You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Lambda返回结果缺失LastModifiedTime字段问题求助

问题:AWS Lambda调用Network Firewall接口缺失LastModifiedTime字段

我用Python3编写脚本调用AWS Network Firewall的describe_rule_group_metadata接口获取托管规则组元数据,本地执行时返回结果包含LastModifiedTime字段;但将相同逻辑部署到AWS Lambda中运行时,返回结果缺失该关键字段,查阅官方文档确认该字段应存在,恳请帮忙排查原因。

本地脚本代码

def get_current_version(rule_group_arn):
    response = network_firewall.describe_rule_group_metadata(RuleGroupArn=rule_group_arn)
    return response

print(get_current_version("arn:aws:network-firewall:eu-central-1:aws-managed:stateful-rulegroup/ThreatSignaturesDoSStrictOrder"))

本地返回结果

{'RuleGroupArn': 'arn:aws:network-firewall:eu-central-1:aws-managed:stateful-rulegroup/ThreatSignaturesDoSStrictOrder', 'RuleGroupName': 'ThreatSignaturesDoSStrictOrder', 'Description': 'Signatures that detect Denial of Service attempts.', 'Type': 'STATEFUL', 'Capacity': 200, 'StatefulRuleOptions': {'RuleOrder': 'STRICT_ORDER'}, 'LastModifiedTime': datetime.datetime(2022, 6, 21, 12, 54, 12, 241000, tzinfo=tzlocal()), 'ResponseMetadata': {'RequestId': 'a4ea84ee-f908-4f2c-9ff1-6b4542b1313c', 'HTTPStatusCode': 200, 'HTTPHeaders': {'x-amzn-requestid': 'a4ea84ee-f908-4f2c-9ff1-6b4542b1313c', 'content-type': 'application/x-amz-json-1.0', 'content-length': '354', 'date': 'Tue, 27 Sep 2022 18:10:26 GMT'}, 'RetryAttempts': 0}}

Lambda代码

def lambda_handler(event, context):
    response = network_firewall.describe_rule_group_metadata(RuleGroupArn="arn:aws:network-firewall:eu-central-1:aws-managed:stateful-rulegroup/ThreatSignaturesDoSStrictOrder")
    return response

Lambda返回结果

{
  "RuleGroupArn": "arn:aws:network-firewall:eu-central-1:aws-managed:stateful-rulegroup/ThreatSignaturesDoSStrictOrder",
  "RuleGroupName": "ThreatSignaturesDoSStrictOrder",
  "Description": "Signatures that detect Denial of Service attempts.",
  "Type": "STATEFUL",
  "Capacity": 200,
  "StatefulRuleOptions": {
    "RuleOrder": "STRICT_ORDER"
  },
  "ResponseMetadata": {
    "RequestId": "45bafe6f-8df4-479a-b0bb-c4572dc7f039",
    "HTTPStatusCode": 200,
    "HTTPHeaders": {
      "x-amzn-requestid": "45bafe6f-8df4-479a-b0bb-c4572dc7f039",
      "content-type": "application/x-amz-json-1.0",
      "content-length": "354",
      "date": "Tue, 27 Sep 2022 18:37:07 GMT"
    },
    "RetryAttempts": 0
  }
}

排查方向

  • Boto3版本差异:本地环境与Lambda运行时的Boto3版本不一致是最可能的原因。LastModifiedTime字段可能在较新版本的Boto3中才被加入响应解析逻辑,而Lambda默认的Boto3版本可能偏旧。解决办法是在Lambda层添加指定版本的Boto3,或在部署包中包含最新版Boto3。
  • JSON序列化验证:Lambda返回结果时会自动将Python对象序列化为JSON,datetime对象默认无法直接序列化,但本地打印是Python原生输出所以能显示。可以尝试手动提取字段并转换为字符串后返回,验证字段是否实际存在:
    def lambda_handler(event, context):
        response = network_firewall.describe_rule_group_metadata(RuleGroupArn="arn:aws:network-firewall:eu-central-1:aws-managed:stateful-rulegroup/ThreatSignaturesDoSStrictOrder")
        if 'LastModifiedTime' in response:
            response['LastModifiedTime'] = response['LastModifiedTime'].isoformat()
        return response
    
  • 权限与区域确认:检查Lambda执行角色是否拥有network-firewall:DescribeRuleGroupMetadata权限,同时确认Lambda部署区域与调用接口的区域一致(本例均为eu-central-1,此可能性较低)。
  • SDK解析逻辑问题:旧版本Boto3可能未正确解析LastModifiedTime字段,即使API返回了该字段,SDK也未将其加入响应字典,升级Boto3版本可解决此问题。

内容的提问来源于stack exchange,提问作者elmario-nc

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 05:50:57