You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ARN调用boto3 get_secret_value接口报错,如何通过ARN获取密钥?

问题描述

AWS Secrets Manager文档说明,get_secret_value接口的SecretId参数支持传入密钥的完整ARN或名称,但调用时传入ARN却触发ValidationException错误:

Invalid name. Must be a valid name containing alphanumeric characters, or any of the following: -/_+=.@!

调用代码如下:

import boto3

boto3.client("secretsmanager").get_secret_value(SecretId="arn:aws:secretsmanager:us-east-1:260890374087:secret/Datadog/ApiKey-s3xUqf")

对应的错误回溯信息:

Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
  File "/Library/Python/3.9/site-packages/botocore/client.py", line 530, in _api_call
    return self._make_api_call(operation_name, kwargs)
  File "/Library/Python/3.9/site-packages/botocore/client.py", line 960, in _make_api_call
    raise error_class(parsed_response, operation_name)
botocore.exceptions.ClientError: An error occurred (ValidationException) when calling the GetSecretValue operation: Invalid name. Must be a valid name containing alphanumeric characters, or any of the following: -/_+=.@!
解决方案

错误根源是ARN格式错误:secret与密钥名称之间需用**冒号(:)**分隔,而非斜杠(/)。SDK会将格式错误的ARN识别为普通密钥名称,而名称不允许使用路径式斜杠结构,因此触发验证失败。

修正后的调用代码:

import boto3

boto3.client("secretsmanager").get_secret_value(SecretId="arn:aws:secretsmanager:us-east-1:260890374087:secret:Datadog/ApiKey-s3xUqf")

建议直接从AWS控制台或执行aws secretsmanager describe-secret --secret-id <密钥名称>命令复制返回的完整ARN,避免手动输入时出现格式错误。

内容的提问来源于stack exchange,提问作者Paul Draper

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 18:33:29