You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

VSCode WSL环境下SAM调试遇AWS凭证缺失及SSO令牌无效问题

问题概述

在VSCode的WSL(Amazon Linux 2)环境配置SAM调试时,触发以下错误:

  • 调试启动时提示「SAM debug: missing AWS credentials (Toolkit is not connected)」和「SAM CLI not configured」
  • 手动执行sam local invoke --debug返回「Error loading SSO Token: The SSO access token has either expired or is otherwise invalid」

主机系统为Windows 11,已通过aws sso login完成AWS登录,但WSL环境无法正常复用主机的SSO凭证,此前在其他机器操作无需额外登录即可运行。

解决方案

1. 同步WSL与Windows的AWS配置及SSO缓存

WSL默认不会自动读取Windows的AWS配置文件,需手动指定路径:

  • 先确认Windows的AWS配置位置(通常在C:\Users\<你的Windows用户名>\.aws)
  • 在WSL终端执行以下命令临时生效:
    export AWS_CONFIG_FILE="/mnt/c/Users/<你的Windows用户名>/.aws/config"
    export AWS_SHARED_CREDENTIALS_FILE="/mnt/c/Users/<你的Windows用户名>/.aws/credentials"
    export AWS_SSO_CACHE_DIR="/mnt/c/Users/<你的Windows用户名>/.aws/sso/cache"
    
  • 如需永久生效,将上述命令添加到WSL的shell配置文件(如~/.bashrc或~/.zshrc):
    echo 'export AWS_CONFIG_FILE="/mnt/c/Users/<你的Windows用户名>/.aws/config"' >> ~/.bashrc
    echo 'export AWS_SHARED_CREDENTIALS_FILE="/mnt/c/Users/<你的Windows用户名>/.aws/credentials"' >> ~/.bashrc
    echo 'export AWS_SSO_CACHE_DIR="/mnt/c/Users/<你的Windows用户名>/.aws/sso/cache"' >> ~/.bashrc
    source ~/.bashrc
    

2. 刷新SSO凭证

即使主机已登录,WSL可能无法识别缓存的令牌,需重新登录:

  • 执行aws sso login --profile <你的SSO配置文件名称>(若未指定profile可省略--profile参数)
  • 验证凭证有效性:aws sts get-caller-identity,能返回用户身份信息即为正常

3. 配置VSCode AWS Toolkit

确保Toolkit能正确读取WSL中的AWS凭证:

  • 打开VSCode的AWS Toolkit扩展,点击左侧栏AWS图标
  • 选择「连接到AWS」,选择「使用现有AWS凭证」,确保Toolkit使用的是WSL中配置的Windows路径凭证
  • 建议直接在WSL终端中运行code .启动VSCode,让Toolkit自动继承WSL的环境变量

4. 初始化SAM CLI配置

解决「SAM CLI not configured」提示:

  • 执行sam configure,按照提示设置默认区域、关联的AWS profile等信息
  • 验证配置:sam configure list,确认输出包含正确的profile和region
调试日志参考

VSCode SAM调试日志

2023-01-27 19:42:44 [WARN]: SAM debug: missing AWS credentials (Toolkit is not connected)
2023-01-27 19:42:45 [INFO]: SAM CLI location: [object Object]
2023-01-27 19:42:46 [INFO]: SAM CLI location: [object Object]
2023-01-27 19:42:47 [INFO]: SAM CLI location: [object Object]
2023-01-27 19:42:47 [INFO]: SAM CLI location: [object Object]
2023-01-27 19:42:48 [INFO]: Preparing to debug locally: Lambda "HelloWorld::HelloWorld.Function::FunctionHandler"
2023-01-27 19:42:48 [INFO]: Building SAM application...
2023-01-27 19:42:48 [INFO]: SAM CLI location: [object Object]
2023-01-27 19:42:48 [INFO]: Command: (not started) [/usr/local/bin/sam build --build-dir /tmp/aws-toolkit-vscode/vsctkkE0arS/output --template /src/sample/template.yaml]
2023-01-27 19:42:48 [INFO]: SAM CLI not configured, using SAM found at: '/usr/local/bin/sam'
2023-01-27 19:42:54 [INFO]: Build complete.
2023-01-27 19:42:54 [INFO]: Installing .NET Core Debugger to /src/sample/src/HelloWorld/.vsdbg...
2023-01-27 19:42:56 [INFO]: Command: (not started) [/src/sample/src/HelloWorld/.vsdbg/installVsdbgScript.sh -v latest -r linux-x64 -l /src/sample/src/HelloWorld/.vsdbg]
2023-01-27 19:42:56 [INFO]: Starting SAM application locally
2023-01-27 19:42:56 [INFO]: SAM CLI location: [object Object]
2023-01-27 19:42:56 [INFO]: AWS.running.command
2023-01-27 19:42:56 [INFO]: SAM CLI not configured, using SAM found at: '/usr/local/bin/sam'
2023-01-27 19:42:56 [INFO]: Command: (not started) [/usr/local/bin/sam local invoke HelloWorldFunction --template /tmp/aws-toolkit-vscode/vsctkkE0arS/output/template.yaml -d 5858 --debugger-path /src/sample/src/HelloWorld/.vsdbg]
2023-01-27 19:42:58 [ERROR]: SamLaunchRequestError: Failed to run SAM application locally

