You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用aws-vault连接AWS EKS集群,如何修改1小时自动登出时长?

调整AWS EKS集群连接自动登出时长的解决方案

一、修改AWS STS临时凭证有效期(核心)

aws-vault依赖AWS STS临时凭证,默认1小时过期,可通过两种方式调整:

  • 持久化配置:编辑~/.aws/config文件,给目标AWS profile添加sts_duration_seconds参数,比如设置为4小时(14400秒):
    [profile your-eks-profile]
    sts_duration_seconds = 14400
    
  • 临时指定:登录时通过--duration参数直接设置时长,例如:
    aws-vault login your-eks-profile --duration=4h
    

二、同步kubeconfig的凭证有效期

生成kubeconfig时,确保凭证过期时间和STS凭证一致:

  • 若用aws-cli生成kubeconfig,只要对应profile的STS有效期已调整,执行以下命令会自动同步:
    aws eks update-kubeconfig --name your-eks-cluster --profile your-eks-profile --kubeconfig ~/.kube/config
    
  • 若用自定义kubeconfig脚本,需在生成user段时,同步exec输出的凭证过期时间。

三、验证调整结果

  • 查看当前STS凭证过期时间:
    aws-vault exec your-eks-profile -- aws sts get-caller-identity --query 'Credentials.Expiration' --output text
    
  • 检查kubeconfig:打开~/.kube/config,确认对应集群的user部分中exec返回的expiration字段是否符合设置的时长。

注意事项

AWS IAM角色的MaxSessionDuration参数限制了STS临时凭证的最长有效期,默认是1小时。如果需要设置超过1小时的时长,需先修改目标IAM角色的该参数(最大值为12小时)。

内容的提问来源于stack exchange,提问作者Dylan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 18:12:39