配置K8s连接AWS时遇身份验证错误及AWS凭证无效问题求助
问题排查:Kubectl连接AWS EKS凭证错误 & AWS STS身份验证失败
问题现象
- 执行
kubectl get svc时反复报错:
jackma@jackma-MacBook-Pro ~ % kubectl get svc E0202 23:58:23.323851 66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E0202 23:58:23.822265 66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E0202 23:58:24.300791 66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E0202 23:58:24.794799 66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E0202 23:58:25.279269 66169 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials error: You must be logged in to the server (the server has asked for the client to provide credentials)
- 执行
aws sts get-caller-identity --profile default验证凭证时返回错误:
jackma@jackma-MacBook-Pro ~ % aws sts get-caller-identity --profile default An error occurred (InvalidClientTokenId) when calling the GetCallerIdentity operation: The security token included in the request is invalid.
已删除~/.aws/credentials并重新执行aws configure配置凭证,但问题未解决,当前默认凭证内容:
[default] aws_access_key_id = ZSIB2NADXYH5MTSQ29X4 aws_secret_access_key = Wcnlg1GC8zBTuyIMoAheRKDycypSRTGjjcVWTHZv
排查步骤
1. 确认AWS凭证的有效性
- 核对Access Key ID和Secret Access Key是否与AWS控制台生成的完全一致:注意大小写、首尾空格、特殊字符,避免复制粘贴时引入错误。
- 登录AWS控制台,进入IAM → 用户 → 对应用户 → 安全凭证,查看该访问密钥的状态是否为「活跃」,若已禁用则启用或直接删除生成新密钥。
- 直接在IAM控制台生成新的访问密钥,替换现有凭证后重新执行
aws configure,再测试aws sts get-caller-identity --profile default。
2. 检查凭证来源的优先级冲突
系统可能存在多个凭证来源,优先级高于~/.aws/credentials:
- 检查环境变量:执行
echo $AWS_ACCESS_KEY_ID和echo $AWS_SECRET_ACCESS_KEY,若输出非空,执行unset AWS_ACCESS_KEY_ID和unset AWS_SECRET_ACCESS_KEY清除环境变量凭证。 - 检查
~/.aws/config文件:确认是否存在冲突的profile配置,比如错误指定了credential_source或region,可临时重命名该文件测试。 - 若在EC2实例上操作:执行
export AWS_EC2_METADATA_DISABLED=true禁用实例元数据凭证,避免角色凭证干扰。
3. 修复Kubectl的kubeconfig配置
- 查看当前kubeconfig内容:
cat ~/.kube/config,找到对应EKS集群的user配置段,确认是否通过exec调用aws eks get-token,且指定了正确的--profile default。 - 手动生成EKS访问令牌:
aws eks get-token --cluster-name <你的EKS集群名称> --profile default,若报错则回到凭证问题排查;若成功,更新kubeconfig:aws eks update-kubeconfig --cluster-name <你的EKS集群名称> --profile default。
4. 更新AWS CLI版本
旧版本AWS CLI可能存在兼容性问题,执行aws --version查看版本,MacOS用户可通过brew upgrade awscli更新,其他系统使用对应包管理器更新到最新稳定版。
内容的提问来源于stack exchange,提问作者AKALawrence
相关产品推荐
相关产品推荐

