使用Terraform部署AWS Amplify时遇BadRequestException错误求助
解决Terraform部署AWS Amplify应用时的Token错误
问题描述
执行terraform init和terraform plan无报错,但terraform apply时抛出以下错误:
Error: creating Amplify App (nextjs_app_amplify): BadRequestException: You should at least provide one valid token with aws_amplify_app.nextjs_app, on main.tf line 7, in resource aws_amplify_app "nextjs_app": 7: resource "aws_amplify_app" "nextjs_app" {
使用的main.tf配置如下:
provider "aws" { region = "ap-south-1" access_key = "xxxxx" secret_key = "xxxxx" } resource "aws_amplify_app" "nextjs_app" { name = "nextjs_app_amplify" platform = "WEB" repository = "https://github.com/xxx/nectjs-example.git" }
注:代码仓库为公开仓库。
解决方案
即使是公开GitHub仓库,Terraform的aws_amplify_app资源仍要求提供有效的OAuth令牌来完成仓库访问验证,具体操作如下:
生成GitHub只读个人访问令牌(PAT)
- 登录GitHub,进入「Settings」>「Developer settings」>「Personal access tokens」
- 生成新令牌,勾选
public_repo权限(仅需只读权限即可) - 保存生成的令牌,后续配置会用到
修改Terraform配置
在aws_amplify_app资源中添加oauth_token参数,建议通过Terraform变量传递令牌(避免硬编码敏感信息):修改后的
main.tf:provider "aws" { region = "ap-south-1" # 强烈建议通过环境变量AWS_ACCESS_KEY_ID和AWS_SECRET_ACCESS_KEY传递密钥,不要硬编码 } resource "aws_amplify_app" "nextjs_app" { name = "nextjs_app_amplify" platform = "WEB" repository = "https://github.com/xxx/nectjs-example.git" oauth_token = var.github_pat }同时创建
variables.tf文件定义敏感变量:variable "github_pat" { type = string description = "GitHub个人访问令牌,需拥有public_repo权限" sensitive = true }执行部署
通过命令行传递变量值:terraform apply -var "github_pat=你的GitHub令牌"或通过环境变量传递:
export TF_VAR_github_pat="你的GitHub令牌" terraform apply
关键说明
- 这是Terraform AWS Provider的强制要求,即使仓库公开,Amplify仍需令牌完成初始化阶段的仓库访问验证
- 不要将密钥或令牌硬编码在配置文件中,避免敏感信息泄露
- 令牌仅需
public_repo权限,最小化权限范围提升安全性
内容的提问来源于stack exchange,提问作者Akshay Jain
相关产品推荐
相关产品推荐

