You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用_cat/indices?v访问Amazon OpenSearch Serverless返回403禁止访问

排查Amazon OpenSearch Serverless调用_cat/indices接口返回403 Forbidden的原因

问题重现

使用Curl 8.3.0执行以下请求获取Amazon OpenSearch Serverless集群索引信息:

curl -XGET https://my_domain.us-east-1.aoss.amazonaws.com/_cat/indices?v \
  --aws-sigv4 aws:amz:us-east-1:aoss \
  --user $AWS_ACCESS_KEY:$AWS_SECRET_KEY \
  --header "Content-Type: application/json; charset=utf-8" \
  --header "x-amz-security-token:${AWS_SESSION_TOKEN}"

收到403 Forbidden错误:

{"status":403,"request-id":"a6603a35-6757-9a13-86c9-xxx","error":{"reason":"403 Forbidden","type":"Forbidden"}}

curl -v输出详情:

Note: Unnecessary use of -X or --request, GET is already inferred.
*   Trying x.x.x.x:443...
* Connected to my_domain.us-east-1.aoss.amazonaws.com (x.x.x.x) port 443
* ALPN: curl offers http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
*  CAfile: /etc/ssl/certs/ca-certificates.crt
*  CApath: none
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS handshake, Server key exchange (12):
* TLSv1.2 (IN), TLS handshake, Server finished (14):
* TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
* TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.2 (OUT), TLS handshake, Finished (20):
* TLSv1.2 (IN), TLS handshake, Finished (20):
* SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256
* ALPN: server did not agree on a protocol. Uses default.
* Server certificate:
*  subject: CN=*.us-east-1.aoss.amazonaws.com
*  start date: Dec 18 00:00:00 2022 GMT
*  expire date: Jan 16 23:59:59 2024 GMT
*  subjectAltName: host "my_domain.us-east-1.aoss.amazonaws.com" matched cert's "*.us-east-1.aoss.amazonaws.com"
*  issuer: C=US; O=Amazon; CN=Amazon RSA 2048 M02
*  SSL certificate verify ok.
* using HTTP/1.x
* Server auth using AWS_SIGV4 with user ''
> GET /_cat/indices?v HTTP/1.1
> Host: my_domain.us-east-1.aoss.amazonaws.com
> Authorization: AWS4-HMAC-SHA256 Credential=/20230927/us-east-1/aoss/aws4_request, SignedHeaders=content-type;host;x-amz-date;x-amz-security-token, Signature=ab....
> X-Amz-Date: 20230927T065937Z
> User-Agent: curl/8.3.0
> Accept: */*
> Content-Type: application/json; charset=utf-8
> x-amz-security-token:abc
> 
< HTTP/1.1 403 Forbidden
< x-request-id: 642feace-d1d2-9705-a97b-xxx
< x-aoss-response-hint: X01:gw-helper-deny
< content-type: application/json
< date: Wed, 27 Sep 2023 06:59:37 GMT
< content-length: 121
< server: aoss-amazon
< 
{"status":403,"request-id":"642feace-d1d2-9705-a97b-xxx","error":{"reason":"403 Forbidden","type":"Forbidden"}}
* Connection #0 to host my_domain.us-east-1.aoss.amazonaws.com left intact

当前配置的数据访问策略:

{
  "Rules": [
    {
      "ResourceType": "index",
      "Resource": [
        "index/my_collection/*"
      ],
      "Permission": [
        "aoss:CreateIndex",
        "aoss:DeleteIndex",
        "aoss:DescribeIndex",
        "aoss:ReadDocument",
        "aoss:UpdateIndex",
        "aoss:WriteDocument"
      ]
    },
    {
      "ResourceType": "collection",
      "Resource": [
        "collection/my_collection"
      ],
      "Permission": [
        "aoss:CreateCollectionItems",
        "aoss:DeleteCollectionItems",
        "aoss:DescribeCollectionItems",
        "aoss:UpdateCollectionItems"
      ]
    }
  ],
  "Principal": [
    "my_role_arn"
  ]
}

可能的原因及修复方案

  • 缺少aoss:ListIndices权限:_cat/indices接口属于索引列表查询操作,需要aoss:ListIndices权限,当前数据访问策略的index权限组中未包含该权限。需在index资源的Permission数组中添加"aoss:ListIndices"。
  • 凭证加载异常:从curl verbose输出可见Server auth using AWS_SIGV4 with user '',且Authorization头的Credential字段为空(Credential=/20230927/...),说明$AWS_ACCESS_KEY环境变量未正确注入。需检查环境变量是否已正确设置,或直接替换为实际的Access Key值测试。
  • 资源匹配不一致:确认请求的域名my_domain.us-east-1.aoss.amazonaws.com对应的collection是否为my_collection,若域名属于其他collection,当前策略的资源路径index/my_collection/*将无法匹配,导致权限验证失败。
  • 临时凭证有效性问题:检查$AWS_SESSION_TOKEN对应的临时凭证是否过期,以及该凭证是否关联到策略中指定的my_role_arn角色,确保角色与凭证一致。

内容的提问来源于stack exchange,提问作者RNA

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 01:37:04