You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

单微服务连接S3遇SdkClientException: Connection Reset问题求助

特定微服务通过AssumeRole连接AWS S3时出现Connection Reset错误排查

我们的应用包含9个微服务,均通过AssumeRole方式连接AWS S3,服务运行在Docker容器内并通过代理访问S3。其中8个服务可正常连接S3并获取会话令牌,但某一个特定服务抛出SdkClientException: Could not execute HTTP request - Connection Reset错误。

服务Dockerfile

FROM openjdk:11-jdk-slim

ENV HTTPS_PROXY 'http://proxyip:proxyport' 
ENV HTTP_PROXY 'http://proxyip:proxyport'
ENV https_proxy 'http://proxyip:proxyport'
ENV http_proxy 'http://proxyip:proxyport

RUN apt -y update && apt -y upgrade
RUN apt -y install unzip
RUN apt -y install curl
RUN apt -y install less
RUN curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
RUN unzip awscliv2.zip
RUN ./aws/install

VOLUME ~/.aws:/root/.aws
WORKDIR /tmp
ENV NO_PROXY 'someip'
ENV no_proxy 'someip'
ARG JAVA_OPTS
ENV JAVA_OPTS=$JAVA_OPTS
COPY services-0.0.1-SNAPSHOT.jar services-0.0.1-SNAPSHOT.jar
ENTRYPOINT java $JAVA_OPTS -Dagentlib:jdwp=transport=dt_socket,server=y,suspend=y,address=5006 -XX:+UseContainerSupport -XX:+UnlockDiagnosticVMOptions -XX:+LogVMOutput -XX:LogFile=~/jvm-us.log -jar services-0.0.1-SNAPSHOT.jar --spring.profiles.active="test-profile"

注:原Dockerfile中http_proxy环境变量末尾缺失单引号,可能导致变量配置失效

AWS连接代码

@Bean(name = "awsCredentialsProvider")
public AWSCredentialsProvider getAWSCredentials() {
    BasicAWSCredentials basicAWSCredentials = new BasicAWSCredentials(accessKey, secretKey);
    return new AWSStaticCredentialsProvider(basicAWSCredentials);

}

@Bean
public AWSSecurityTokenService stsClient() {
    AWSSecurityTokenService stsClient = AWSSecurityTokenServiceClientBuilder.standard()
            .withCredentials(getAWSCredentials())
            .withRegion(region)
            .build();
    return stsClient;
}

@Bean(name = "awsS3AudioBucket")
public String getAWSS3AudioBucket() {
    return bucket;
}


@Bean(name = "region")
public String getRegion() {
    return region;
}

public AWSSessionCredentialsProvider getAWSSTSCredentials() throws Exception {
    AWSCredentialsProvider credentialsProvider = null;
    log.info("Role Arn for the connection is: " + roleArn);
    AWSSessionCredentialsProvider awsCredentialsProvider = new STSAssumeRoleSessionCredentialsProvider.Builder(roleArn, "session-s3-access")
            .withStsClient(stsClient()).build();
    log.info("Credentials obtained and the token is: " + awsCredentialsProvider.getCredentials().getSessionToken());

    return awsCredentialsProvider;
}

版本信息

  • aws-java-sdk-sts: 1.11.174
  • Java版本: 11

错误日志

Bean instantiation via factory method failed; nested exception is org.springframework.beans.BeanInstantiationException: Failed to instantiate [com.amazonaws.services.s3.AmazonS3]: Factory method 'amazonS3' threw exception; nested exception is com.amazonaws.SdkClientException: Unable to execute HTTP request: Connection reset
        at org.springframework.beans.factory.annotation.AutowiredAnnotationBeanPostProcessor$AutowiredFieldElement.inject(AutowiredAnnotationBeanPostProcessor.java:643) ~[spring-beans-5.2.8.RELEASE.jar!/:5.2.8.RELEASE]
        at org.springframework.beans.factory.annotation.InjectionMetadata.inject(InjectionMetadata.java:130) ~[spring-beans-5.2.8.RELEASE.jar!/:5.2.8.RELEASE]
        at org.springframework.beans.factory.annotation.AutowiredAnnotationBeanPostProcessor.postProcessProperties(AutowiredAnnotationBeanPostProcessor.java:399) ~[spring-beans-5.2.8.RELEASE.jar!/:5.2.8.RELEASE]
        at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.populateBean(AbstractAutowireCapableBeanFactory.java:1420) ~[spring-beans-5.2.8.RELEASE.jar!/:5.2.8.RELEASE]

排查与解决建议

  • 修复代理环境变量:将Dockerfile中http_proxy的配置补全单引号,改为ENV http_proxy 'http://proxyip:proxyport',确保代理变量被正确识别
  • 显式配置AWS SDK代理:老版本AWS SDK(1.11.x)可能不会自动读取系统代理变量,需在STS和S3客户端构建时添加代理配置:
    ClientConfiguration clientConfig = new ClientConfiguration()
            .withProxyHost("proxyip")
            .withProxyPort(proxyport);
    AWSSecurityTokenService stsClient = AWSSecurityTokenServiceClientBuilder.standard()
            .withCredentials(getAWSCredentials())
            .withRegion(region)
            .withClientConfiguration(clientConfig)
            .build();
    
  • 检查容器网络差异:对比异常服务与正常服务的容器网络配置,确认是否存在端口限制、网络策略或代理服务器访问权限差异,比如该服务是否被代理IP白名单排除
  • 升级AWS SDK版本:1.11.174版本存在较多已知的网络连接和代理相关bug,建议升级到1.11.x系列的最新稳定版,或迁移至AWS SDK for Java v2以获得更好的网络兼容性
  • 排查JVM参数与依赖:检查该服务的JAVA_OPTS是否包含影响网络的参数(如代理覆盖),同时扫描依赖树确认是否存在HTTP客户端库冲突(如OkHttp、Apache HttpClient版本不一致)
  • 验证角色与区域配置:确认该服务使用的roleArn、AWS区域与正常服务完全一致,避免因角色权限不足、区域错误导致的连接失败

内容的提问来源于stack exchange,提问作者Jaighanesh S

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 20:52:55