VPC内Lambda访问AWS SecretsManager的安全组配置规则咨询
VPC内Lambda访问SecretsManager的安全组配置方案
你的问题核心是接口型VPC端点的安全组规则未正确配置,导致VPC内的Lambda无法通过端点访问SecretsManager。以下是具体调整方案:
关键配置逻辑
接口型SecretsManager VPC端点依赖HTTPS(443端口)通信,必须满足两个核心条件:
- VPC端点的安全组允许来自Lambda所在安全组的443端口入站流量
- Lambda的安全组允许出站访问443端口(你的现有配置已满足,可按需优化)
修改后的CloudFormation配置
建议给VPC端点单独创建安全组(遵循权限最小化原则),替换原有模板中的相关部分:
CrossadVpc: Type: AWS::EC2::VPC Properties: CidrBlock: 192.168.0.0/21 EnableDnsHostnames: true EnableDnsSupport: true InstanceTenancy: default # 新增VPC端点专用安全组 VpcEndpointSecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: Allow Lambda access to SecretsManager VPC Endpoint VpcId: !Ref CrossadVpc SecurityGroupIngress: - Description: Allow HTTPS from Lambda security group IpProtocol: tcp FromPort: 443 ToPort: 443 SourceSecurityGroupId: !Ref LambdaSecurityGroup SecurityGroupEgress: - Description: Allow necessary outbound traffic IpProtocol: -1 CidrIp: 0.0.0.0/0 VpcEndpoint: Type: AWS::EC2::VPCEndpoint Properties: PrivateDnsEnabled: true SecurityGroupIds: - !Ref VpcEndpointSecurityGroup # 替换为专用安全组 ServiceName: !Sub 'com.amazonaws.${AWS::Region}.secretsmanager' VpcEndpointType: Interface SubnetIds: - !Ref LambdaSubnet VpcId: !Ref CrossadVpc LambdaSubnet: Type: AWS::EC2::Subnet Properties: CidrBlock: 192.168.0.0/24 VpcId: !Ref CrossadVpc LambdaSecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: LambdaSecurityGroup GroupName: LambdaSecurityGroup SecurityGroupEgress: - CidrIp: 0.0.0.0/0 Description: AllowAllOutbound IpProtocol: -1 # Lambda通常无需主动接收外部流量,移除冗余全量入站规则 SecurityGroupIngress: [] VpcId: !Ref CrossadVpc ProxyLambda: Type: AWS::Serverless::Function Properties: Architectures: - arm64 CodeUri: proxy Handler: com.github.somegroup.crossad.proxy.Proxy::handleRequest MemorySize: 1798 PackageType: Zip Role: !GetAtt LambdaRole.Arn Runtime: java17 Timeout: 600 Tracing: Active Environment: Variables: ALLOWED_ORIGIN: "*" DEFAULT_HOST: !Ref CrossAdHost CROSSAD_CREDENTIALS_SECRET_NAME: !Ref CrossAdCredentialsSecretName VpcConfig: SecurityGroupIds: - !GetAtt LambdaSecurityGroup.GroupId SubnetIds: - !GetAtt LambdaSubnet.SubnetId Events: GetQuery: Type: Api Properties: Auth: Authorizer: CognitoAuth Scopes: ["https://crossad.loremipsum.com/scopes/backend"] Path: /{proxy+} Method: get RestApiId: !Ref ApiGateway PostQuery: Type: Api Properties: Auth: Authorizer: CognitoAuth Scopes: [ "https://crossad.loremipsum.com/scopes/backend" ] Path: /{proxy+} Method: post RestApiId: !Ref ApiGateway
调整细节说明
- VPC端点安全组:仅开放Lambda安全组的443端口入站,避免无关流量访问端点,符合权限最小化原则
- Lambda安全组:移除了冗余的全量入站规则(Lambda作为被动触发的服务,通常不需要主动接收外部流量),出站规则保留全量可满足多数场景,若需进一步收紧可修改为仅允许到VPC端点安全组的443端口
- PrivateDnsEnabled:已设置为
true,确保Lambda可以通过SecretsManager的标准域名访问,无需手动指定端点IP
内容的提问来源于stack exchange,提问作者orestis
相关产品推荐
相关产品推荐

