调用_cat/indices?v访问Amazon OpenSearch Serverless返回403禁止访问
排查Amazon OpenSearch Serverless调用_cat/indices接口返回403 Forbidden的原因
问题重现
使用Curl 8.3.0执行以下请求获取Amazon OpenSearch Serverless集群索引信息:
curl -XGET https://my_domain.us-east-1.aoss.amazonaws.com/_cat/indices?v \ --aws-sigv4 aws:amz:us-east-1:aoss \ --user $AWS_ACCESS_KEY:$AWS_SECRET_KEY \ --header "Content-Type: application/json; charset=utf-8" \ --header "x-amz-security-token:${AWS_SESSION_TOKEN}"
收到403 Forbidden错误:
{"status":403,"request-id":"a6603a35-6757-9a13-86c9-xxx","error":{"reason":"403 Forbidden","type":"Forbidden"}}
curl -v输出详情:
Note: Unnecessary use of -X or --request, GET is already inferred. * Trying x.x.x.x:443... * Connected to my_domain.us-east-1.aoss.amazonaws.com (x.x.x.x) port 443 * ALPN: curl offers http/1.1 * TLSv1.3 (OUT), TLS handshake, Client hello (1): * CAfile: /etc/ssl/certs/ca-certificates.crt * CApath: none * TLSv1.3 (IN), TLS handshake, Server hello (2): * TLSv1.2 (IN), TLS handshake, Certificate (11): * TLSv1.2 (IN), TLS handshake, Server key exchange (12): * TLSv1.2 (IN), TLS handshake, Server finished (14): * TLSv1.2 (OUT), TLS handshake, Client key exchange (16): * TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1): * TLSv1.2 (OUT), TLS handshake, Finished (20): * TLSv1.2 (IN), TLS handshake, Finished (20): * SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256 * ALPN: server did not agree on a protocol. Uses default. * Server certificate: * subject: CN=*.us-east-1.aoss.amazonaws.com * start date: Dec 18 00:00:00 2022 GMT * expire date: Jan 16 23:59:59 2024 GMT * subjectAltName: host "my_domain.us-east-1.aoss.amazonaws.com" matched cert's "*.us-east-1.aoss.amazonaws.com" * issuer: C=US; O=Amazon; CN=Amazon RSA 2048 M02 * SSL certificate verify ok. * using HTTP/1.x * Server auth using AWS_SIGV4 with user '' > GET /_cat/indices?v HTTP/1.1 > Host: my_domain.us-east-1.aoss.amazonaws.com > Authorization: AWS4-HMAC-SHA256 Credential=/20230927/us-east-1/aoss/aws4_request, SignedHeaders=content-type;host;x-amz-date;x-amz-security-token, Signature=ab.... > X-Amz-Date: 20230927T065937Z > User-Agent: curl/8.3.0 > Accept: */* > Content-Type: application/json; charset=utf-8 > x-amz-security-token:abc > < HTTP/1.1 403 Forbidden < x-request-id: 642feace-d1d2-9705-a97b-xxx < x-aoss-response-hint: X01:gw-helper-deny < content-type: application/json < date: Wed, 27 Sep 2023 06:59:37 GMT < content-length: 121 < server: aoss-amazon < {"status":403,"request-id":"642feace-d1d2-9705-a97b-xxx","error":{"reason":"403 Forbidden","type":"Forbidden"}} * Connection #0 to host my_domain.us-east-1.aoss.amazonaws.com left intact
当前配置的数据访问策略:
{ "Rules": [ { "ResourceType": "index", "Resource": [ "index/my_collection/*" ], "Permission": [ "aoss:CreateIndex", "aoss:DeleteIndex", "aoss:DescribeIndex", "aoss:ReadDocument", "aoss:UpdateIndex", "aoss:WriteDocument" ] }, { "ResourceType": "collection", "Resource": [ "collection/my_collection" ], "Permission": [ "aoss:CreateCollectionItems", "aoss:DeleteCollectionItems", "aoss:DescribeCollectionItems", "aoss:UpdateCollectionItems" ] } ], "Principal": [ "my_role_arn" ] }
可能的原因及修复方案
- 缺少
aoss:ListIndices权限:_cat/indices接口属于索引列表查询操作,需要aoss:ListIndices权限,当前数据访问策略的index权限组中未包含该权限。需在index资源的Permission数组中添加"aoss:ListIndices"。 - 凭证加载异常:从curl verbose输出可见
Server auth using AWS_SIGV4 with user '',且Authorization头的Credential字段为空(Credential=/20230927/...),说明$AWS_ACCESS_KEY环境变量未正确注入。需检查环境变量是否已正确设置,或直接替换为实际的Access Key值测试。 - 资源匹配不一致:确认请求的域名
my_domain.us-east-1.aoss.amazonaws.com对应的collection是否为my_collection,若域名属于其他collection,当前策略的资源路径index/my_collection/*将无法匹配,导致权限验证失败。 - 临时凭证有效性问题:检查
$AWS_SESSION_TOKEN对应的临时凭证是否过期,以及该凭证是否关联到策略中指定的my_role_arn角色,确保角色与凭证一致。
内容的提问来源于stack exchange,提问作者RNA
相关产品推荐
相关产品推荐

