You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Lambda创建临时AWS凭证?遇ValidationError问题求助

问题:Lambda生成AWS Batch临时凭证时遇ValidationError错误

尝试通过Lambda脚本生成AWS Batch可使用的临时凭证,但在AWS控制台本地测试Lambda时,出现如下错误:

{
  "statusCode": 500,
  "body": "{\"message\":\"Error retrieving temp credentials\",\"error\": {\"name\":\"ValidationError\",\"$fault\":\"client\",\"$metadata\": {\"httpStatusCode\":400,\"requestId\":\"6bf2751a-8bf8-4835-91a8-d5fd80dd5c6f\",\"attempts\":1,\"totalRetryDelay\":0},\"Type\":\"Sender\",\"Code\":\"ValidationError\",\"message\":\"1 validation error detected: Value null at 'roleArn' failed to satisfy constraint: Member must not be null\"}}"
}

Lambda函数定义(CloudFormation)

GenerateCredentialsLambdaFunction:
  Type: AWS::Lambda::Function
  Properties:
    Description: >
      Lambda function to generate temp credentials
    FunctionName:
      !Sub
      - '${TheEnv}-${TheAppNameForResources}-${TheFunctionBaseName}-v1'
      - TheEnv: !Ref Environment
        TheAppNameForResources: !Ref AppNameForResources
        TheFunctionBaseName: !Ref FunctionBaseNameForLambdaEvent
    EphemeralStorage:
      Size: 10240
    Code:
      ZipFile: |
        const { STS, AssumeRoleCommand } = require('@aws-sdk/client-sts');
        exports.handler = async(event) => {
        const roleToAssumeArn = event.roleArn;
        const stsClient = new STS();
        try {
          //Assume the specified role to get temp credentials
          const assumedRoleResponse = await stsClient.send(new AssumeRoleCommand(
            {
              RoleArn: roleToAssumeArn,
              RoleSessionName: 'TemporarySession'
            }));
          //Extract temp credentials from AssumeRole Response
          const temporaryCredentials = assumedRoleResponse.Credentials;
      
          // Lambda function logic here
          return { 
            statusCode: 200, 
            body: JSON.stringify(temporaryCredentials)
          };
        } catch (error) {
          return {
            statusCode: 500,
            body: JSON.stringify({message: "Error retrieving temp credentials", error})
          };
        }
      };

Lambda执行角色定义(CloudFormation)

LambdaExecutionRole:
  Type: AWS::IAM::Role
  Properties:
    RoleName:
      !Sub
      - "${TheAppNameForResources}-${TheEnvName}-lambda-execution-role"
      - TheAppNameForResources: !Ref AppNameForResources
        TheEnvName: !Ref Environment
    AssumeRolePolicyDocument:
      Statement:
        - Effect: Allow
          Principal:
            Service: lambda.amazonaws.com
          Action: ['sts:AssumeRole']
    Policies:
      - PolicyName:
          !Sub
          - "${TheAppNameForResources}-${TheEnvName}-lambda-execution-policy"
          - TheAppNameForResources: !Ref AppNameForResources
            TheEnvName: !Ref Environment
        PolicyDocument:
          Version: "2012-10-17"
          Statement:
            - Effect: Allow
              Action:
                - 'batch:SubmitJob'
                - 'batch:CancelJob'
                - 'batch:DescribeJobs'
              Resource: "*"

临时凭证生成角色定义(CloudFormation)

GenerateTempCredentialsRole:
  Type: AWS::IAM::Role
  Properties:
    RoleName:
      !Sub
      - "${TheAppNameForResources}-${TheEnvName}-ecs-credentials-role"
      - TheAppNameForResources: !Ref AppNameForResources
        TheEnvName: !Ref Environment
    AssumeRolePolicyDocument:
      Statement:
        - Effect: Allow
          Principal:
            Service: lambda.amazonaws.com
            Action: ['sts:AssumeRole']
    Policies:
      - PolicyName:
          !Sub
          - "${TheAppNameForResources}-${TheEnvName}-ecs-credentials-policy"
          - TheAppNameForResources: !Ref AppNameForResources
            TheEnvName: !Ref Environment
        PolicyDocument:
          Version: "2012-10-17"
          Statement:
            - Effect: Allow
              Action: ['sts:AssumeRole']
              Resource: "*"
      - PolicyName:
          !Sub
          - "${TheAppNameForResources}-${TheEnvName}-ec2-permissions-policy"
          - TheAppNameForResources: !Ref AppNameForResources
            TheEnvName: !Ref Environment
        PolicyDocument:
          Version: "2012-10-17"
          Statement:
            - Effect: Allow
              Action: ['ec2:CreateNetworkInterface', 'ec2:DescribeNetworkInterfaces', 'ec2:AttachNetworkInterface',
            'ec2:DescribeInstances', 'ec2:DeleteNetworkInterface', 'logs:CreateLogGroup', 'logs:CreateLogStream',
            'logs:PutLogEvents']
              Resource: "*"

Lambda运行时已指定LambdaExecutionRole的ARN,我知道这是权限相关问题,但作为AWS新手难以调试,希望能得到帮助。


内容的提问来源于stack exchange,提问作者Ram

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 22:57:46