AWS工作负载身份联合中google.auth凭证无token问题排查
问题原因及修复方案
核心原因:凭证未主动触发刷新
aws.Credentials实例初始化后不会自动获取token,必须手动调用refresh()方法触发完整的凭证获取流程,否则token会保持None,valid字段也会返回False。
其他可能的影响因素
- 依赖缺失:确保环境已安装
google-auth和boto3,二者是处理AWS身份验证和GCP凭证交换的必要依赖。 - IAM角色权限不足:
- 运行Lambda的IAM角色需允许调用
sts:GetCallerIdentity接口(验证AWS身份的核心操作) - 该角色必须已被添加到GCP Workload Identity Pool的AWS提供商允许列表中
- 确认VPC配置未限制对EC2元数据服务(
http://169.254.169.254)的访问
- 运行Lambda的IAM角色需允许调用
- 配置信息错误:
- 核对
audience字段中的项目ID、池名、提供商名与GCP控制台配置完全一致 - 确认
service_account_impersonation_url中的服务账号邮箱正确,且该账号已授予允许被当前AWS角色 impersonate 的权限
- 核对
修复后的示例代码
from google.auth import aws from google.auth.transport.requests import Request def lambda_handler(event, context): json_config_info = { "type": "external_account", "audience": "//iam.googleapis.com/projects/XXX/locations/global/workloadIdentityPools/awspool/providers/awsprovider", "subject_token_type": "urn:ietf:params:aws:token-type:aws4_request", "service_account_impersonation_url": "https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/serviceaccount@XXX.iam.gserviceaccount.com:generateAccessToken", "token_url": "https://sts.googleapis.com/v1/token", "credential_source": { "environment_id": "aws1", "region_url": "http://169.254.169.254/latest/meta-data/placement/availability-zone", "url": "http://169.254.169.254/latest/meta-data/iam/security-credentials", "regional_cred_verification_url": "https://sts.{region}.amazonaws.com?Action=GetCallerIdentity&Version=2011-06-15" } } credentials = aws.Credentials.from_info(json_config_info) # 手动触发凭证刷新流程 credentials.refresh(Request()) print('token: ', credentials.token) print('valid: ', credentials.valid)
内容的提问来源于stack exchange,提问作者morulaus
相关产品推荐
相关产品推荐

