Spring Boot集成AWS Secrets Manager报错:找不到指定密钥
问题:LocalStack模拟AWS环境下Spring Boot读取Secrets Manager密钥报ResourceNotFoundException
在Spring Boot项目中用LocalStack模拟AWS环境,尝试从Secrets Manager获取指定密钥时触发ResourceNotFoundException,已通过脚本成功创建密钥且能通过list-secrets查询到,但项目运行时仍报错。
相关配置与代码
1. docker-compose LocalStack配置片段
localstack: image: localstack/localstack:latest environment: - SERVICES=s3 - EDGE_PORT=4566 - AWS_ACCESS_KEY_ID=test - AWS_SECRET_ACCESS_KEY=test - AWS_DEFAULT_REGION=eu-west-3 ports: - '4566-4597:4566-4597' volumes: - "${TMPDIR:-/tmp/localstack}:/tmp/localstack"
2. application.properties配置
cloud.aws.end-point.uri=http://s3.localhost.localstack.cloud:4566/ cloud.aws.secrets-manager.end-point.uri=http://localhost:4566 # 对应代码中的secretManagerUrl s3.bucket.base.url=http://bucketnameproject.s3.localhost.localstack.cloud:4566/
3. AWSConfiguration类init方法代码
public void init() throws JsonProcessingException { String secretName = "aws/secret"; String region = "eu-west-3"; AWSSecretsManager client = AWSSecretsManagerClientBuilder.standard() .withEndpointConfiguration(new EndpointConfiguration(secretManagerUrl, region)) .build(); String secret; GetSecretValueRequest getSecretValueRequest = new GetSecretValueRequest() .withSecretId(secretName); GetSecretValueResult getSecretValueResult = null; getSecretValueResult = client.getSecretValue(getSecretValueRequest); secret = getSecretValueResult.getSecretString(); // 报错位置 ObjectMapper m = new ObjectMapper(); Map<String, String> read = m.readValue(secret, Map.class); read.forEach((key, value) -> { secretCache.put("accessKey", key); secretCache.put("secretKey", value); }); }
4. setup-aws.sh初始化脚本
aws configure set aws_access_key_id "test" aws configure set aws_secret_access_key "test" aws configure set default.region eu-west-3 aws --endpoint-url=http://localhost:4566 secretsmanager create-secret --name aws/secret --secret-string '{"my_uname":"username","my_pwd":"password"}' aws --endpoint-url=http://localhost:4566 s3api create-bucket \ --bucket bucketnameproject \ --region eu-west-1 \ --create-bucket-configuration LocationConstraint=eu-west-3
报错信息
com.amazonaws.services.secretsmanager.model.ResourceNotFoundException: Secrets Manager can't find the specified secret. (Service: AWSSecretsManager; Status Code: 400; Error Code: ResourceNotFoundException; Request ID: 55AQCW3AFW5RK39GQZGXAK6MVHG80K7W6SGYTUE5MTJ5X5TMLEMB; Proxy: null)
解决方案
1. 启用LocalStack的Secrets Manager服务
当前docker-compose的SERVICES仅配置了s3,LocalStack默认不会启动未声明的服务,添加secretsmanager到服务列表:
environment: - SERVICES=s3,secretsmanager # 新增secretsmanager服务 - EDGE_PORT=4566 - AWS_ACCESS_KEY_ID=test - AWS_SECRET_ACCESS_KEY=test - AWS_DEFAULT_REGION=eu-west-3
修改后重启LocalStack容器。
2. 为AWS客户端配置凭证
AWS SDK客户端需要凭证才能访问LocalStack,代码中缺少凭证配置,添加以下代码:
AWSSecretsManager client = AWSSecretsManagerClientBuilder.standard() .withEndpointConfiguration(new EndpointConfiguration(secretManagerUrl, region)) .withCredentials(new AWSStaticCredentialsProvider(new BasicAWSCredentials("test", "test"))) // 添加凭证配置 .build();
3. 验证密钥与客户端的region一致性
确认创建密钥的region(脚本中为eu-west-3)和代码中使用的region完全一致,避免跨region访问导致找不到资源。可通过以下命令再次验证密钥存在:
aws --endpoint-url=http://localhost:4566 secretsmanager describe-secret --secret-id aws/secret
4. 检查端点URL正确性
确保代码中secretManagerUrl的值为http://localhost:4566,无多余路径或后缀,与application.properties中的配置完全匹配。
内容的提问来源于stack exchange,提问作者Sercan Noyan Germiyanoğlu
相关产品推荐
相关产品推荐

