AWS Lambda函数无法在S3存储桶创建文件问题求助
Looking at your issue, it's clear that your Lambda function can fetch data from MSSQL without issues, but gets stuck when trying to upload to S3—resulting in a timeout. Let's break down the most likely causes and actionable fixes:
1. Lambda Execution Role Permissions Are Missing
When running locally, you're probably using your personal AWS credentials which have S3 access. But Lambda runs under its own dedicated execution role, which might not have the necessary permissions to write to your target S3 bucket.
Fix:
Update your Lambda IAM role to include a policy that allows s3:PutObject for your bucket. Here's an example policy snippet:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::your-bucket-name/*" } ] }
Replace your-bucket-name with your actual S3 bucket name.
2. VPC Configuration Is Blocking S3 Access
If your Lambda is configured to run inside a VPC, it won't have default access to public services like S3. Your local environment isn't restricted by the VPC, which is why the upload works there.
Fixes:
- Recommended: Add an S3 VPC Endpoint to your VPC. This lets Lambda access S3 directly without routing through the public internet.
- If you don't need Lambda to access other VPC resources, remove it from the VPC entirely.
- Set up a NAT Gateway in your VPC to allow outbound internet access (this is less cost-effective than using a VPC endpoint).
3. Lambda Timeout Configuration Didn't Take Effect
Your CloudWatch logs show a timeout after 30 seconds, but you mentioned updating the timeout to 60 seconds. It's possible the configuration change didn't apply correctly.
Fix:
Double-check your Lambda function's Basic Settings in the AWS Console to confirm the "Timeout" is set to 60 seconds. If you're using Infrastructure as Code (like CloudFormation or SAM), verify the Timeout parameter in your template is configured properly.
4. Manual AWS Credentials Are Causing Conflicts
Your code passes config.awsCredentials to the S3 client. In Lambda, you don't need to manually provide credentials—Lambda automatically injects temporary credentials from the execution role. Using local credentials here might be invalid or cause permission conflicts.
Fix:
Modify your S3 client initialization to use the default SDK configuration:
// Replace this: const s3 = new AWS.S3(config.awsCredentials); // With this: const s3 = new AWS.S3();
5. Add Detailed Error Logging
Right now, your error message is generic. Adding more detailed logs will help you pinpoint the exact issue (like permission denied, network timeout, etc.).
Fix:
Update your error handling to log the full error stack:
if (s3Err) { console.error('Full S3 Upload Error:', s3Err.stack); callback(s3Err, 'There was an error creating file on S3'); }
This will give you specific context in CloudWatch logs instead of just a generic failure message.
Start with these steps—permissions and VPC configuration are the most common culprits for this kind of timeout. After applying these fixes, test the Lambda function again and check the CloudWatch logs for any new error details.
内容的提问来源于stack exchange,提问作者astm1982

