You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Node.js 18 AWS Lambda结合AWS SDK v3执行Neptune的openCypher查询?

解决AWS Lambda向Neptune发送openCypher查询的问题

你之前使用@aws-sdk/client-neptune的方向有误——这个SDK是用于管理Neptune资源(如创建、配置实例)的管理类API,并不提供执行查询的接口。要向Neptune发送openCypher查询,需要直接向Neptune的专属HTTP端点发送请求,并通过IAM签名完成身份认证。

以下是修改后的可运行Lambda代码,包含从SSM参数存储获取Neptune端点的逻辑:

import { SignatureV4 } from "@aws-sdk/signature-v4";
import { Sha256 } from "@aws-crypto/sha256-browser";
import { SSMClient, GetParameterCommand } from "@aws-sdk/client-ssm";

// 初始化SSM客户端
const ssmClient = new SSMClient({ region: "us-east-1" });

export async function handler() {
    try {
        // 1. 从SSM参数存储获取Neptune端点(替换为你的参数名称)
        const ssmCommand = new GetParameterCommand({
            Name: "/neptune/db-endpoint",
            WithDecryption: false // 如果参数未加密可设为false
        });
        const ssmResponse = await ssmClient.send(ssmCommand);
        const neptuneEndpoint = ssmResponse.Parameter.Value; // 格式应为 https://<instance-id>.us-east-1.neptune.amazonaws.com:8182

        // 2. 构造openCypher查询
        const cypherQuery = `MATCH (n) RETURN n LIMIT 10`; // 限制返回数量避免数据过大
        const requestBody = JSON.stringify({ query: cypherQuery });

        // 3. 生成IAM签名
        const signer = new SignatureV4({
            credentials: {
                accessKeyId: process.env.AWS_ACCESS_KEY_ID,
                secretAccessKey: process.env.AWS_SECRET_ACCESS_KEY,
                sessionToken: process.env.AWS_SESSION_TOKEN
            },
            region: "us-east-1",
            service: "neptune-db",
            sha256: Sha256
        });

        const signedRequest = await signer.sign({
            method: "POST",
            hostname: new URL(neptuneEndpoint).hostname,
            path: "/openCypher",
            protocol: "https:",
            headers: {
                "Content-Type": "application/json",
                "Host": new URL(neptuneEndpoint).hostname
            },
            body: requestBody
        });

        // 4. 发送查询请求
        const response = await fetch(`${neptuneEndpoint}/openCypher`, {
            method: "POST",
            headers: signedRequest.headers,
            body: requestBody
        });

        if (!response.ok) {
            throw new Error(`Neptune request failed: ${response.statusText}`);
        }

        const result = await response.json();
        console.log("查询结果:", result);
        return {
            statusCode: 200,
            body: JSON.stringify(result)
        };
    } catch (error) {
        console.error("执行出错:", error);
        return {
            statusCode: 500,
            body: JSON.stringify({ error: error.message })
        };
    }
}

关键注意事项:

  • 端口与端点格式:Neptune的HTTPS查询端口默认是8182,确保SSM中存储的端点包含端口(如https://xxxx.us-east-1.neptune.amazonaws.com:8182)
  • 安全组配置:确保Neptune实例的安全组允许Lambda所在VPC的8182端口(HTTPS)入站访问
  • IAM权限:NeptuneFullAccess策略已包含neptune-db:*权限,允许执行查询操作
  • 依赖安装:需要在Lambda部署包中包含以下依赖:@aws-sdk/signature-v4、@aws-crypto/sha256-browser、@aws-sdk/client-ssm——可以通过npm安装后打包,或使用Lambda层

内容的提问来源于stack exchange,提问作者Mor Sagmon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 19:50:18