使用Amazon SES V2发送邮件遇WebIdentityTokenCredentialsProvider依赖错误
解决Amazon SES V2使用WebIdentityTokenCredentialsProvider时的STS依赖问题
问题描述
尝试使用Amazon SES V2发送邮件,计划通过WebIdentityTokenCredentialsProvider获取凭证,但运行时报错:
To use web identity tokens, the 'sts' service module must be on the class path.
当前Maven依赖
<dependency> <groupId>software.amazon.awssdk</groupId> <artifactId>bom</artifactId> <version>2.17.288</version> <type>pom</type> <scope>runtime</scope> </dependency> <dependency> <groupId>software.amazon.awssdk</groupId> <artifactId>sesv2</artifactId> <version>2.17.288</version> </dependency> <dependency> <groupId>com.amazonaws</groupId> <artifactId>aws-java-sdk-sts</artifactId> </dependency>
Java代码实现
package com.company.core.service.util.email.sender; import javax.annotation.PostConstruct; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import org.springframework.stereotype.Service; import software.amazon.awssdk.services.sesv2.SesV2Client; import software.amazon.awssdk.services.sesv2.model.*; @Service public class CompanySesClient { private static final Logger LOG = LoggerFactory.getLogger(CompanySesClient.class); private final SesV2Client client = SesV2Client.builder().build(); @PostConstruct public void testSendMail(){ try{ LOG.info("about to try to send mail"); sendEmail("test@noreply.staging.test.com","abc@abc.com", "test subject", "test body"); LOG.info("Sucess to send mail"); }catch (Throwable error){ LOG.error("failed to send mail with error,"+error.getMessage(), error.getMessage() , error.getStackTrace()); } } public void sendEmail(String sender, String recipient, String emailSubject, String emailBody) { final Destination destination = Destination.builder() .toAddresses(recipient) .build(); final EmailContent emailContent = getEmailContent(emailSubject, emailBody); final SendEmailRequest emailRequest = SendEmailRequest.builder() .destination(destination) .content(emailContent) .fromEmailAddress(sender) .build(); try { LOG.info("Attempting to send an email through Amazon SES " + "using the AWS SDK for Java..."); client.sendEmail(emailRequest); LOG.info("email was sent"); } catch (SesV2Exception e) { LOG.error("email sent error:" + e.awsErrorDetails().errorMessage()); throw e; } } private static EmailContent getEmailContent(String emailSubject, String emailBody) { final Content subject = Content.builder() .data(emailSubject) .build(); final Content content = Content.builder() .data(emailBody) .build(); final Body body = Body.builder() .html(content) .build(); final Message msg = Message.builder() .subject(subject) .body(body) .build(); final EmailContent emailContent = EmailContent.builder() .simple(msg) .build(); return emailContent; } }
错误堆栈信息
failed to send mail with error,Unable to load credentials from any of the providers in the chain AwsCredentialsProviderChain(credentialsProviders=[SystemPropertyCredentialsProvider(), EnvironmentVariableCredentialsProvider(), WebIdentityTokenCredentialsProvider(), ProfileCredentialsProvider(profileName=default, profileFile=ProfileFile(profilesAndSectionsMap=[])), ContainerCredentialsProvider(),InstanceProfileCredentialsProvider()]) : [SystemPropertyCredentialsProvider(): Unable to load credentials from system settings.Access key must be specified either via environment variable (AWS_ACCESS_KEY_ID) or system property (aws.accessKeyId).,,EnvironmentVariableCredentialsProvider(): Unable to load credentials from system settings. Access key must be specified either via environment variable (AWS_ACCESS_KEY_ID) or system property (aws.accessKeyId)., WebIdentityTokenCredentialsProvider(): To use web identity tokens,the 'sts' service module must be on the class path., ProfileCredentialsProvider(profileName=default,profileFile=ProfileFile(profilesAndSectionsMap=[])): Profile file contained no credentials for profile 'default': ProfileFile(profilesAndSectionsMap=[]), ContainerCredentialsProvider(): Cannot fetch credentials from container - neither AWS_CONTAINER_CREDENTIALS_FULL_URI or AWS_CONTAINER_CREDENTIALS_RELATIVE_URI environment variables are set., InstanceProfileCredentialsProvider(): Failed to load credentials from IMDS.]
已尝试的无效方案
添加了如下依赖但未解决问题:
<dependency> <groupId>software.amazon.awssdk</groupId> <artifactId>sts</artifactId> <version>2.17.288</version> <scope>test</scope> </dependency>
有效解决方案
1. 清理冲突依赖
移除AWS SDK V1的STS依赖:com.amazonaws:aws-java-sdk-sts,当前使用的是AWS SDK V2,V1依赖不仅无效,还可能引发版本冲突。
2. 添加正确的V2 STS依赖
添加AWS SDK V2的STS模块依赖,必须移除scope=test,因为运行时需要加载该模块:
<dependency> <groupId>software.amazon.awssdk</groupId> <artifactId>sts</artifactId> <version>2.17.288</version> </dependency>
3. 可选:显式配置凭证提供者
如果需要明确指定使用WebIdentityTokenCredentialsProvider,可以在构建SesV2Client时显式配置:
private final SesV2Client client = SesV2Client.builder() .credentialsProvider(WebIdentityTokenCredentialsProvider.create()) .build();
4. 验证环境变量
确保运行环境已设置WebIdentityTokenCredentialsProvider所需的环境变量:
AWS_WEB_IDENTITY_TOKEN_FILE:指向包含Web身份令牌的文件路径AWS_ROLE_ARN:要假定的IAM角色ARN
内容的提问来源于stack exchange,提问作者Hard Worker
相关产品推荐
相关产品推荐

