如何为Lambda创建临时AWS凭证?遇ValidationError问题求助
问题:Lambda生成AWS Batch临时凭证时遇ValidationError错误
尝试通过Lambda脚本生成AWS Batch可使用的临时凭证,但在AWS控制台本地测试Lambda时,出现如下错误:
{ "statusCode": 500, "body": "{\"message\":\"Error retrieving temp credentials\",\"error\": {\"name\":\"ValidationError\",\"$fault\":\"client\",\"$metadata\": {\"httpStatusCode\":400,\"requestId\":\"6bf2751a-8bf8-4835-91a8-d5fd80dd5c6f\",\"attempts\":1,\"totalRetryDelay\":0},\"Type\":\"Sender\",\"Code\":\"ValidationError\",\"message\":\"1 validation error detected: Value null at 'roleArn' failed to satisfy constraint: Member must not be null\"}}" }
Lambda函数定义(CloudFormation)
GenerateCredentialsLambdaFunction: Type: AWS::Lambda::Function Properties: Description: > Lambda function to generate temp credentials FunctionName: !Sub - '${TheEnv}-${TheAppNameForResources}-${TheFunctionBaseName}-v1' - TheEnv: !Ref Environment TheAppNameForResources: !Ref AppNameForResources TheFunctionBaseName: !Ref FunctionBaseNameForLambdaEvent EphemeralStorage: Size: 10240 Code: ZipFile: | const { STS, AssumeRoleCommand } = require('@aws-sdk/client-sts'); exports.handler = async(event) => { const roleToAssumeArn = event.roleArn; const stsClient = new STS(); try { //Assume the specified role to get temp credentials const assumedRoleResponse = await stsClient.send(new AssumeRoleCommand( { RoleArn: roleToAssumeArn, RoleSessionName: 'TemporarySession' })); //Extract temp credentials from AssumeRole Response const temporaryCredentials = assumedRoleResponse.Credentials; // Lambda function logic here return { statusCode: 200, body: JSON.stringify(temporaryCredentials) }; } catch (error) { return { statusCode: 500, body: JSON.stringify({message: "Error retrieving temp credentials", error}) }; } };
Lambda执行角色定义(CloudFormation)
LambdaExecutionRole: Type: AWS::IAM::Role Properties: RoleName: !Sub - "${TheAppNameForResources}-${TheEnvName}-lambda-execution-role" - TheAppNameForResources: !Ref AppNameForResources TheEnvName: !Ref Environment AssumeRolePolicyDocument: Statement: - Effect: Allow Principal: Service: lambda.amazonaws.com Action: ['sts:AssumeRole'] Policies: - PolicyName: !Sub - "${TheAppNameForResources}-${TheEnvName}-lambda-execution-policy" - TheAppNameForResources: !Ref AppNameForResources TheEnvName: !Ref Environment PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - 'batch:SubmitJob' - 'batch:CancelJob' - 'batch:DescribeJobs' Resource: "*"
临时凭证生成角色定义(CloudFormation)
GenerateTempCredentialsRole: Type: AWS::IAM::Role Properties: RoleName: !Sub - "${TheAppNameForResources}-${TheEnvName}-ecs-credentials-role" - TheAppNameForResources: !Ref AppNameForResources TheEnvName: !Ref Environment AssumeRolePolicyDocument: Statement: - Effect: Allow Principal: Service: lambda.amazonaws.com Action: ['sts:AssumeRole'] Policies: - PolicyName: !Sub - "${TheAppNameForResources}-${TheEnvName}-ecs-credentials-policy" - TheAppNameForResources: !Ref AppNameForResources TheEnvName: !Ref Environment PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: ['sts:AssumeRole'] Resource: "*" - PolicyName: !Sub - "${TheAppNameForResources}-${TheEnvName}-ec2-permissions-policy" - TheAppNameForResources: !Ref AppNameForResources TheEnvName: !Ref Environment PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: ['ec2:CreateNetworkInterface', 'ec2:DescribeNetworkInterfaces', 'ec2:AttachNetworkInterface', 'ec2:DescribeInstances', 'ec2:DeleteNetworkInterface', 'logs:CreateLogGroup', 'logs:CreateLogStream', 'logs:PutLogEvents'] Resource: "*"
Lambda运行时已指定LambdaExecutionRole的ARN,我知道这是权限相关问题,但作为AWS新手难以调试,希望能得到帮助。
内容的提问来源于stack exchange,提问作者Ram
相关产品推荐
相关产品推荐

