Lambda连接RDS Proxy执行查询触发认证错误排查求助
按照AWS官方博客步骤配置Lambda连接RDS Proxy,连接成功后执行查询立即断开,报错:FATAL: RDS Proxy supports only IAM or MD5 authentication.
已完成以下排查操作:
- 为Lambda角色添加
AmazonRDSDataFullAccess权限 - 为角色附加两条自定义策略:
- KMS解密权限:
{ "Effect": "Allow", "Action": "kms:Decrypt", "Resource": "arn:aws:kms:eu-west-1:[acct-id]:key/*", "Condition": { "StringEquals": { "kms:ViaService": "secretsmanager.eu-west-1.amazonaws.com" } } }- RDS连接权限:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "rds-db:connect" ], "Resource": [ "arn:aws:rds-db:ue-west-1:[acct-id]:dbuser:prx-ABCDEFGHIJKL01234/*" ] } ] } - 在RDS实例中创建了与IAM用户名同名的读写用户
- 无法创建默认加密密钥,已选择现有密钥
本地执行测试命令时也出现相同错误:
export PGPASSWORD="$(aws rds generate-db-auth-token --hostname ${host} --port 5432 --region eu-west-1 --username iamuser)" psql -h ${host} -p 5432 -d postgres -U iamuser
测试输出:
psql (14.4, server 13.4)
SSL connection (protocol: TLSv1.3, cipher:***, bits: 256, compression: off)
Type "help" for help.postgres=> select current_user;
FATAL: RDS Proxy supports only IAM or MD5 authentication
SSL connection has been closed unexpectedly
The connection to the server was lost. Attempting reset: Succeeded.
psql (14.4, server 13.4)
SSL connection (protocol: TLSv1.3, cipher: ***, bits: 256, compression: off)
这个报错核心是RDS Proxy仅接受IAM认证或MD5加密的密码认证,以下是针对性修复步骤:
1. 修正IAM策略中的区域拼写错误
你提供的rds-db:connect策略里,区域写成了ue-west-1(拼写错误),正确应为eu-west-1,这个错误会导致权限不生效,修正后的策略如下:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "rds-db:connect" ], "Resource": [ "arn:aws:rds-db:eu-west-1:[acct-id]:dbuser:prx-ABCDEFGHIJKL01234/*" ] } ] }
2. 确认RDS实例中用户的认证方式为rds_iam
你在RDS实例创建的iamuser必须配置为IAM认证类型,而非普通密码认证:
- 登录RDS PostgreSQL实例,执行以下SQL检查用户认证方式:
SELECT rolname, rolpassword, rolcanlogin FROM pg_roles WHERE rolname = 'iamuser';
- 如果
rolpassword不为空,或者用户未启用rds_iam认证,执行以下SQL修改:
ALTER USER iamuser WITH PASSWORD NULL; ALTER USER iamuser rds_iam;
3. 检查RDS Proxy的认证配置
- 进入RDS Proxy控制台,在「认证」选项卡中确认已启用IAM认证
- 若使用MD5认证,检查Proxy关联的Secrets Manager密钥是否正确;若使用IAM认证,确认IAM角色已关联到Proxy
4. 重新测试
完成以上修改后,重新运行Lambda函数或本地测试命令,确认连接查询正常。
内容的提问来源于stack exchange,提问作者codeSeeker

