You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用IAM角色连接AWS ElastiCache Valkey实例时遭遇WRONGPASS错误的求助

使用IAM角色连接AWS ElastiCache Valkey实例时遭遇WRONGPASS错误的求助

大家好,我现在在Go项目里需要通过IAM角色生成临时token来连接AWS ElastiCache的Valkey实例,但一直遇到WRONGPASS invalid username-password pair or user is disabled.错误。

我已经用Cloud Shell尝试连接,也得到了同样的错误,所以可以排除VPC/防火墙/SSL配置的问题。另外IAM角色的权限应该是没问题的——我能成功调用DescribeReplicationGroups接口获取实例信息,没有遇到权限相关的前置错误。

我的Token生成代码

import (
    // ... 其他导入依赖
    v4 "github.com/aws/aws-sdk-go-v2/aws/signer/v4"
    "github.com/aws/aws-sdk-go-v2/config"
    "github.com/aws/aws-sdk-go-v2/service/elasticache"
)

func (r *RedisHealthController) setupCustomIamAuthTokenAltAlt(ctx context.Context, username, replicationGroupID string) string {
    cfg, err := config.LoadDefaultConfig(ctx)
    if err != nil {
        // 自定义错误处理逻辑
    }

    const (
        requestMethod       = "GET"
        paramAction         = "Action"
        paramUser           = "User"
        actionName          = "connect"
        serviceName         = "elasticache"
        tokenExpirySeconds  = 900
        emptyPayloadHash    = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
    )

    region := cfg.Region
    ecClient := elasticache.NewFromConfig(cfg)

    describeOutput, err := ecClient.DescribeReplicationGroups(ctx, &elasticache.DescribeReplicationGroupsInput{
        ReplicationGroupId: &replicationGroupID,
    })
    if err != nil {
        // 自定义错误处理逻辑
    }

    if len(describeOutput.ReplicationGroups) == 0 || len(describeOutput.ReplicationGroups[0].NodeGroups) == 0 {
        // 自定义错误处理逻辑
    }

    endpointAddress := *describeOutput.ReplicationGroups[0].NodeGroups[0].PrimaryEndpoint.Address
    endpointPort := *describeOutput.ReplicationGroups[0].NodeGroups[0].PrimaryEndpoint.Port

    authURL := url.URL{
        Scheme: "https",
        Host:   fmt.Sprintf("%s:%d", endpointAddress, endpointPort),
        Path:   "/",
    }

    queryParams := url.Values{}
    queryParams.Set(paramAction, actionName)
    queryParams.Set(paramUser, username)
    authURL.RawQuery = queryParams.Encode()

    req, err := http.NewRequestWithContext(ctx, requestMethod, authURL.String(), nil)
    if err != nil {
        // 自定义错误处理逻辑
    }

    credentials, err := cfg.Credentials.Retrieve(ctx)
    if err != nil {
        // 自定义错误处理逻辑
    }

    presigner := v4.NewSigner()
    signedURL, _, err := presigner.PresignHTTP(
        ctx,
        credentials,
        req,
        emptyPayloadHash,
        serviceName,
        region,
        time.Now().UTC().Add(time.Duration(tokenExpirySeconds)*time.Second),
    )
    if err != nil {
        // 自定义错误处理逻辑
    }

    return signedURL
}

客户端初始化代码

endpoint := fmt.Sprintf("%s:%s", redisURL, redisPort)
token := r.setupCustomIamAuthToken(ctx, details, username)
if token == "" {
    // 自定义错误处理逻辑
}

rdb = redis.NewClient(&redis.Options{
    Addr:     endpoint,
    Username: username,
    Password: token,
    DB:       0,
    TLSConfig: &tls.Config{
        MinVersion:         tls.VersionTLS12,
        InsecureSkipVerify: true,
    },
})

生成的token格式大概是这样的:

"https://master.<elasticache-instance-name>.<connection-string>.usw2.cache.amazonaws.com:6379/?Action=connect&User=<elasticache-user-id>&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=<...>&X-Amz-Date=20250701T021930Z&X-Amz-Security-Token=<...>&X-Amz-SignedHeaders=host&X-Amz-Signature=<...>"

已做的排查

  • 确认VPC/防火墙配置无问题:Cloud Shell处于同一VPC,能连接实例但报错相同
  • 确认IAM角色权限:能正常调用DescribeReplicationGroups接口,未出现权限拒绝的前置错误
  • 参考了AWS文档中的Java版ElastiCache IAM token生成逻辑,同时借鉴了AWS SDK中RDS auth的相关代码,但没有找到Go语言的官方示例

求助点

  1. 哪里能找到Go语言下正确生成ElastiCache IAM auth token的官方资源或示例代码?
  2. 我的token生成逻辑里有没有明显的错误点?比如签名的URL构造、参数设置、签名过程哪里不对?

内容来源于stack exchange

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.07 10:43:02