使用aws-vault连接AWS EKS集群,如何修改1小时自动登出时长?
调整AWS EKS集群连接自动登出时长的解决方案
一、修改AWS STS临时凭证有效期(核心)
aws-vault依赖AWS STS临时凭证,默认1小时过期,可通过两种方式调整:
- 持久化配置:编辑
~/.aws/config文件,给目标AWS profile添加sts_duration_seconds参数,比如设置为4小时(14400秒):[profile your-eks-profile] sts_duration_seconds = 14400 - 临时指定:登录时通过
--duration参数直接设置时长,例如:aws-vault login your-eks-profile --duration=4h
二、同步kubeconfig的凭证有效期
生成kubeconfig时,确保凭证过期时间和STS凭证一致:
- 若用aws-cli生成kubeconfig,只要对应profile的STS有效期已调整,执行以下命令会自动同步:
aws eks update-kubeconfig --name your-eks-cluster --profile your-eks-profile --kubeconfig ~/.kube/config - 若用自定义kubeconfig脚本,需在生成
user段时,同步exec输出的凭证过期时间。
三、验证调整结果
- 查看当前STS凭证过期时间:
aws-vault exec your-eks-profile -- aws sts get-caller-identity --query 'Credentials.Expiration' --output text - 检查kubeconfig:打开
~/.kube/config,确认对应集群的user部分中exec返回的expiration字段是否符合设置的时长。
注意事项
AWS IAM角色的MaxSessionDuration参数限制了STS临时凭证的最长有效期,默认是1小时。如果需要设置超过1小时的时长,需先修改目标IAM角色的该参数(最大值为12小时)。
内容的提问来源于stack exchange,提问作者Dylan
相关产品推荐
相关产品推荐

