You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot集成AWS Secrets Manager报错:找不到指定密钥

问题:LocalStack模拟AWS环境下Spring Boot读取Secrets Manager密钥报ResourceNotFoundException

在Spring Boot项目中用LocalStack模拟AWS环境,尝试从Secrets Manager获取指定密钥时触发ResourceNotFoundException,已通过脚本成功创建密钥且能通过list-secrets查询到,但项目运行时仍报错。

相关配置与代码

1. docker-compose LocalStack配置片段

localstack:
    image: localstack/localstack:latest
    environment:
      - SERVICES=s3
      - EDGE_PORT=4566
      - AWS_ACCESS_KEY_ID=test
      - AWS_SECRET_ACCESS_KEY=test
      - AWS_DEFAULT_REGION=eu-west-3
    ports:
      - '4566-4597:4566-4597'
    volumes:
      - "${TMPDIR:-/tmp/localstack}:/tmp/localstack"

2. application.properties配置

cloud.aws.end-point.uri=http://s3.localhost.localstack.cloud:4566/
cloud.aws.secrets-manager.end-point.uri=http://localhost:4566  # 对应代码中的secretManagerUrl
s3.bucket.base.url=http://bucketnameproject.s3.localhost.localstack.cloud:4566/

3. AWSConfiguration类init方法代码

public void init() throws JsonProcessingException {
        String secretName = "aws/secret";
        String region = "eu-west-3";

        AWSSecretsManager client = AWSSecretsManagerClientBuilder.standard()
                .withEndpointConfiguration(new EndpointConfiguration(secretManagerUrl, region))
                .build();

        String secret;
        GetSecretValueRequest getSecretValueRequest = new GetSecretValueRequest()
                .withSecretId(secretName);
        GetSecretValueResult getSecretValueResult = null;

        getSecretValueResult = client.getSecretValue(getSecretValueRequest);

        secret = getSecretValueResult.getSecretString(); // 报错位置

        ObjectMapper m = new ObjectMapper();
        Map<String, String>  read = m.readValue(secret, Map.class);
        read.forEach((key, value) -> {
            secretCache.put("accessKey", key);
            secretCache.put("secretKey", value);
        });
    }

4. setup-aws.sh初始化脚本

aws configure set aws_access_key_id "test"
aws configure set aws_secret_access_key "test"
aws configure set default.region eu-west-3


aws --endpoint-url=http://localhost:4566 secretsmanager create-secret --name aws/secret --secret-string '{"my_uname":"username","my_pwd":"password"}'

aws --endpoint-url=http://localhost:4566  s3api create-bucket \
              --bucket bucketnameproject \
              --region eu-west-1 \
              --create-bucket-configuration LocationConstraint=eu-west-3

报错信息

com.amazonaws.services.secretsmanager.model.ResourceNotFoundException: Secrets Manager can't find the specified secret. (Service: AWSSecretsManager; Status Code: 400; Error Code: ResourceNotFoundException; Request ID: 55AQCW3AFW5RK39GQZGXAK6MVHG80K7W6SGYTUE5MTJ5X5TMLEMB; Proxy: null)

解决方案

1. 启用LocalStack的Secrets Manager服务

当前docker-compose的SERVICES仅配置了s3,LocalStack默认不会启动未声明的服务,添加secretsmanager到服务列表:

environment:
  - SERVICES=s3,secretsmanager  # 新增secretsmanager服务
  - EDGE_PORT=4566
  - AWS_ACCESS_KEY_ID=test
  - AWS_SECRET_ACCESS_KEY=test
  - AWS_DEFAULT_REGION=eu-west-3

修改后重启LocalStack容器。

2. 为AWS客户端配置凭证

AWS SDK客户端需要凭证才能访问LocalStack,代码中缺少凭证配置,添加以下代码:

AWSSecretsManager client = AWSSecretsManagerClientBuilder.standard()
        .withEndpointConfiguration(new EndpointConfiguration(secretManagerUrl, region))
        .withCredentials(new AWSStaticCredentialsProvider(new BasicAWSCredentials("test", "test"))) // 添加凭证配置
        .build();

3. 验证密钥与客户端的region一致性

确认创建密钥的region(脚本中为eu-west-3)和代码中使用的region完全一致,避免跨region访问导致找不到资源。可通过以下命令再次验证密钥存在:

aws --endpoint-url=http://localhost:4566 secretsmanager describe-secret --secret-id aws/secret

4. 检查端点URL正确性

确保代码中secretManagerUrl的值为http://localhost:4566,无多余路径或后缀,与application.properties中的配置完全匹配。

内容的提问来源于stack exchange,提问作者Sercan Noyan Germiyanoğlu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 08:00:58