AWS Lambda访问Azure私有Wiki出现连接超时问题求助
问题描述
作为项目管理员,我尝试用AWS Lambda访问Azure私有Wiki,编写的Python代码如下:
import requests import base64 def lambda_handler(event, context): # Replace with your own Azure DevOps organization name organization_name = "name of the organization" # Replace with the project name that contains the wiki project_name = "project name" # Replace with the name of the wiki wiki_name = "wiki name" # Replace with the version of the wiki to retrieve wiki_version = "1234" # Replace with your own personal access token (PAT) personal_access_token = "my pat" # Build the URL to retrieve the wiki content url = f"https://dev.azure.com/{organization_name}/{project_name}/_apis/wiki/wikis/{wiki_name}/{wiki_version}/content?api-version=7.0" # Set the authorization header with the base64-encoded PAT auth_header = f"Basic {base64.b64encode(f'{personal_access_token}'.encode('utf-8')).decode('utf-8')}" headers = { "Authorization": auth_header, "Accept": "application/json" } # Make the request to retrieve the wiki content response = requests.get(url, headers=headers) # Return the response if successful, otherwise return an error message if response.status_code == 200: return response.json() else:
该Lambda配置了允许所有出入流量的安全组与公网子网,角色权限宽松,但始终收到连接超时错误:
"[ERROR] ConnectionError: HTTPSConnectionPool(host='dev.azure.com', port=443): Max retries exceeded with url:xxxxx (Caused by NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x7f405ba34790>: Failed to establish a new connection: [Errno 110] Connection timed out'))"
已尝试调整权限、更换Lambda角色及使用全权限PAT,仍未解决,寻求排查方案。
排查方案
- 验证Lambda网络连通性
- 在Lambda中执行简单公网测试,比如请求
https://www.google.com,确认是否能正常建立连接。若连公网都不通,说明Lambda网络配置存在问题:检查公网子网是否关联Internet Gateway(IGW),子网路由表是否包含0.0.0.0/0指向IGW的默认路由;同时确认子网的网络访问控制列表(NACL)允许出站443端口流量。
- 在Lambda中执行简单公网测试,比如请求
- 检查Azure DevOps网络限制
- 确认Azure DevOps组织是否设置了IP白名单限制,若有则需将Lambda的出口IP加入白名单;可临时关闭IP限制测试是否能正常访问。
- 确认dev.azure.com服务状态正常,无区域性故障。
- 修复代码细节
- 补全else分支逻辑,返回错误信息便于调试:
else: return { 'statusCode': response.status_code, 'error': response.text } - 修正Basic认证格式:Azure DevOps的Basic认证需要
用户名:PAT的base64编码,允许用户名为空,因此正确的编码应为base64.b64encode(f':{personal_access_token}'.encode('utf-8')).decode('utf-8')(注意开头的冒号)。 - 给requests添加超时参数并开启debug日志:
import logging logging.basicConfig(level=logging.DEBUG) # 请求时添加超时 response = requests.get(url, headers=headers, timeout=10)
- 补全else分支逻辑,返回错误信息便于调试:
- 排查DNS解析问题
- 在Lambda中添加DNS测试代码,检查是否能正常解析dev.azure.com:
若解析失败,检查VPC的DNS服务器配置是否正确,确保能正常解析公网域名。import socket try: ip = socket.gethostbyname('dev.azure.com') print(f"Resolved dev.azure.com to {ip}") except socket.gaierror as e: print(f"DNS resolution failed: {e}")
- 在Lambda中添加DNS测试代码,检查是否能正常解析dev.azure.com:
- 规范敏感信息存储
- 避免将PAT硬编码在代码中,改用Lambda环境变量存储,提升安全性且便于修改。
内容的提问来源于stack exchange,提问作者gbrl
相关产品推荐
相关产品推荐

