You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS工作负载身份联合中google.auth凭证无token问题排查

问题原因及修复方案

核心原因:凭证未主动触发刷新

aws.Credentials实例初始化后不会自动获取token,必须手动调用refresh()方法触发完整的凭证获取流程,否则token会保持None,valid字段也会返回False。

其他可能的影响因素

  • 依赖缺失:确保环境已安装google-auth和boto3,二者是处理AWS身份验证和GCP凭证交换的必要依赖。
  • IAM角色权限不足:
    • 运行Lambda的IAM角色需允许调用sts:GetCallerIdentity接口(验证AWS身份的核心操作)
    • 该角色必须已被添加到GCP Workload Identity Pool的AWS提供商允许列表中
    • 确认VPC配置未限制对EC2元数据服务(http://169.254.169.254)的访问
  • 配置信息错误:
    • 核对audience字段中的项目ID、池名、提供商名与GCP控制台配置完全一致
    • 确认service_account_impersonation_url中的服务账号邮箱正确,且该账号已授予允许被当前AWS角色 impersonate 的权限

修复后的示例代码

from google.auth import aws
from google.auth.transport.requests import Request

def lambda_handler(event, context):

    json_config_info = {
      "type": "external_account",
      "audience": "//iam.googleapis.com/projects/XXX/locations/global/workloadIdentityPools/awspool/providers/awsprovider",
      "subject_token_type": "urn:ietf:params:aws:token-type:aws4_request",
      "service_account_impersonation_url": "https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/serviceaccount@XXX.iam.gserviceaccount.com:generateAccessToken",
      "token_url": "https://sts.googleapis.com/v1/token",
      "credential_source": {
        "environment_id": "aws1",
        "region_url": "http://169.254.169.254/latest/meta-data/placement/availability-zone",
        "url": "http://169.254.169.254/latest/meta-data/iam/security-credentials",
        "regional_cred_verification_url": "https://sts.{region}.amazonaws.com?Action=GetCallerIdentity&Version=2011-06-15"
      }
    }

    credentials = aws.Credentials.from_info(json_config_info)
    # 手动触发凭证刷新流程
    credentials.refresh(Request())
    print('token: ', credentials.token)
    print('valid: ', credentials.valid)

内容的提问来源于stack exchange,提问作者morulaus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 16:05:12