You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用aws-java-sdk创建VPC终端节点时遇InvalidServiceName错误求助

排查AWS Java SDK创建VPC终端节点时的InvalidServiceName错误

我正尝试使用AWS Java SDK的com.amazonaws.services.ec2.model.CreateVpcEndpointRequest API在私有子网中创建VPC终端节点,但遇到以下错误:

error": "com.amazonaws.services.ec2.model.AmazonEC2Exception: The Vpc Endpoint Service 'com.amazonaws.vpce.us-west-2.vpce-svc-***' does not exist (Service: AmazonEC2; Status Code: 400; Error Code: InvalidServiceName; Request ID: ***; Proxy: null)"

已知情况

  • 该VPCE服务已添加允许的主体,并配置为自动接受连接请求
  • 手动针对同一VPCE服务可以创建VPC终端节点
  • 代码在其他账号/VPCE服务/VPC/子网环境中可正常运行,仅当前特定环境出现问题

代码片段

createVpcEndpointRequest request = new CreateVpcEndpointRequest()
        .withPrivateDnsEnabled(privateDns)
        .withSecurityGroupIds(Collections.singleton(securityGroupId))
        // VPCE Service
        .withVpcEndpointType(VpcEndpointType.Interface.toString())
        .withServiceName(privatelinkServiceName)
        // Network
        .withVpcId(vpcId)
        .withSubnetIds(subnetIds);
createVpcEndpointResult = ec2Client.createVpcEndpoint(request);

排查方向

  • 校验服务名称准确性:确认privatelinkServiceName与目标VPCE服务的完整名称完全一致,注意大小写、区域后缀(us-west-2)及vpce-svc的ID部分,避免字符遗漏或拼写错误。
  • 检查EC2客户端区域配置:确保ec2Client已正确配置为VPCE服务所在的区域(us-west-2),客户端区域不匹配会导致无法识别服务。
  • 验证账号权限与访问权限:检查运行代码的IAM身份是否拥有ec2:CreateVpcEndpoint权限,同时确认该账号已被添加到VPCE服务的允许主体列表中,排查是否存在IAM策略或账号级别的访问限制。
  • 确认子网与VPC归属:验证传入的子网ID确实属于指定的VPC,且该VPC与VPCE服务处于同一区域——接口型VPC终端节点不支持跨区域创建。
  • 检查VPCE服务状态:通过AWS控制台或describeVpcEndpointServices API确认目标VPCE服务处于可用状态,未被删除或故障。
  • 核对终端节点类型匹配:确保代码中指定的Interface类型与目标VPCE服务的类型一致,类型不匹配会导致服务识别失败。

内容的提问来源于stack exchange,提问作者Kedarnath

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 21:33:13