eksctl create cluster命令执行失败,请求排查STS访问错误
解决eksctl创建EKS集群时的STS访问错误
错误详情
执行eksctl创建集群命令时出现如下错误:
C:\WINDOWS\system32>eksctl create cluster --name eksctl-demo --profile myAdmin2 Error: checking AWS STS access – cannot get role ARN for current session: operation error STS: GetCallerIdentity, failed to sign request: failed to retrieve credentials: failed to refresh cached credentials, no EC2 IMDS role found, operation error ec2imds: GetMetadata, request send failed, Get "http://169.254.169.254/latest/meta-data/iam/security-credentials/": dial tcp 169.254.169.254:80: i/o timeout
相关配置信息
IAM用户myAdmin2凭证配置
- 凭证文件(~/.aws/credentials):
[myAdmin2] aws_access_key_id = ****************** aws_secret_access_key = ********************
- 配置文件(~/.aws/config):
[profile myAdmin2] region = us-east-2 output = json
AWS CLI验证结果
myAdmin2可正常通过AWS CLI调用接口:
C:\WINDOWS\system32>aws iam list-users --profile myAdmin2 { "Users": [ { "Path": "/", "UserName": "myAdmin", "UserId": "AIDAYYPFV776ELVEJ5ZVQ", "Arn": "arn:aws:iam::602313981948:user/myAdmin", "CreateDate": "2022-09-30T19:08:08+00:00" }, { "Path": "/", "UserName": "myAdmin2", "UserId": "AIDAYYPFV776LEDK2PCCI", "Arn": "arn:aws:iam::602313981948:user/myAdmin2", "CreateDate": "2022-09-30T21:39:33+00:00" } ] }
权限说明
myAdmin2已被授予AdministratorAccess权限。
工具版本与环境变量
- AWS CLI版本:
C:\WINDOWS\system32>aws --version aws-cli/2.7.35 Python/3.9.11 Windows/10 exe/AMD64 prompt/off
- 环境变量配置:
C:\WINDOWS\system32>set AWS_ACCESS_KEY_ID= ***********the same as I have in credentials file AWS_CONFIG_FILE=~/.aws/config AWS_DEFAULT_PROFILE=myAdmin2 AWS_DEFAULT_REGION=us-east-2 AWS_PROFILE=myAdmin2 AWS_SECRET_ACCESS_KEY=****************the same as I have in credentials file AWS_SHARED_CREDENTIALS_FILE=~/.aws/credentials
问题分析与解决方案
问题原因
错误提示显示eksctl尝试访问EC2实例元数据服务(IMDS)获取凭证,但本地Windows机器不存在该服务,导致超时。同时环境变量中AWS_ACCESS_KEY_ID和AWS_SECRET_ACCESS_KEY的值前存在空格,会导致凭证解析失败,迫使eksctl fallback到尝试IMDS获取凭证。
解决步骤
修正环境变量的空格问题
编辑系统环境变量,移除AWS_ACCESS_KEY_ID和AWS_SECRET_ACCESS_KEY值前面的空格,确保格式为:AWS_ACCESS_KEY_ID=*********** AWS_SECRET_ACCESS_KEY=****************修改后重启终端,使环境变量生效。
强制禁用IMDS凭证获取
在执行eksctl命令前,设置环境变量禁用IMDS:set AWS_EC2_METADATA_DISABLED=true再执行创建集群命令:
eksctl create cluster --name eksctl-demo --profile myAdmin2直接指定凭证执行命令
如果环境变量问题仍存在,可直接在命令中指定凭证:eksctl create cluster --name eksctl-demo --override-aws-access-key-id YOUR_ACCESS_KEY --override-aws-secret-access-key YOUR_SECRET_KEY --region us-east-2验证凭证有效性
执行以下命令验证eksctl是否能正确获取身份:eksctl get iamidentity --profile myAdmin2若返回正确的IAM用户ARN,说明凭证配置正常。
内容的提问来源于stack exchange,提问作者Aicha AIT OUMGHAR
相关产品推荐
相关产品推荐

