Terraform部署AWS GovCloud遇InvalidClientTokenId错误求助
Terraform/Terragrunt部署AWS GovCloud时触发InvalidClientTokenId错误
商用AWS环境部署完全正常,但在GovCloud环境执行terragrunt plan或terraform plan时,始终抛出InvalidClientTokenId错误,具体表现为STS调用GetCallerIdentity返回403。
已完成的排查操作
- 验证
~/.aws/credentials和~/.aws/config中的GovCloud凭证信息无误 - 使用相同GovCloud凭证部署仅包含数据资源的极简Terraform代码成功,证明凭证本身有效
- 执行
printenv检查环境变量,无多余AWS/TF相关变量干扰 - 查看GovCloud访问日志,发现请求使用了会话令牌
ASIAxxxxxxxxx,但未找到该令牌的生成来源(未手动执行aws sts get-session-token) - 分别测试
terragrunt plan和terraform plan,均出现相同错误
环境信息
- 工具链:Terragrunt封装Terraform
- Terraform版本:v1.4.5
- Terragrunt版本:v0.45.2
错误日志
Terraform planned the following actions, but then encountered a problem: ... ... ... Plan: 1 to add, 0 to change, 0 to destroy. ╷ │ Error: configuring Terraform AWS Provider: validating provider credentials: retrieving caller identity from STS: operation error STS: GetCallerIdentity, https response error StatusCode: 403, RequestID: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx, api error InvalidClientTokenId: The security token included in the request is invalid. │ │ with provider["registry.terraform.io/hashicorp/aws"], │ on provider.tf line 27, in provider "aws": │ 27: provider "aws" { │ ╵ ERRO[0003] Terraform invocation failed in /path/to/tf/repo/tf-modules ERRO[0003] 1 error occurred: * exit status 1
相关配置文件
Provider.tf(Terragrunt生成)
# Generated by Terragrunt. terraform { required_providers { aws = { source = "hashicorp/aws" version = "~> 4.62.0" } kubernetes = { source = "hashicorp/kubernetes" version = "~> 2.19.0" } helm = { source = "hashicorp/helm" version = "~> 2.9.0" } http = { source = "hashicorp/http" version = "~> 3.2.1" } null = { source = "hashicorp/null" version = "~> 3.2.1" } } } provider "aws" { region = var.region # sts_region = var.region profile = "govcloud" shared_config_files = [pathexpand("~/.aws/config")] shared_credentials_files = [pathexpand("~/.aws/credentials")] }
Terragrunt.hcl
locals { name = "terragrunt" cloud = "aws" # Only Valid [aws] version = { tf_aws = "4.62.0", # DONT TOUCH tf_k8s = "2.19.0", # DONT TOUCH tf_helm = "2.9.0", # DONT TOUCH tf_http = "3.2.1", # DONT TOUCH tf_null = "3.2.1" # DONT TOUCH } environment = { aws = "govcloud" # Only Valid [eastwest, govcloud] } region = { govcloud = "us-gov-east-1", eastwest = "us-east-1" } } # Indicate the input values to use for the variables of the module. inputs = { k8s_ver = "1.25" cloud_provider = local.cloud cloud_environment = local.environment[local.cloud] instance_type = "t2.medium" ... ... (Misc node configs) ... region = local.region[local.environment[local.cloud]] name = "${local.name}" domain = "domain.tld" subnet = "10.11.0.0" helm_charts = [ { name = "cert-manager" }, { name = "code-server" } ] default_tags = {keys=values} } # ======================================================= # - - - - - - - DO NOT EDIT BELOW THIS LINE - - - - - - - # ======================================================= terraform { extra_arguments "common_vars" { commands = get_terraform_commands_that_need_vars() arguments = [ "-var-file=./${local.name}.tfvars" ] env_vars = { # Set this b/c its what made the small seperate plan work. AWS_PROFILE = "govcloud" } } } # Indicate what region to deploy the resources into generate "provider" { path = "provider.tf" if_exists = "overwrite_terragrunt" contents = <<EOF ... ... <Provider.tf contents> ... EOF }
~/.aws/config
[default] region=us-east-1 output=yaml [profile govcloud] region=us-gov-east-1 output=yaml [profile eastwest] region=us-east-1 output=yaml
~/.aws/credentials
[default] aws_access_key_id=<eastwest_access_key> aws_secret_access_key=<eastwest_secret_key> [govcloud] aws_access_key_id=<govcloud_access_key> aws_secret_access_key=<govcloud_secret_key> [eastwest] aws_access_key_id=<eastwest_access_key> aws_secret_access_key=<eastwest_secret_key>
求助方向
怀疑存在未被发现的无效会话令牌,但暂未尝试删除~/.aws目录(目录下仅包含上述config和credentials文件)。请提供针对性的排查或解决建议。
内容的提问来源于stack exchange,提问作者aRustyDev
相关产品推荐
相关产品推荐

