AWS SSO配置Boto3免手动粘贴临时凭证问题求助
解决Boto3无法读取AWS SSO凭证的问题
核心原因
Boto3默认不会自动读取aws configure sso生成的SSO配置,需要额外配置让它自动获取临时凭证,或先通过CLI将凭证存入标准凭证文件。
具体解决方法
方法1:让Boto3直接使用SSO配置(推荐)
- 升级依赖版本
旧版本Boto3/botocore不支持SSO自动凭证获取,执行升级命令:
pip install --upgrade boto3 botocore
- 代码中指定SSO配置文件
无需手动粘贴凭证,直接加载~/.aws/config中的SSO profile:
import boto3 # 替换为你在aws configure sso时设置的profile名称 session = boto3.Session(profile_name="your-sso-profile-name") s3 = session.client('s3') # 测试调用 response = s3.list_buckets() print("存储桶列表:", [bucket['Name'] for bucket in response['Buckets']])
首次运行会弹出浏览器引导SSO登录,登录成功后凭证会缓存到~/.aws/sso/cache/,后续运行无需重复操作。
方法2:通过CLI预导出临时凭证
如果需要兼容旧版本依赖,可先通过CLI获取凭证并存入~/.aws/credentials:
- 执行SSO登录
aws sso login --profile your-sso-profile-name
登录成功后临时凭证会被缓存。
- 导出凭证到标准文件
Linux/macOS下执行:
aws configure export-credentials --profile your-sso-profile-name --format ini >> ~/.aws/credentials
之后Boto3就能像读取普通凭证一样加载这些临时凭证,有效期内无需重复操作。
排查要点
- 检查
~/.aws/config中的profile配置,确保包含以下关键字段:[profile your-sso-profile-name] sso_start_url = https://你的AWS SSO启动地址.awsapps.com/start sso_region = 你的SSO区域(如us-east-1) sso_account_id = 你的企业AWS账户ID sso_role_name = 你被授予的SSO角色名 region = 你的默认服务区域 - 确保
~/.aws/目录权限正确:执行chmod 700 ~/.aws/,chmod 600 ~/.aws/config ~/.aws/credentials,避免权限过高导致凭证无法读取。 - 确认当前运行环境的Boto3是目标版本,虚拟环境下需检查是否安装在当前虚拟环境内。
内容的提问来源于stack exchange,提问作者Bunny Talks
相关产品推荐
相关产品推荐

