You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何自动化更新npm的AWS CodeArtifact认证令牌?

自动化更新AWS CodeArtifact认证令牌的实用方案

方案1:Shell函数按需检查更新(推荐)

这个方案只会在令牌过期或不存在时执行生成命令,避免每次打开终端都触发不必要的请求。

  1. 创建令牌更新脚本(比如~/.codeartifact_token_updater.sh),填入你的CodeArtifact配置:
#!/bin/bash

# 替换成你的CodeArtifact参数
DOMAIN="your-domain"
DOMAIN_OWNER="your-account-id"
REPOSITORY="your-repo"
REGION="your-region"

# 令牌和过期时间的存储路径
TOKEN_FILE="$HOME/.codeartifact_token"
EXPIRE_FILE="$HOME/.codeartifact_token_expire"

# 检查令牌是否有效
check_token_validity() {
    if [ ! -f "$TOKEN_FILE" ] || [ ! -f "$EXPIRE_FILE" ]; then
        return 1
    fi

    CURRENT_TIME=$(date +%s)
    EXPIRE_TIME=$(cat "$EXPIRE_FILE")

    [ "$CURRENT_TIME" -ge "$EXPIRE_TIME" ] && return 1 || return 0
}

# 生成并保存新令牌
update_token() {
    TOKEN=$(aws codeartifact get-authorization-token --domain "$DOMAIN" --domain-owner "$DOMAIN_OWNER" --region "$REGION" --query authorizationToken --output text)
    if [ $? -ne 0 ]; then
        echo "CodeArtifact令牌生成失败"
        return 1
    fi

    # 计算12小时后的过期时间
    EXPIRE_TIME=$(($(date +%s) + 43200))
    echo "$TOKEN" > "$TOKEN_FILE"
    echo "$EXPIRE_TIME" > "$EXPIRE_FILE"

    # 加载令牌到环境变量
    export CODEARTIFACT_AUTH_TOKEN="$TOKEN"

    # 可选:自动更新包管理器配置(以pip为例)
    # echo "[global]" > ~/.pip/pip.conf
    # echo "extra-index-url = https://aws:$TOKEN@$DOMAIN-$DOMAIN_OWNER.d.codeartifact.$REGION.amazonaws.com/pypi/$REPOSITORY/simple/" >> ~/.pip/pip.conf
}

# 对外暴露的触发函数
ensure_codeartifact_token() {
    if ! check_token_validity; then
        update_token
    fi
    export CODEARTIFACT_AUTH_TOKEN=$(cat "$TOKEN_FILE")
}
  1. 给脚本添加执行权限:
chmod +x ~/.codeartifact_token_updater.sh
  1. 在~/.bashrc(或~/.zshrc)中加载脚本,可选在终端启动时预检查一次:
source ~/.codeartifact_token_updater.sh
# 终端启动时自动检查令牌状态(可选)
ensure_codeartifact_token
  1. 包装常用的包管理器命令,比如pip,让它每次执行前自动校验令牌:
alias pip='ensure_codeartifact_token && pip'

这样每次用pip拉取CodeArtifact依赖时,都会自动确保令牌有效,完全无需手动操作。

方案2:Cron定时自动更新

如果需要令牌始终保持有效(即使没有打开终端),可以用cron每11小时执行一次更新(比12小时短,避免出现过期间隙)。

  1. 编写定时更新脚本~/.codeartifact_cron_updater.sh:
#!/bin/bash

DOMAIN="your-domain"
DOMAIN_OWNER="your-account-id"
REGION="your-region"
TOKEN_FILE="$HOME/.codeartifact_token"

TOKEN=$(aws codeartifact get-authorization-token --domain "$DOMAIN" --domain-owner "$DOMAIN_OWNER" --region "$REGION" --query authorizationToken --output text)
if [ $? -eq 0 ]; then
    echo "$TOKEN" > "$TOKEN_FILE"
fi
  1. 添加执行权限:
chmod +x ~/.codeartifact_cron_updater.sh
  1. 编辑crontab任务:
crontab -e
  1. 添加定时规则(每11小时执行一次):
0 */11 * * * /bin/bash ~/.codeartifact_cron_updater.sh
  1. 在~/.bashrc中添加令牌加载逻辑:
if [ -f "$HOME/.codeartifact_token" ]; then
    export CODEARTIFACT_AUTH_TOKEN=$(cat "$HOME/.codeartifact_token")
fi

这样每次打开终端都会自动加载最新的令牌,cron则负责后台定时更新。

注意事项

  • 确保AWS CLI已配置足够权限,能正常调用codeartifact get-authorization-token命令(可通过aws configure或IAM角色配置)。
  • 不同包管理器(npm、maven等)的令牌配置方式不同,需根据工具文档调整脚本中的配置逻辑。
  • 方案1更轻量,仅在需要时更新;方案2适合需要令牌持续有效的场景,但要注意cron的环境变量与终端可能存在差异,需确保AWS CLI在cron环境中能正常运行。

内容的提问来源于stack exchange,提问作者john sity

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 00:52:31