为ECS Job Definition添加Secret值时遇类型转换错误
解决AWS CDK中ECS Secret与Batch Secret的类型转换问题
你尝试为ECS Job Definition添加Secret值,编写的代码如下:
secret_id = f"mysecretid" secret = secretsmanager.Secret.from_secret_name_v2( self, secret_id, secret_name=secret_id, ) # Mongo DB URI mongodb_uri = ecs.Secret.from_secrets_manager(secret, "MONGODB_URI") job_definition = batch.EcsJobDefinition(self, f"{stage}{NAME}JobDefinition", container=batch.EcsEc2ContainerDefinition(self, "Container", image=image, memory=Size.mebibytes(4096), cpu=2, secrets={"MONGO_DB_URI": mongodb_uri}, command=["npm run crawl"], ) )
运行时触发如下错误:
RuntimeError: Passed to parameter props of new aws-cdk-lib.aws_batch.EcsEc2ContainerDefinition: Unable to deserialize value as aws-cdk-lib.aws_batch.EcsEc2ContainerDefinitionProps ├── 🛑 Failing value is an object │ { '$jsii.struct': [Object] } ╰── 🔍 Failure reason(s): ╰─ Key 'secrets': Unable to deserialize value as map<aws-cdk-lib.aws_batch.Secret> | undefined ├── 🛑 Failing value is an object │ { '$jsii.map': [Object] } ╰── 🔍 Failure reason(s): ╰─ Key 'MONGO_DB_URI': Unable to deserialize value as aws-cdk-lib.aws_batch.Secret ├── 🛑 Failing value is an object │ { '$jsii.byref': 'aws-cdk-lib.aws_ecs.Secret@10003' } ╰── 🔍 Failure reason(s): ╰─ Object of type 'aws-cdk-lib.aws_ecs.Secret' is not convertible to aws-cdk-lib.aws_batch.Secret
问题原因与解决方法
- 核心问题:AWS CDK里
aws_ecs.Secret和aws_batch.Secret是两个独立的类型,不能直接混用。Batch容器定义必须使用Batch专属的Secret类型。 - 修复方式:把生成Secret的代码从
ecs.Secret.from_secrets_manager换成batch.Secret.from_secrets_manager,保证类型匹配。
修改后的完整代码
secret_id = f"mysecretid" secret = secretsmanager.Secret.from_secret_name_v2( self, secret_id, secret_name=secret_id, ) # 改用Batch的Secret类型 mongodb_uri = batch.Secret.from_secrets_manager(secret, "MONGODB_URI") job_definition = batch.EcsJobDefinition(self, f"{stage}{NAME}JobDefinition", container=batch.EcsEc2ContainerDefinition(self, "Container", image=image, memory=Size.mebibytes(4096), cpu=2, secrets={"MONGO_DB_URI": mongodb_uri}, command=["npm run crawl"], ) )
补充说明:
- 两个模块的
from_secrets_manager方法参数完全一致,只是所属模块不同,替换后就能解决类型不兼容的问题。 - 确保代码中已经导入了
aws_batch.Secret类(如果之前没导入的话)。
内容的提问来源于stack exchange,提问作者spitfiredd
相关产品推荐
相关产品推荐

