You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Lambda下载S3存储的IoT证书时报[Errno 30]只读错误如何解决?

报错原因

AWS Lambda运行环境的文件系统有固定权限限制:除/tmp临时目录(默认提供512MB存储空间,函数执行结束后数据会自动清除)外,其余所有目录均为只读状态。你原代码直接将证书文件下载到当前工作目录(属于只读目录),因此触发了只读文件系统报错。

解决方案

方案1:修改下载路径到/tmp目录

将所有证书的本地存储路径统一改为/tmp目录下的路径即可,修改后的代码示例如下:

# download certs and keys
certification_path = organisation + '/' + uuid + '/'
# 本地路径统一指向/tmp目录
local_cert = '/tmp/' + cert_file
local_key = '/tmp/' + key_file
local_root = '/tmp/' + root_file

client.download_file(BUCKET, certification_path + cert_file, local_cert)
client.download_file(BUCKET, certification_path + key_file, local_key)
client.download_file(BUCKET, certification_path + root_file, local_root)

后续调用IoT SDK发布消息时,加载证书的路径也要同步替换为上述/tmp下的对应路径即可。

方案2:直接读取证书内容到内存(无需落盘)

如果所使用的IoT SDK支持直接传入证书字节内容作为参数,可以不用将证书文件写入磁盘,直接从S3读取内容到内存使用,避免文件系统操作,效率更高:

# 直接读取S3文件内容到内存,无需存储到本地磁盘
cert_content = client.get_object(Bucket=BUCKET, Key=certification_path + cert_file)['Body'].read()
key_content = client.get_object(Bucket=BUCKET, Key=certification_path + key_file)['Body'].read()
root_content = client.get_object(Bucket=BUCKET, Key=certification_path + root_file)['Body'].read()
额外注意事项
  • 需确保Lambda执行角色已经配置对应S3存储桶的s3:GetObject权限,以及目标IoT主题的iot:Publish权限,避免后续调用出现权限类报错。

内容的提问来源于stack exchange,提问作者ioquitteoo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 09:48:04