You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS SSO配置Boto3免手动粘贴临时凭证问题求助

解决Boto3无法读取AWS SSO凭证的问题

核心原因

Boto3默认不会自动读取aws configure sso生成的SSO配置,需要额外配置让它自动获取临时凭证,或先通过CLI将凭证存入标准凭证文件。

具体解决方法

方法1:让Boto3直接使用SSO配置(推荐)

  1. 升级依赖版本
    旧版本Boto3/botocore不支持SSO自动凭证获取,执行升级命令:
pip install --upgrade boto3 botocore
  1. 代码中指定SSO配置文件
    无需手动粘贴凭证,直接加载~/.aws/config中的SSO profile:
import boto3

# 替换为你在aws configure sso时设置的profile名称
session = boto3.Session(profile_name="your-sso-profile-name")
s3 = session.client('s3')

# 测试调用
response = s3.list_buckets()
print("存储桶列表:", [bucket['Name'] for bucket in response['Buckets']])

首次运行会弹出浏览器引导SSO登录,登录成功后凭证会缓存到~/.aws/sso/cache/,后续运行无需重复操作。

方法2:通过CLI预导出临时凭证

如果需要兼容旧版本依赖,可先通过CLI获取凭证并存入~/.aws/credentials:

  1. 执行SSO登录
aws sso login --profile your-sso-profile-name

登录成功后临时凭证会被缓存。

  1. 导出凭证到标准文件
    Linux/macOS下执行:
aws configure export-credentials --profile your-sso-profile-name --format ini >> ~/.aws/credentials

之后Boto3就能像读取普通凭证一样加载这些临时凭证,有效期内无需重复操作。

排查要点

  • 检查~/.aws/config中的profile配置,确保包含以下关键字段:
    [profile your-sso-profile-name]
    sso_start_url = https://你的AWS SSO启动地址.awsapps.com/start
    sso_region = 你的SSO区域(如us-east-1)
    sso_account_id = 你的企业AWS账户ID
    sso_role_name = 你被授予的SSO角色名
    region = 你的默认服务区域
    
  • 确保~/.aws/目录权限正确:执行chmod 700 ~/.aws/,chmod 600 ~/.aws/config ~/.aws/credentials,避免权限过高导致凭证无法读取。
  • 确认当前运行环境的Boto3是目标版本,虚拟环境下需检查是否安装在当前虚拟环境内。

内容的提问来源于stack exchange,提问作者Bunny Talks

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 06:28:17