You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Cloud Stream Kinesis生产者无法连接LocalStack故障排查

解决方案:Spring Cloud Stream 对接 LocalStack Kinesis 问题排查

问题1:证书认证错误(Curl错误码60)

LocalStack 默认使用自签名 SSL 证书,KPL(Kinesis Producer Library)默认会严格验证服务器证书,导致信任失败。可通过以下两种方式解决:

方案1:直接禁用证书验证

在 AWS 客户端配置中添加证书信任跳过逻辑,或通过 JVM 参数全局禁用:

// AwsConfigLocal 配置类中修改 Kinesis 客户端构建逻辑
@Bean
public AmazonKinesis amazonKinesis() {
    return AmazonKinesisClientBuilder.standard()
            .withEndpointConfiguration(new AwsClientBuilder.EndpointConfiguration("http://localhost:4566", "us-east-1"))
            .withCredentials(new AWSStaticCredentialsProvider(new BasicAWSCredentials("test", "test")))
            .withClientConfiguration(buildClientConfig())
            .build();
}

private ClientConfiguration buildClientConfig() {
    ClientConfiguration config = new ClientConfiguration();
    config.withTrustAllCertificates(true); // 跳过证书验证
    config.withDisableSocketProxy(true);
    return config;
}

或者启动应用时添加 JVM 参数:

-Dcom.amazonaws.sdk.disableCertChecking=true

方案2:导入 LocalStack 证书到 JVM 信任存储

若不想全局禁用验证,可导出 LocalStack 证书并添加到 JVM 信任链:

  1. 导出证书:
openssl s_client -connect localhost:4566 < /dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > localstack.crt
  1. 导入到 JVM 信任存储(默认密码为 changeit):
keytool -import -alias localstack -keystore $JAVA_HOME/jre/lib/security/cacerts -file localstack.crt

问题2:连接AWS主服务而非LocalStack(UnrecognizedClientException)

该问题是因为 AWS SDK 未正确读取 LocalStack 端点配置,导致请求发送到 AWS 官方服务,测试凭证自然无效。需确保全链路配置指向 LocalStack:

1. 修改 application.yml 配置

确保 Spring Cloud Stream Kinesis Binder 明确指向 LocalStack 端点并禁用签名:

spring:
  cloud:
    stream:
      kinesis:
        binder:
          kinesis-endpoint: http://localhost:4566
          aws-region: us-east-1
          credentials:
            access-key: test
            secret-key: test
          sign-requests: false # LocalStack 不需要真实签名
      bindings:
        output:
          destination: your-stream-name
          content-type: application/json

2. 修正 AwsConfigLocal 配置

确保自定义 AWS 客户端的端点和凭证配置正确:

@Configuration
@Profile("local")
public class AwsConfigLocal {

    @Value("${spring.cloud.stream.kinesis.binder.kinesis-endpoint}")
    private String kinesisEndpoint;

    @Value("${spring.cloud.stream.kinesis.binder.aws-region}")
    private String awsRegion;

    @Bean
    public AmazonKinesis amazonKinesis() {
        AwsClientBuilder.EndpointConfiguration endpointConfig = 
            new AwsClientBuilder.EndpointConfiguration(kinesisEndpoint, awsRegion);

        return AmazonKinesisClientBuilder.standard()
                .withEndpointConfiguration(endpointConfig)
                .withCredentials(new AWSStaticCredentialsProvider(
                        new BasicAWSCredentials("test", "test")))
                .build();
    }

    // 若使用 KPL 生产者,单独配置 KinesisProducerConfiguration
    @Bean
    public KinesisProducerConfiguration kinesisProducerConfiguration() {
        KinesisProducerConfiguration config = new KinesisProducerConfiguration();
        config.setRegion(awsRegion);
        config.setKinesisEndpoint(kinesisEndpoint.split("://")[1]);
        config.setPort(Integer.parseInt(kinesisEndpoint.split(":")[2]));
        config.setCredentialsProvider(new AWSStaticCredentialsProvider(
                new BasicAWSCredentials("test", "test")));
        config.setVerifyCertificate(false); // 跳过证书验证
        return config;
    }
}

3. 检查 Docker Compose 配置(localstack.yml)

确保 LocalStack 正确启用 Kinesis 服务并映射端口:

version: '3.8'
services:
  localstack:
    image: localstack/localstack:latest
    ports:
      - "4566:4566" # 新版 LocalStack 统一通过该端口访问所有服务
    environment:
      - SERVICES=kinesis
      - DEFAULT_REGION=us-east-1
      - EDGE_PORT=4566
      - DISABLE_CORS_CHECKS=1
      - DISABLE_SSL=1 # 若使用 HTTP,禁用 SSL 避免证书问题
    volumes:
      - "${LOCALSTACK_VOLUME_DIR:-./volume}:/var/lib/localstack"
      - "/var/run/docker.sock:/var/run/docker.sock"

额外注意事项

  • 确保 spring-cloud-stream-binder-kinesis:2.2.0 与 LocalStack 版本兼容,建议使用 LocalStack 最新稳定版
  • 检查系统环境变量,避免 AWS_ACCESS_KEY_ID、AWS_SECRET_ACCESS_KEY 等变量覆盖配置文件中的测试凭证
  • KPL 为独立库,需单独配置端点和证书验证,不会自动继承 AWS 客户端的配置

内容的提问来源于stack exchange,提问作者mibrahim.iti

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 15:50:27