使用Terraform部署AWS中国区全局资源遇STS凭证验证错误
解决AWS中国区Terraform部署CloudFront/WAF的STS凭证错误
问题根因
AWS中国区与全球区的服务endpoint完全隔离,默认情况下Terraform AWS Provider会调用全球区的STS(https://sts.amazonaws.com)验证凭证,但AWS中国区的凭证仅能在专属的中国区STS endpoint通过验证,因此出现InvalidClientTokenId错误。部署特定区域资源时,Provider会自动使用对应中国区的区域endpoint,所以能成功;但CloudFront、CloudFront关联的WAF属于全局服务,Provider默认走全球endpoint,导致验证失败。
解决方案
1. 修正Terraform AWS Provider配置
在provider "aws"块中明确指定中国区的region,并配置专属的服务endpoint:
provider "aws" { region = "cn-north-1" # 根据账号选择:北京区cn-north-1/宁夏区cn-northwest-1 endpoints { sts = "https://sts.cn-north-1.amazonaws.com.cn" # 对应region的STS endpoint cloudfront = "https://cloudfront.amazonaws.com.cn" # AWS中国区CloudFront专属endpoint wafv2 = "https://wafv2.cn-north-1.amazonaws.com.cn" # 若使用WAFv2,对应region的endpoint } # 凭证传入方式三选一: # 方式1:AWS配置文件profile(推荐) # profile = "aws-cn" # 方式2:环境变量(AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY) # 方式3:直接指定(不推荐生产环境) # access_key = "YOUR_CN_ACCESS_KEY" # secret_key = "YOUR_CN_SECRET_KEY" }
2. 验证AWS凭证与配置有效性
用AWS CLI测试中国区STS调用,确认凭证和endpoint正常:
# 若使用profile aws sts get-caller-identity --profile aws-cn # 若使用环境变量 export AWS_ACCESS_KEY_ID=YOUR_CN_ACCESS_KEY export AWS_SECRET_ACCESS_KEY=YOUR_CN_SECRET_KEY export AWS_REGION=cn-north-1 aws sts get-caller-identity --endpoint-url https://sts.cn-north-1.amazonaws.com.cn
返回账号ID、用户ARN等信息即表示凭证和endpoint配置正确。
3. 清理冲突配置
- 检查环境变量是否存在
AWS_REGION、AWS_STS_REGIONAL_ENDPOINTS等全局区相关配置,若有则临时取消或覆盖为中国区值。 - 确保
~/.aws/config和~/.aws/credentials中,对应profile的region和凭证为AWS中国区专属,无全局区配置干扰。
内容的提问来源于stack exchange,提问作者adminaf
相关产品推荐
相关产品推荐

