You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform部署AWS中国区全局资源遇STS凭证验证错误

解决AWS中国区Terraform部署CloudFront/WAF的STS凭证错误

问题根因

AWS中国区与全球区的服务endpoint完全隔离,默认情况下Terraform AWS Provider会调用全球区的STS(https://sts.amazonaws.com)验证凭证,但AWS中国区的凭证仅能在专属的中国区STS endpoint通过验证,因此出现InvalidClientTokenId错误。部署特定区域资源时,Provider会自动使用对应中国区的区域endpoint,所以能成功;但CloudFront、CloudFront关联的WAF属于全局服务,Provider默认走全球endpoint,导致验证失败。

解决方案

1. 修正Terraform AWS Provider配置

在provider "aws"块中明确指定中国区的region,并配置专属的服务endpoint:

provider "aws" {
  region = "cn-north-1"  # 根据账号选择:北京区cn-north-1/宁夏区cn-northwest-1

  endpoints {
    sts        = "https://sts.cn-north-1.amazonaws.com.cn"  # 对应region的STS endpoint
    cloudfront = "https://cloudfront.amazonaws.com.cn"      # AWS中国区CloudFront专属endpoint
    wafv2      = "https://wafv2.cn-north-1.amazonaws.com.cn" # 若使用WAFv2,对应region的endpoint
  }

  # 凭证传入方式三选一:
  # 方式1:AWS配置文件profile(推荐)
  # profile = "aws-cn"
  # 方式2:环境变量(AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY)
  # 方式3:直接指定(不推荐生产环境)
  # access_key = "YOUR_CN_ACCESS_KEY"
  # secret_key = "YOUR_CN_SECRET_KEY"
}

2. 验证AWS凭证与配置有效性

用AWS CLI测试中国区STS调用,确认凭证和endpoint正常:

# 若使用profile
aws sts get-caller-identity --profile aws-cn

# 若使用环境变量
export AWS_ACCESS_KEY_ID=YOUR_CN_ACCESS_KEY
export AWS_SECRET_ACCESS_KEY=YOUR_CN_SECRET_KEY
export AWS_REGION=cn-north-1
aws sts get-caller-identity --endpoint-url https://sts.cn-north-1.amazonaws.com.cn

返回账号ID、用户ARN等信息即表示凭证和endpoint配置正确。

3. 清理冲突配置

  • 检查环境变量是否存在AWS_REGION、AWS_STS_REGIONAL_ENDPOINTS等全局区相关配置,若有则临时取消或覆盖为中国区值。
  • 确保~/.aws/config和~/.aws/credentials中,对应profile的region和凭证为AWS中国区专属,无全局区配置干扰。

内容的提问来源于stack exchange,提问作者adminaf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 09:52:38