables
- Ensure
AWS_ACCESSKEYandAWS_SECRETKEYare correctly set in your environment (no typos, no empty values). Note that standard AWS environment variables areAWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEY—adjust your code if you’re using these:accessKeyId: process.env.AWS_ACCESS_KEY_ID, secretAccessKey: process.env.AWS_SECRET_ACCESS_KEY, - Confirm the IAM user linked to these credentials has the
secretsmanager:GetSecretValuepermission for your target secret.
4. Check Region and Endpoint
- Double-check that your secret is stored in
us-east-1. If it’s in another region, update theregionfield in your config to match. - For testing, explicitly set the endpoint to rule out DNS issues:
const SM = new AWS.SecretsManager({ endpoint: 'https://secretsmanager.us-east-1.amazonaws.com' });
5. Update AWS SDK Version
Outdated SDK versions may have connectivity bugs. Update to the latest version:
npm update aws-sdk
Bonus: Simplify Secret Parsing
Your current regex-based parsing is error-prone. Replace it with direct JSON parsing:
const secretData = await SM.getSecretValue({ SecretId: process.env.wallet_private_key_secret_name }).promise(); const secretObj = JSON.parse(secretData.SecretString); return secretObj[process.env.secret_key];
This is more reliable and handles standard secret formats correctly.
内容的提问来源于stack exchange,提问作者Blockchain Kid
相关产品推荐
相关产品推荐

