You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EC2上部署的Java SDK连接OpenSearchService遇认证授权失败

EC2实例上Java SDK连接OpenSearch Service报security_exception认证失败

我在EC2实例上部署的Java应用,通过Java SDK连接AWS OpenSearch Service,已执行aws configure配置凭证,但仍触发认证/授权失败错误。本地机器可正常连接目标OpenSearch域,EC2实例上无法连通。

错误日志

Servlet.service() for servlet [dispatcherServlet] in context with path [] threw exception [Request processing failed: org.opensearch.client.opensearch._types.OpenSearchException: Request failed: [security_exception] authentication/authorization failure] with root cause
org.opensearch.client.opensearch._types.OpenSearchException: Request failed: [security_exception] authentication/authorization failure

aws configure 配置状态

执行aws configure list输出:

Name                    Value             Type    Location
      ----                    -----             ----    --------
   profile                <not set>             None    None
access_key     ****************2Y4Y shared-credentials-file    
secret_key     ****************NjjN shared-credentials-file    
    region               ap-south-1      config-file    ~/.aws/config

Java客户端Bean配置

@Bean
public OpenSearchClient getClient() {
        SdkHttpClient httpClient = ApacheHttpClient.builder().build();
        return new OpenSearchClient(
                new AwsSdk2Transport(
                        httpClient,
                        host,
                        region,
                        AwsSdk2TransportOptions.builder().build()));

    }

OpenSearch域相关配置

  • 已启用细粒度访问控制
  • 域级访问策略:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "*"
      },
      "Action": "es:*",
      "Resource": "arn:aws:es:ap-south-1:************:domain/opensearch-domain/*"
    }
  ]
}

内容的提问来源于stack exchange,提问作者Suvid Sahay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 17:17:44