You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

VPC内Lambda访问AWS SecretsManager的安全组配置规则咨询

VPC内Lambda访问SecretsManager的安全组配置方案

你的问题核心是接口型VPC端点的安全组规则未正确配置,导致VPC内的Lambda无法通过端点访问SecretsManager。以下是具体调整方案:

关键配置逻辑

接口型SecretsManager VPC端点依赖HTTPS(443端口)通信,必须满足两个核心条件:

  1. VPC端点的安全组允许来自Lambda所在安全组的443端口入站流量
  2. Lambda的安全组允许出站访问443端口(你的现有配置已满足,可按需优化)

修改后的CloudFormation配置

建议给VPC端点单独创建安全组(遵循权限最小化原则),替换原有模板中的相关部分:

CrossadVpc:
  Type: AWS::EC2::VPC
  Properties:
    CidrBlock: 192.168.0.0/21
    EnableDnsHostnames: true
    EnableDnsSupport: true
    InstanceTenancy: default

# 新增VPC端点专用安全组
VpcEndpointSecurityGroup:
  Type: AWS::EC2::SecurityGroup
  Properties:
    GroupDescription: Allow Lambda access to SecretsManager VPC Endpoint
    VpcId: !Ref CrossadVpc
    SecurityGroupIngress:
      - Description: Allow HTTPS from Lambda security group
        IpProtocol: tcp
        FromPort: 443
        ToPort: 443
        SourceSecurityGroupId: !Ref LambdaSecurityGroup
    SecurityGroupEgress:
      - Description: Allow necessary outbound traffic
        IpProtocol: -1
        CidrIp: 0.0.0.0/0

VpcEndpoint:
  Type: AWS::EC2::VPCEndpoint
  Properties:
    PrivateDnsEnabled: true
    SecurityGroupIds:
      - !Ref VpcEndpointSecurityGroup # 替换为专用安全组
    ServiceName: !Sub 'com.amazonaws.${AWS::Region}.secretsmanager'
    VpcEndpointType: Interface
    SubnetIds:
      - !Ref LambdaSubnet
    VpcId: !Ref CrossadVpc

LambdaSubnet:
  Type: AWS::EC2::Subnet
  Properties:
    CidrBlock: 192.168.0.0/24
    VpcId: !Ref CrossadVpc

LambdaSecurityGroup:
  Type: AWS::EC2::SecurityGroup
  Properties:
    GroupDescription: LambdaSecurityGroup
    GroupName: LambdaSecurityGroup
    SecurityGroupEgress:
      - CidrIp: 0.0.0.0/0
        Description: AllowAllOutbound
        IpProtocol: -1
    # Lambda通常无需主动接收外部流量,移除冗余全量入站规则
    SecurityGroupIngress: []
    VpcId: !Ref CrossadVpc

ProxyLambda:
  Type: AWS::Serverless::Function
  Properties:
    Architectures:
      - arm64
    CodeUri: proxy
    Handler: com.github.somegroup.crossad.proxy.Proxy::handleRequest
    MemorySize: 1798
    PackageType: Zip
    Role: !GetAtt LambdaRole.Arn
    Runtime: java17
    Timeout: 600
    Tracing: Active
    Environment:
      Variables:
        ALLOWED_ORIGIN: "*"
        DEFAULT_HOST: !Ref CrossAdHost
        CROSSAD_CREDENTIALS_SECRET_NAME: !Ref CrossAdCredentialsSecretName
    VpcConfig:
      SecurityGroupIds:
        - !GetAtt LambdaSecurityGroup.GroupId
      SubnetIds:
        - !GetAtt LambdaSubnet.SubnetId
    Events:
      GetQuery:
        Type: Api
        Properties:
          Auth:
            Authorizer: CognitoAuth
            Scopes: ["https://crossad.loremipsum.com/scopes/backend"]
          Path: /{proxy+}
          Method: get
          RestApiId: !Ref ApiGateway
      PostQuery:
        Type: Api
        Properties:
          Auth:
            Authorizer: CognitoAuth
            Scopes: [ "https://crossad.loremipsum.com/scopes/backend" ]
          Path: /{proxy+}
          Method: post
          RestApiId: !Ref ApiGateway

调整细节说明

  • VPC端点安全组:仅开放Lambda安全组的443端口入站,避免无关流量访问端点,符合权限最小化原则
  • Lambda安全组:移除了冗余的全量入站规则(Lambda作为被动触发的服务,通常不需要主动接收外部流量),出站规则保留全量可满足多数场景,若需进一步收紧可修改为仅允许到VPC端点安全组的443端口
  • PrivateDnsEnabled:已设置为true,确保Lambda可以通过SecretsManager的标准域名访问,无需手动指定端点IP

内容的提问来源于stack exchange,提问作者orestis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 18:46:16