You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Lambda连接RDS Proxy执行查询触发认证错误排查求助

问题

按照AWS官方博客步骤配置Lambda连接RDS Proxy,连接成功后执行查询立即断开,报错:
FATAL: RDS Proxy supports only IAM or MD5 authentication.

已完成以下排查操作:

  • 为Lambda角色添加AmazonRDSDataFullAccess权限
  • 为角色附加两条自定义策略:
    1. KMS解密权限:
    {
        "Effect": "Allow",
        "Action": "kms:Decrypt",
        "Resource": "arn:aws:kms:eu-west-1:[acct-id]:key/*",
        "Condition": {
            "StringEquals": {
                "kms:ViaService": "secretsmanager.eu-west-1.amazonaws.com"
            }
        }
    }
    
    1. RDS连接权限:
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": [
                    "rds-db:connect"
                ],
                "Resource": [
                    "arn:aws:rds-db:ue-west-1:[acct-id]:dbuser:prx-ABCDEFGHIJKL01234/*"
                ]
            }
        ]
    }
    
  • 在RDS实例中创建了与IAM用户名同名的读写用户
  • 无法创建默认加密密钥,已选择现有密钥

本地执行测试命令时也出现相同错误:

export PGPASSWORD="$(aws rds generate-db-auth-token --hostname ${host} --port 5432 --region eu-west-1 --username iamuser)"

psql -h ${host} -p 5432 -d postgres -U iamuser

测试输出:

psql (14.4, server 13.4)
SSL connection (protocol: TLSv1.3, cipher:***, bits: 256, compression: off)
Type "help" for help.

postgres=> select current_user;
FATAL: RDS Proxy supports only IAM or MD5 authentication
SSL connection has been closed unexpectedly
The connection to the server was lost. Attempting reset: Succeeded.
psql (14.4, server 13.4)
SSL connection (protocol: TLSv1.3, cipher: ***, bits: 256, compression: off)

解决方案

这个报错核心是RDS Proxy仅接受IAM认证或MD5加密的密码认证,以下是针对性修复步骤:

1. 修正IAM策略中的区域拼写错误

你提供的rds-db:connect策略里,区域写成了ue-west-1(拼写错误),正确应为eu-west-1,这个错误会导致权限不生效,修正后的策略如下:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "rds-db:connect"
            ],
            "Resource": [
                "arn:aws:rds-db:eu-west-1:[acct-id]:dbuser:prx-ABCDEFGHIJKL01234/*"
            ]
        }
    ]
}

2. 确认RDS实例中用户的认证方式为rds_iam

你在RDS实例创建的iamuser必须配置为IAM认证类型,而非普通密码认证:

  • 登录RDS PostgreSQL实例,执行以下SQL检查用户认证方式:
SELECT rolname, rolpassword, rolcanlogin FROM pg_roles WHERE rolname = 'iamuser';
  • 如果rolpassword不为空,或者用户未启用rds_iam认证,执行以下SQL修改:
ALTER USER iamuser WITH PASSWORD NULL;
ALTER USER iamuser rds_iam;

3. 检查RDS Proxy的认证配置

  • 进入RDS Proxy控制台,在「认证」选项卡中确认已启用IAM认证
  • 若使用MD5认证,检查Proxy关联的Secrets Manager密钥是否正确;若使用IAM认证,确认IAM角色已关联到Proxy

4. 重新测试

完成以上修改后,重新运行Lambda函数或本地测试命令,确认连接查询正常。


内容的提问来源于stack exchange,提问作者codeSeeker

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 19:09:28