SAM CLI手动执行日志

2023-01-27 19:49:24,748 | Config file location: /src/sample/samconfig.toml
2023-01-27 19:49:24,748 | Config file '/src/sample/samconfig.toml' does not exist
2023-01-27 19:49:24,752 | Using SAM Template at /src/sample/template.yaml
2023-01-27 19:49:24,854 | Using config file: samconfig.toml, config environment: default
2023-01-27 19:49:24,854 | Expand command line arguments to:
2023-01-27 19:49:24,854 | --template_file=/src/sample/template.yaml --no_event --layer_cache_basedir=/root/.aws-sam/layers-pkg --container_host=localhost --container_host_interface=127.0.0.1 
2023-01-27 19:49:24,854 | local invoke command is called
2023-01-27 19:49:24,858 | No Parameters detected in the template
2023-01-27 19:49:24,868 | There is no customer defined id or cdk path defined for resource HelloWorldFunction, so we will use the resource logical id as the resource id
2023-01-27 19:49:24,868 | There is no customer defined id or cdk path defined for resource ServerlessRestApi, so we will use the resource logical id as the resource id
2023-01-27 19:49:24,868 | 0 stacks found in the template
2023-01-27 19:49:24,868 | No Parameters detected in the template
2023-01-27 19:49:24,876 | There is no customer defined id or cdk path defined for resource HelloWorldFunction, so we will use the resource logical id as the resource id
2023-01-27 19:49:24,876 | There is no customer defined id or cdk path defined for resource ServerlessRestApi, so we will use the resource logical id as the resource id
2023-01-27 19:49:24,876 | 2 resources found in the stack 
2023-01-27 19:49:24,876 | Found Serverless function with name='HelloWorldFunction' and CodeUri='./src/HelloWorld/'
2023-01-27 19:49:24,876 | --base-dir is not presented, adjusting uri ./src/HelloWorld/ relative to /src/sample/template.yaml
2023-01-27 19:49:24,883 | Found one Lambda function with name 'HelloWorldFunction'
2023-01-27 19:49:24,883 | Invoking HelloWorld::HelloWorld.Function::FunctionHandler (dotnetcore3.1)
2023-01-27 19:49:24,883 | Loading AWS credentials from session with profile 'None'
2023-01-27 19:49:24,979 | Telemetry endpoint configured to be https://aws-serverless-tools-telemetry.us-west-2.amazonaws.com/metrics
2023-01-27 19:49:24,988 | Sending Telemetry: {'metrics': [{'commandRun': {'requestId': 'cf4207d7-0554-4bcf-9e05-1dda22ed4df8', 'installationId': 'fb284138-2b0f-4c16-98b3-b665990567fc', 'sessionId': 'fd097a74-adc6-42c5-a6cc-de3bceaadc9b', 'executionEnvironment': 'CLI', 'ci': False, 'pyversion': '3.7.10', 'samcliVersion': '1.71.0', 'awsProfileProvided': False, 'debugFlagProvided': True, 'region': '', 'commandName': 'sam local invoke', 'metricSpecificAttributes': {'projectType': 'CFN', 'gitOrigin': None, 'projectName': 'af2bdbe1aa9b6ec1e2ade1d694f41fc71a831d0268e9891562113d8a62add1bf', 'initialCommit': None}, 'duration': 125, 'exitReason': 'SSOTokenLoadError', 'exitCode': 255}}]}
2023-01-27 19:49:25,735 | HTTPSConnectionPool(host='aws-serverless-tools-telemetry.us-west-2.amazonaws.com', port=443): Read timed out. (read timeout=0.1)

Error: Error loading SSO Token: The SSO access token has either expired or is otherwise invalid.
Traceback:
  File "click/core.py", line 1055, in main
  File "click/core.py", line 1657, in invoke
  File "click/core.py", line 1657, in invoke
  File "click/core.py", line 1404, in invoke
  File "click/core.py", line 760, in invoke
  File "click/decorators.py", line 84, in new_func
  File "click/core.py", line 760, in invoke
  File "samcli/lib/telemetry/metric.py", line 183, in wrapped
  File "samcli/lib/telemetry/metric.py", line 150, in wrapped
  File "samcli/lib/utils/version_checker.py", line 41, in wrapped
  File "samcli/cli/main.py", line 92, in wrapper
  File "samcli/commands/local/invoke/cli.py", line 116, in cli
  File "samcli/commands/local/invoke/cli.py", line 202, in do_cli
  File "samcli/commands/local/lib/local_lambda.py", line 133, in invoke
  File "samcli/commands/local/lib/local_lambda.py", line 185, in get_invoke_config
  File "samcli/commands/local/lib/local_lambda.py", line 285, in _make_env_vars
  File "samcli/commands/local/lib/local_lambda.py", line 341, in get_aws_creds
  File "botocore/credentials.py", line 435, in access_key
  File "botocore/credentials.py", line 527, in _refresh
  File "botocore/credentials.py", line 543, in _protected_refresh
  File "botocore/credentials.py", line 684, in fetch_credentials
  File "botocore/credentials.py", line 694, in _get_cached_credentials
  File "botocore/credentials.py", line 2053, in _get_credentials
  File "botocore/utils.py", line 2679, in __call__

An unexpected error was encountered while executing "sam local invoke".
Search for an existing issue:
https://github.com/aws/aws-sam-cli/issues?q=is%3Aissue+is%3Aopen+Bug%3A%20sam%20local%20invoke%20-%20SSOTokenLoadError
Or create a bug report:
https://github.com/aws/aws-sam-cli/issues/new?template=Bug_report.md&amp;title=Bug%3A%20sam%20local%20invoke%20-%20SSOTokenLoadError

内容的提问来源于stack exchange,提问作者tone

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 18:05:48