You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CLI中“default”凭证源无效,如何解决pulumi up认证问题?

解决AWS授权认证问题以执行pulumi up

问题根源

你的AWS配置存在两处关键错误:

  1. ~/.aws/config中使用了无效的credential_source = default——credential_source的有效值为Environment、Ec2InstanceMetadata、EcsContainer等,不能直接指定profile名称;
  2. ~/.aws/credentials中混入了role_arn配置,该字段应仅放在config文件中,credentials文件只负责存储访问密钥对。

解决方案(本地环境使用访问密钥Assume Role)

步骤1:修正~/.aws/config文件

将配置改为使用source_profile引用本地凭证,而非无效的credential_source:

[default]
role_arn=arn:aws:iam::<some number>:role/<some role>
source_profile=default

source_profile=default会告诉AWS SDK使用credentials文件中default profile的访问密钥来Assume指定的角色。

步骤2:修正~/.aws/credentials文件

移除多余的role_arn字段,只保留访问密钥:

[default]
aws_access_key_id = <some id>
aws_secret_access_key = <some key>

备选方案(直接使用访问密钥,无需Assume Role)

如果你的访问密钥本身已经拥有执行pulumi up所需的权限,可以简化配置:

  1. 删除~/.aws/config中的role_arn和credential_source字段,文件内容可仅保留[default];
  2. 移除~/.aws/credentials中的role_arn字段,仅保留访问密钥对。

完成配置修改后,重新执行pulumi up即可正常发起AWS API调用。

内容的提问来源于stack exchange,提问作者Aviral Srivastava

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 02:52:10