Docker中NestJS调用AWS SDK S3 V3报NoSuchKey错误的解决
Docker容器中NestJS应用使用AWS SDK S3 V3遇NoSuchKey错误的解决
问题场景
在Docker容器内运行基于Node.js的NestJS应用时,使用AWS SDK S3 V3调用ListObjectsCommand获取S3对象,持续抛出「The specified key does not exist」(NoSuchKey)错误。
初始配置与尝试
最初通过fromIni方法加载本地~/.aws/credentials和config文件中的default配置凭证,Dockerfile已将本地.aws目录文件复制到容器内,尝试修改profile名称、省略文件路径等操作均未解决问题。
原始S3Client初始化代码
private client = new S3Client({ credentials: fromIni({ profile: 'default', filepath: '~/.aws/credentials', configFilepath: '~/.aws/config', }), region: this.bucketRegion, });
Dockerfile相关配置
RUN mkdir -p /root/.aws COPY --from=builder /root/.aws/credentials /root/.aws/credentials COPY --from=builder /root/.aws/config /root/.aws/config RUN ls -la /root/.aws RUN whoami
错误日志片段
[Nest] 1 - 02/16/2023, 11:40:15 AM ERROR [ExceptionsHandler] The specified key does not exist. NoSuchKey: The specified key does not exist. ...
解决方法
直接在S3Client构造函数中传入accessKeyId和secretAccessKey参数,绕过fromIni加载凭证的逻辑,问题得到解决。
修改后的S3Client初始化代码
private client = new S3Client({ credentials: { accessKeyId: this.configService.get('AWS_S3_ACCESS_KEY_ID'), secretAccessKey: this.configService.get('AWS_S3_SECRET_ACCESS_KEY'), }, region: this.bucketRegion, });
总结
推测问题根源在于容器内fromIni方法加载凭证文件时存在路径解析或权限问题,导致凭证未正确加载,进而触发S3权限验证相关的NoSuchKey错误(该错误有时会在凭证无效时误抛出)。直接传入密钥参数可绕过文件加载环节,确保凭证正确注入。
内容的提问来源于stack exchange,提问作者BertC
相关产品推荐
相关产品推荐

