You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CodeArtifact配置报错:sts:GetServiceBearerToken权限问题求助

AWS CodeArtifact登录权限错误解决

问题场景

已手动创建CodeArtifact域和仓库,执行以下npm登录命令时触发权限错误:

aws codeartifact login --tool npm --repository npm-store --domain domain-npm --domain-owner 111111111 --region us-east-1

错误信息

when calling the GetAuthorizationToken operation: User: arn:aws:iam::111111111:root is not authorized to perform: sts:GetServiceBearerToken on resource: arn:aws:iam::111111111:root

已配置权限

  • 已在IAM Identity Center中添加AWSCodeArtifactAdminAccess权限
  • 附加了以下内联权限策略:
{
   "Version": "2012-10-17",
   "Statement": [
      {
         "Action": [
            "codeartifact:*"
         ],
         "Effect": "Allow",
         "Resource": "*"
      },
      {
         "Effect": "Allow",
         "Action": "sts:GetServiceBearerToken",
         "Resource": "*",
         "Condition": {
            "StringEquals": {
               "sts:AWSServiceName": "codeartifact.amazonaws.com"
            }
         }
      }
   ]
}

解决步骤

  • 切换非Root身份操作:报错明确显示当前使用Root用户,而IAM Identity Center的权限仅对IAM用户/角色生效,Root用户不会继承这些权限。需切换到通过IAM Identity Center授权的用户身份执行命令。
  • 验证当前身份:执行aws sts get-caller-identity确认当前使用的是目标IAM用户而非Root用户。
  • 确认STS权限有效性:确保内联策略中的sts:GetServiceBearerToken权限已正确关联到目标用户,且条件sts:AWSServiceName设置正确。
  • 刷新IAM Identity Center会话:若使用临时凭证,需确保会话未过期,重新获取有效凭证后再执行登录命令。

内容的提问来源于stack exchange,提问作者user1204615

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 00:03:23