使用IAM角色连接AWS ElastiCache Valkey实例时遭遇WRONGPASS错误的求助
使用IAM角色连接AWS ElastiCache Valkey实例时遭遇WRONGPASS错误的求助
大家好,我现在在Go项目里需要通过IAM角色生成临时token来连接AWS ElastiCache的Valkey实例,但一直遇到WRONGPASS invalid username-password pair or user is disabled.错误。
我已经用Cloud Shell尝试连接,也得到了同样的错误,所以可以排除VPC/防火墙/SSL配置的问题。另外IAM角色的权限应该是没问题的——我能成功调用DescribeReplicationGroups接口获取实例信息,没有遇到权限相关的前置错误。
我的Token生成代码
import ( // ... 其他导入依赖 v4 "github.com/aws/aws-sdk-go-v2/aws/signer/v4" "github.com/aws/aws-sdk-go-v2/config" "github.com/aws/aws-sdk-go-v2/service/elasticache" ) func (r *RedisHealthController) setupCustomIamAuthTokenAltAlt(ctx context.Context, username, replicationGroupID string) string { cfg, err := config.LoadDefaultConfig(ctx) if err != nil { // 自定义错误处理逻辑 } const ( requestMethod = "GET" paramAction = "Action" paramUser = "User" actionName = "connect" serviceName = "elasticache" tokenExpirySeconds = 900 emptyPayloadHash = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" ) region := cfg.Region ecClient := elasticache.NewFromConfig(cfg) describeOutput, err := ecClient.DescribeReplicationGroups(ctx, &elasticache.DescribeReplicationGroupsInput{ ReplicationGroupId: &replicationGroupID, }) if err != nil { // 自定义错误处理逻辑 } if len(describeOutput.ReplicationGroups) == 0 || len(describeOutput.ReplicationGroups[0].NodeGroups) == 0 { // 自定义错误处理逻辑 } endpointAddress := *describeOutput.ReplicationGroups[0].NodeGroups[0].PrimaryEndpoint.Address endpointPort := *describeOutput.ReplicationGroups[0].NodeGroups[0].PrimaryEndpoint.Port authURL := url.URL{ Scheme: "https", Host: fmt.Sprintf("%s:%d", endpointAddress, endpointPort), Path: "/", } queryParams := url.Values{} queryParams.Set(paramAction, actionName) queryParams.Set(paramUser, username) authURL.RawQuery = queryParams.Encode() req, err := http.NewRequestWithContext(ctx, requestMethod, authURL.String(), nil) if err != nil { // 自定义错误处理逻辑 } credentials, err := cfg.Credentials.Retrieve(ctx) if err != nil { // 自定义错误处理逻辑 } presigner := v4.NewSigner() signedURL, _, err := presigner.PresignHTTP( ctx, credentials, req, emptyPayloadHash, serviceName, region, time.Now().UTC().Add(time.Duration(tokenExpirySeconds)*time.Second), ) if err != nil { // 自定义错误处理逻辑 } return signedURL }
客户端初始化代码
endpoint := fmt.Sprintf("%s:%s", redisURL, redisPort) token := r.setupCustomIamAuthToken(ctx, details, username) if token == "" { // 自定义错误处理逻辑 } rdb = redis.NewClient(&redis.Options{ Addr: endpoint, Username: username, Password: token, DB: 0, TLSConfig: &tls.Config{ MinVersion: tls.VersionTLS12, InsecureSkipVerify: true, }, })
生成的token格式大概是这样的:
"https://master.<elasticache-instance-name>.<connection-string>.usw2.cache.amazonaws.com:6379/?Action=connect&User=<elasticache-user-id>&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=<...>&X-Amz-Date=20250701T021930Z&X-Amz-Security-Token=<...>&X-Amz-SignedHeaders=host&X-Amz-Signature=<...>"
已做的排查
- 确认VPC/防火墙配置无问题:Cloud Shell处于同一VPC,能连接实例但报错相同
- 确认IAM角色权限:能正常调用
DescribeReplicationGroups接口,未出现权限拒绝的前置错误 - 参考了AWS文档中的Java版ElastiCache IAM token生成逻辑,同时借鉴了AWS SDK中RDS auth的相关代码,但没有找到Go语言的官方示例
求助点
- 哪里能找到Go语言下正确生成ElastiCache IAM auth token的官方资源或示例代码?
- 我的token生成逻辑里有没有明显的错误点?比如签名的URL构造、参数设置、签名过程哪里不对?
内容来源于stack exchange
相关产品推荐
相关产品推荐

