You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

boto3跨区域复制加密RDS集群快照PreSignedUrl认证失败排查

问题现象

执行跨区域复制加密RDS集群操作时,调用CopyDBClusterSnapshot接口返回错误:

(InvalidParameterValue) CopyDBClusterSnapshot operation: PreSignedUrl could not be authenticated while copying encrypted cluster cross region

参考官方文档说明,调用该接口仅需添加source_region参数即可自动生成预签名URL,但实际操作仍触发上述相同报错。后续自行编写代码生成预签名URL传入copy_db_cluster_snapshot接口发起调用,依旧出现相同报错,使用的代码片段如下:

dest_rds_client = boto3.client('rds', region_name='eu-central-1')
pre_signed_url = dest_rds_client.generate_presigned_url\
            ('copy_db_cluster_snapshot', Params={'KmsKeyId': key,
                                                 'SourceDBClusterSnapshotIdentifier':'test',
                                                 'TargetDBClusterSnapshotIdentifier':'test',
                                                 'SourceRegion': 'us-west-2'},
             ExpiresIn=1000)
dest_rds_client.copy_db_cluster_snapshot(SourceDBClusterSnapshotIdentifier='test',
                                                     TargetDBClusterSnapshotIdentifier='test',
                                                     KmsKeyId=key,
                                                     PreSignedUrl=pre_signed_url)
报错根因

代码存在4个核心配置错误,导致预签名URL认证失败:

  • 生成预签名URL的客户端区域错误:预签名URL是源RDS区域签发的授权凭证,必须使用源区域(示例中为us-west-2)的RDS客户端生成,当前代码使用目标区域(eu-central-1)客户端生成签名,区域、端点校验规则不匹配,直接导致认证失败。
  • 生成预签名URL的参数错误:预签名仅需校验源侧资源权限,不需要传入目标区域专属参数(目标快照ID、目标区域KMS密钥ID),且参数中需要指定DestinationRegion告知源区域复制目标,而非传入SourceRegion。
  • 源快照标识符格式错误:跨区域复制场景下,SourceDBClusterSnapshotIdentifier必须传入源快照的完整ARN,仅传入快照别名test会导致源区域无法定位对应快照,签名校验不通过。
  • 额外注意:如果使用SDK自动生成预签名URL的模式,boto3版本低于1.9.0时存在自动签名计算逻辑bug,也会触发该报错。
修复方案

方案1:SDK自动生成预签名URL(推荐,无需手动签名)

  • 先将boto3升级到最新稳定版本
  • 初始化目标区域RDS客户端,调用接口时仅传入SourceRegion参数即可,不需要手动生成、传入PreSignedUrl,SDK会自动完成签名计算,参考代码:
import boto3
# 初始化目标区域RDS客户端
dest_rds_client = boto3.client('rds', region_name='eu-central-1')
resp = dest_rds_client.copy_db_cluster_snapshot(
    # 必须传入源快照的完整ARN,格式为arn:aws:rds:源区域:账号ID:cluster-snapshot:快照名
    SourceDBClusterSnapshotIdentifier='arn:aws:rds:us-west-2:123456789012:cluster-snapshot:test',
    TargetDBClusterSnapshotIdentifier='test',
    KmsKeyId='目标区域的KMS密钥ARN', # 跨区加密必须使用目标区域的KMS密钥,不能复用源区域密钥
    SourceRegion='us-west-2',
    CopyTags=True
)

方案2:手动生成预签名URL

如果需要手动生成预签名URL,必须使用源区域客户端生成签名,且仅传入签名必要的源侧参数,参考代码:

import boto3
# 1. 初始化源区域RDS客户端,用于生成预签名URL
source_rds_client = boto3.client('rds', region_name='us-west-2')
# 2. 生成预签名URL
pre_signed_url = source_rds_client.generate_presigned_url(
    'copy_db_cluster_snapshot',
    Params={
        'SourceDBClusterSnapshotIdentifier': '源快照完整ARN',
        'DestinationRegion': 'eu-central-1' # 指定目标区域,不要传SourceRegion
    },
    ExpiresIn=900 # 签名有效期建议设置为15分钟以内,过长有效期可能触发认证拦截
)
# 3. 用目标区域客户端发起复制请求
dest_rds_client = boto3.client('rds', region_name='eu-central-1')
resp = dest_rds_client.copy_db_cluster_snapshot(
    SourceDBClusterSnapshotIdentifier='源快照完整ARN',
    TargetDBClusterSnapshotIdentifier='test',
    KmsKeyId='目标区域KMS密钥ARN',
    PreSignedUrl=pre_signed_url,
    SourceRegion='us-west-2'
)

内容的提问来源于stack exchange,提问作者Guneet Bhatia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.27 21:48:11