单微服务连接S3遇SdkClientException: Connection Reset问题求助
特定微服务通过AssumeRole连接AWS S3时出现Connection Reset错误排查
我们的应用包含9个微服务,均通过AssumeRole方式连接AWS S3,服务运行在Docker容器内并通过代理访问S3。其中8个服务可正常连接S3并获取会话令牌,但某一个特定服务抛出SdkClientException: Could not execute HTTP request - Connection Reset错误。
服务Dockerfile
FROM openjdk:11-jdk-slim ENV HTTPS_PROXY 'http://proxyip:proxyport' ENV HTTP_PROXY 'http://proxyip:proxyport' ENV https_proxy 'http://proxyip:proxyport' ENV http_proxy 'http://proxyip:proxyport RUN apt -y update && apt -y upgrade RUN apt -y install unzip RUN apt -y install curl RUN apt -y install less RUN curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip" RUN unzip awscliv2.zip RUN ./aws/install VOLUME ~/.aws:/root/.aws WORKDIR /tmp ENV NO_PROXY 'someip' ENV no_proxy 'someip' ARG JAVA_OPTS ENV JAVA_OPTS=$JAVA_OPTS COPY services-0.0.1-SNAPSHOT.jar services-0.0.1-SNAPSHOT.jar ENTRYPOINT java $JAVA_OPTS -Dagentlib:jdwp=transport=dt_socket,server=y,suspend=y,address=5006 -XX:+UseContainerSupport -XX:+UnlockDiagnosticVMOptions -XX:+LogVMOutput -XX:LogFile=~/jvm-us.log -jar services-0.0.1-SNAPSHOT.jar --spring.profiles.active="test-profile"
注:原Dockerfile中
http_proxy环境变量末尾缺失单引号,可能导致变量配置失效
AWS连接代码
@Bean(name = "awsCredentialsProvider") public AWSCredentialsProvider getAWSCredentials() { BasicAWSCredentials basicAWSCredentials = new BasicAWSCredentials(accessKey, secretKey); return new AWSStaticCredentialsProvider(basicAWSCredentials); } @Bean public AWSSecurityTokenService stsClient() { AWSSecurityTokenService stsClient = AWSSecurityTokenServiceClientBuilder.standard() .withCredentials(getAWSCredentials()) .withRegion(region) .build(); return stsClient; } @Bean(name = "awsS3AudioBucket") public String getAWSS3AudioBucket() { return bucket; } @Bean(name = "region") public String getRegion() { return region; } public AWSSessionCredentialsProvider getAWSSTSCredentials() throws Exception { AWSCredentialsProvider credentialsProvider = null; log.info("Role Arn for the connection is: " + roleArn); AWSSessionCredentialsProvider awsCredentialsProvider = new STSAssumeRoleSessionCredentialsProvider.Builder(roleArn, "session-s3-access") .withStsClient(stsClient()).build(); log.info("Credentials obtained and the token is: " + awsCredentialsProvider.getCredentials().getSessionToken()); return awsCredentialsProvider; }
版本信息
- aws-java-sdk-sts: 1.11.174
- Java版本: 11
错误日志
Bean instantiation via factory method failed; nested exception is org.springframework.beans.BeanInstantiationException: Failed to instantiate [com.amazonaws.services.s3.AmazonS3]: Factory method 'amazonS3' threw exception; nested exception is com.amazonaws.SdkClientException: Unable to execute HTTP request: Connection reset at org.springframework.beans.factory.annotation.AutowiredAnnotationBeanPostProcessor$AutowiredFieldElement.inject(AutowiredAnnotationBeanPostProcessor.java:643) ~[spring-beans-5.2.8.RELEASE.jar!/:5.2.8.RELEASE] at org.springframework.beans.factory.annotation.InjectionMetadata.inject(InjectionMetadata.java:130) ~[spring-beans-5.2.8.RELEASE.jar!/:5.2.8.RELEASE] at org.springframework.beans.factory.annotation.AutowiredAnnotationBeanPostProcessor.postProcessProperties(AutowiredAnnotationBeanPostProcessor.java:399) ~[spring-beans-5.2.8.RELEASE.jar!/:5.2.8.RELEASE] at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.populateBean(AbstractAutowireCapableBeanFactory.java:1420) ~[spring-beans-5.2.8.RELEASE.jar!/:5.2.8.RELEASE]
排查与解决建议
- 修复代理环境变量:将Dockerfile中
http_proxy的配置补全单引号,改为ENV http_proxy 'http://proxyip:proxyport',确保代理变量被正确识别 - 显式配置AWS SDK代理:老版本AWS SDK(1.11.x)可能不会自动读取系统代理变量,需在STS和S3客户端构建时添加代理配置:
ClientConfiguration clientConfig = new ClientConfiguration() .withProxyHost("proxyip") .withProxyPort(proxyport); AWSSecurityTokenService stsClient = AWSSecurityTokenServiceClientBuilder.standard() .withCredentials(getAWSCredentials()) .withRegion(region) .withClientConfiguration(clientConfig) .build(); - 检查容器网络差异:对比异常服务与正常服务的容器网络配置,确认是否存在端口限制、网络策略或代理服务器访问权限差异,比如该服务是否被代理IP白名单排除
- 升级AWS SDK版本:1.11.174版本存在较多已知的网络连接和代理相关bug,建议升级到1.11.x系列的最新稳定版,或迁移至AWS SDK for Java v2以获得更好的网络兼容性
- 排查JVM参数与依赖:检查该服务的
JAVA_OPTS是否包含影响网络的参数(如代理覆盖),同时扫描依赖树确认是否存在HTTP客户端库冲突(如OkHttp、Apache HttpClient版本不一致) - 验证角色与区域配置:确认该服务使用的
roleArn、AWS区域与正常服务完全一致,避免因角色权限不足、区域错误导致的连接失败
内容的提问来源于stack exchange,提问作者Jaighanesh S
相关产品推荐
相关产品推荐

