You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署AWS GovCloud遇InvalidClientTokenId错误求助

Terraform/Terragrunt部署AWS GovCloud时触发InvalidClientTokenId错误

商用AWS环境部署完全正常,但在GovCloud环境执行terragrunt plan或terraform plan时,始终抛出InvalidClientTokenId错误,具体表现为STS调用GetCallerIdentity返回403。

已完成的排查操作

  • 验证~/.aws/credentials和~/.aws/config中的GovCloud凭证信息无误
  • 使用相同GovCloud凭证部署仅包含数据资源的极简Terraform代码成功,证明凭证本身有效
  • 执行printenv检查环境变量,无多余AWS/TF相关变量干扰
  • 查看GovCloud访问日志,发现请求使用了会话令牌ASIAxxxxxxxxx,但未找到该令牌的生成来源(未手动执行aws sts get-session-token)
  • 分别测试terragrunt plan和terraform plan,均出现相同错误

环境信息

  • 工具链:Terragrunt封装Terraform
  • Terraform版本:v1.4.5
  • Terragrunt版本:v0.45.2

错误日志

Terraform planned the following actions, but then encountered a problem:

...
...
...

Plan: 1 to add, 0 to change, 0 to destroy.
╷
│ Error: configuring Terraform AWS Provider: validating provider credentials: retrieving caller identity from STS: operation error STS: GetCallerIdentity, https response error StatusCode: 403, RequestID: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx, api error InvalidClientTokenId: The security token included in the request is invalid.
│ 
│   with provider["registry.terraform.io/hashicorp/aws"],
│   on provider.tf line 27, in provider "aws":
│   27: provider "aws" {
│ 
╵
ERRO[0003] Terraform invocation failed in /path/to/tf/repo/tf-modules 
ERRO[0003] 1 error occurred:
        * exit status 1

相关配置文件

Provider.tf(Terragrunt生成)

# Generated by Terragrunt.
terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 4.62.0"
    }
    kubernetes = {
      source  = "hashicorp/kubernetes"
      version = "~> 2.19.0"
    }
    helm = {
      source  = "hashicorp/helm"
      version = "~> 2.9.0"
    }
    http = {
      source  = "hashicorp/http"
      version = "~> 3.2.1"
    }
    null = {
      source  = "hashicorp/null"
      version = "~> 3.2.1"
    }
  }
}

provider "aws" {
  region                   = var.region
  # sts_region               = var.region
  profile                  = "govcloud"
  shared_config_files      = [pathexpand("~/.aws/config")]
  shared_credentials_files = [pathexpand("~/.aws/credentials")]
}

Terragrunt.hcl

locals {
  name  = "terragrunt"
  cloud = "aws" # Only Valid [aws]

  version = {
    tf_aws  = "4.62.0",     # DONT TOUCH
    tf_k8s  = "2.19.0",     # DONT TOUCH
    tf_helm = "2.9.0",      # DONT TOUCH
    tf_http = "3.2.1",      # DONT TOUCH
    tf_null = "3.2.1"       # DONT TOUCH
  }

  environment = {
    aws = "govcloud" # Only Valid [eastwest, govcloud]
  }

  region = {
    govcloud = "us-gov-east-1",
    eastwest = "us-east-1"
  }
}

# Indicate the input values to use for the variables of the module.
inputs = {
  k8s_ver = "1.25"

  cloud_provider    = local.cloud
  cloud_environment = local.environment[local.cloud]

  instance_type   = "t2.medium"
  ...
  ... (Misc node configs)
  ... 
  region    = local.region[local.environment[local.cloud]]

  name      = "${local.name}"
  domain    = "domain.tld"
  subnet    = "10.11.0.0"

  helm_charts = [
    {
      name = "cert-manager"
    }, 
    {
      name = "code-server"
    }
  ]

  default_tags = {keys=values}
}

# =======================================================
# - - - - - - - DO NOT EDIT BELOW THIS LINE - - - - - - - 
# =======================================================

terraform {
  extra_arguments "common_vars" {
    commands = get_terraform_commands_that_need_vars()

    arguments = [
      "-var-file=./${local.name}.tfvars"
    ]
    
    env_vars = { # Set this b/c its what made the small seperate plan work.
      AWS_PROFILE = "govcloud"
    }
  }
}

# Indicate what region to deploy the resources into
generate "provider" {
  path      = "provider.tf"
  if_exists = "overwrite_terragrunt"
  contents  = <<EOF
...
... <Provider.tf contents>
...
EOF
}

~/.aws/config

[default]
region=us-east-1
output=yaml

[profile govcloud]
region=us-gov-east-1
output=yaml

[profile eastwest]
region=us-east-1
output=yaml

~/.aws/credentials

[default]
aws_access_key_id=<eastwest_access_key>
aws_secret_access_key=<eastwest_secret_key>

[govcloud]
aws_access_key_id=<govcloud_access_key>
aws_secret_access_key=<govcloud_secret_key>

[eastwest]
aws_access_key_id=<eastwest_access_key>
aws_secret_access_key=<eastwest_secret_key>

求助方向

怀疑存在未被发现的无效会话令牌,但暂未尝试删除~/.aws目录(目录下仅包含上述config和credentials文件)。请提供针对性的排查或解决建议。


内容的提问来源于stack exchange,提问作者aRustyDev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 11:09:57