You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform部署AWS Amplify时遇BadRequestException错误求助

解决Terraform部署AWS Amplify应用时的Token错误

问题描述

执行terraform init和terraform plan无报错,但terraform apply时抛出以下错误:

Error: creating Amplify App (nextjs_app_amplify): BadRequestException: You should at least provide one valid token with aws_amplify_app.nextjs_app, on main.tf line 7, in resource aws_amplify_app "nextjs_app": 7: resource "aws_amplify_app" "nextjs_app" {

使用的main.tf配置如下:

provider "aws" {
  region = "ap-south-1"
  access_key = "xxxxx"
  secret_key = "xxxxx"
}

resource "aws_amplify_app" "nextjs_app" {
    name     = "nextjs_app_amplify"
    platform = "WEB"
    repository = "https://github.com/xxx/nectjs-example.git"
    }

注:代码仓库为公开仓库。

解决方案

即使是公开GitHub仓库,Terraform的aws_amplify_app资源仍要求提供有效的OAuth令牌来完成仓库访问验证,具体操作如下:

  1. 生成GitHub只读个人访问令牌(PAT)

    • 登录GitHub,进入「Settings」>「Developer settings」>「Personal access tokens」
    • 生成新令牌,勾选public_repo权限(仅需只读权限即可)
    • 保存生成的令牌,后续配置会用到
  2. 修改Terraform配置
    在aws_amplify_app资源中添加oauth_token参数,建议通过Terraform变量传递令牌(避免硬编码敏感信息):

    修改后的main.tf:

    provider "aws" {
      region = "ap-south-1"
      # 强烈建议通过环境变量AWS_ACCESS_KEY_ID和AWS_SECRET_ACCESS_KEY传递密钥,不要硬编码
    }
    
    resource "aws_amplify_app" "nextjs_app" {
      name      = "nextjs_app_amplify"
      platform  = "WEB"
      repository = "https://github.com/xxx/nectjs-example.git"
      oauth_token = var.github_pat
    }
    

    同时创建variables.tf文件定义敏感变量:

    variable "github_pat" {
      type        = string
      description = "GitHub个人访问令牌,需拥有public_repo权限"
      sensitive   = true
    }
    
  3. 执行部署
    通过命令行传递变量值:

    terraform apply -var "github_pat=你的GitHub令牌"
    

    或通过环境变量传递:

    export TF_VAR_github_pat="你的GitHub令牌"
    terraform apply
    

关键说明

  • 这是Terraform AWS Provider的强制要求,即使仓库公开,Amplify仍需令牌完成初始化阶段的仓库访问验证
  • 不要将密钥或令牌硬编码在配置文件中,避免敏感信息泄露
  • 令牌仅需public_repo权限,最小化权限范围提升安全性

内容的提问来源于stack exchange,提问作者Akshay Jain

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 06:30:16