You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置K8s连接AWS时遇身份验证错误及AWS凭证无效问题求助

问题排查:Kubectl连接AWS EKS凭证错误 & AWS STS身份验证失败

问题现象

  1. 执行kubectl get svc时反复报错:
jackma@jackma-MacBook-Pro ~ %  kubectl get svc                              
E0202 23:58:23.323851   66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
E0202 23:58:23.822265   66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
E0202 23:58:24.300791   66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
E0202 23:58:24.794799   66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
E0202 23:58:25.279269   66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
error: You must be logged in to the server (the server has asked for the client to provide credentials)
  1. 执行aws sts get-caller-identity --profile default验证凭证时返回错误:
jackma@jackma-MacBook-Pro ~ % aws sts get-caller-identity --profile default                                               

An error occurred (InvalidClientTokenId) when calling the GetCallerIdentity operation: The security token included in the request is invalid.

已删除~/.aws/credentials并重新执行aws configure配置凭证,但问题未解决,当前默认凭证内容:

[default]
aws_access_key_id = ZSIB2NADXYH5MTSQ29X4
aws_secret_access_key = Wcnlg1GC8zBTuyIMoAheRKDycypSRTGjjcVWTHZv

排查步骤

1. 确认AWS凭证的有效性

  • 核对Access Key ID和Secret Access Key是否与AWS控制台生成的完全一致:注意大小写、首尾空格、特殊字符,避免复制粘贴时引入错误。
  • 登录AWS控制台,进入IAM → 用户 → 对应用户 → 安全凭证,查看该访问密钥的状态是否为「活跃」,若已禁用则启用或直接删除生成新密钥。
  • 直接在IAM控制台生成新的访问密钥,替换现有凭证后重新执行aws configure,再测试aws sts get-caller-identity --profile default。

2. 检查凭证来源的优先级冲突

系统可能存在多个凭证来源,优先级高于~/.aws/credentials:

  • 检查环境变量:执行echo $AWS_ACCESS_KEY_ID和echo $AWS_SECRET_ACCESS_KEY,若输出非空,执行unset AWS_ACCESS_KEY_ID和unset AWS_SECRET_ACCESS_KEY清除环境变量凭证。
  • 检查~/.aws/config文件:确认是否存在冲突的profile配置,比如错误指定了credential_source或region,可临时重命名该文件测试。
  • 若在EC2实例上操作:执行export AWS_EC2_METADATA_DISABLED=true禁用实例元数据凭证,避免角色凭证干扰。

3. 修复Kubectl的kubeconfig配置

  • 查看当前kubeconfig内容:cat ~/.kube/config,找到对应EKS集群的user配置段,确认是否通过exec调用aws eks get-token,且指定了正确的--profile default。
  • 手动生成EKS访问令牌:aws eks get-token --cluster-name <你的EKS集群名称> --profile default,若报错则回到凭证问题排查;若成功,更新kubeconfig:aws eks update-kubeconfig --cluster-name <你的EKS集群名称> --profile default。

4. 更新AWS CLI版本

旧版本AWS CLI可能存在兼容性问题,执行aws --version查看版本,MacOS用户可通过brew upgrade awscli更新,其他系统使用对应包管理器更新到最新稳定版。


内容的提问来源于stack exchange,提问作者AKALawrence

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 13:01:11