You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置AWS Provider报错:安全令牌无效(InvalidClientTokenId)

排查Terraform AWS Provider的InvalidClientTokenId错误

错误信息

Error: error configuring Terraform AWS Provider:
error validating provider credentials: error calling sts:GetCallerIdentity: operation error STS: GetCallerIdentity, https response error StatusCode: 403, RequestID: 95e52463-8cd7-038-b924-3a5d4ad6ef03, api error InvalidClientTokenId: The security token included in the request is invalid. with provider["registry.terraform.io/hashicorp/aws"], on provider.tf line 1, in provider "aws": 1: provider "aws" {

用户配置文件

1. instance.tf

resource "aws_instance" "web" {
  ami           = "ami-068257025f72f470d"
  instance_type = "t2.micro"
    
  tags = {
    Name = "instance_using_terraform"
  }
}

2. provider.tf

provider "aws" {
  region = "ap-east-1"
  access_key = "xxxx"
  secret_key = "xxxx/xxx+xxx"
}

排查与解决步骤

  • 核对凭证准确性
    登录AWS控制台,进入IAM用户管理页面,找到对应的用户:
    • 确认Access Key ID完全匹配,无大小写错误或多余空格
    • 若Secret Key丢失,直接重新生成(Secret Key仅在生成时可见,无法找回),确保复制时包含所有特殊字符(如/、+),无遗漏或截断
  • 验证IAM用户权限
    确保该用户拥有sts:GetCallerIdentity权限(Terraform验证凭证的核心操作),可临时附加AmazonEC2FullAccess策略测试,后续再根据需求缩小权限范围
  • 检查区域可用性
    确认ap-east-1(香港区域)已在你的AWS账户中启用,部分新账户默认未开放所有区域,可在控制台区域列表中查看并启用
  • 优化凭证配置(推荐)
    避免在代码中硬编码凭证,改用更安全的方式:
    • 环境变量:终端执行
      export AWS_ACCESS_KEY_ID="你的Access Key"
      export AWS_SECRET_ACCESS_KEY="你的Secret Key"
      
    • 本地凭证文件:在~/.aws/credentials(Linux/macOS)或C:\Users\<用户名>\.aws\credentials(Windows)中添加:
      [default]
      aws_access_key_id = 你的Access Key
      aws_secret_access_key = 你的Secret Key
      
      之后provider.tf可简化为:
      provider "aws" {
        region = "ap-east-1"
      }
      
  • 重置Terraform初始化状态
    执行terraform init -reconfigure,强制重新加载凭证配置,清除之前的错误缓存

内容的提问来源于stack exchange,提问作者RAVINDRA PUROHIT

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 02:06:31