You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.Net Core 2.0 API部署IIS遇AmazonServiceException:无法找到凭证求助

Fixing "Unable to find credentials" AmazonServiceException in .NET Core 2.0 API on IIS

Hey there, let’s work through this AWS credentials issue you’re hitting with your .NET Core 2.0 API when deploying to IIS. Local runs work because your user account has access to the C:\ credentials file, but IIS runs under a different identity—so let’s cover the most practical fixes:

1. Configure Credentials via App Settings (Clean & Configurable)

Instead of relying on local file paths, move your AWS credentials into your app’s configuration. This keeps them tied to your application and accessible regardless of the running user:

First, add your AWS details to appsettings.json:

"AWS": {
  "AccessKey": "your-aws-access-key",
  "SecretKey": "your-aws-secret-key",
  "Region": "us-east-1" // or your target region
}

Then, in Startup.cs, set up the AWS SDK to use these settings:

using Amazon.Extensions.NETCore.Setup;

public void ConfigureServices(IServiceCollection services)
{
    // Load AWS options from appsettings
    var awsOptions = Configuration.GetAWSOptions();
    // Add AWS service clients (e.g., S3, DynamoDB)
    services.AddAWSService<IAmazonS3>(awsOptions);
    
    // ... rest of your service configuration
}

This way, the SDK will pull credentials directly from your app’s config without needing a local .aws folder.

2. Set Up Credentials for the IIS Application Pool Identity

IIS runs your API under the application pool’s user account (like DefaultAppPool by default). You need to give this account access to AWS credentials:

  • Install AWS CLI on the server if you haven’t already.
  • Open a command prompt running as the application pool’s user:
    • For built-in accounts like DefaultAppPool, use a tool like PsExec to launch cmd as that user:
      psexec -i -u "IIS AppPool\DefaultAppPool" cmd.exe
      
  • Run aws configure in the command prompt, and enter your AWS access key, secret key, default region, and output format.
  • This creates a .aws/credentials file in the user’s profile directory (e.g., C:\Users\DefaultAppPool\.aws\credentials), which the IIS process can now access.

3. Use IAM Roles (Most Secure, If Running on AWS)

If your IIS server is an AWS EC2 instance, skip manual credential setup entirely by using an IAM role:

  • Create an IAM role in the AWS Console with the exact permissions your API needs (e.g., S3 read/write, Lambda invoke).
  • Attach this role to your EC2 instance via the EC2 Console (Instance Settings → Attach/Replace IAM Role).
  • The AWS SDK for .NET will automatically fetch credentials from the instance’s metadata service—no code or config changes needed. This is the safest approach since credentials are temporary and never stored on the server.

4. Use Environment Variables for the Application Pool

You can set AWS credentials as environment variables directly on the IIS application pool:

  • Open IIS Manager, navigate to your application pool, right-click → Advanced Settings.
  • Under Process Model, click the ellipsis next to Environment Variables.
  • Add two new variables:
    • AWS_ACCESS_KEY_ID with your access key value
    • AWS_SECRET_ACCESS_KEY with your secret key value
  • Restart the application pool. The AWS SDK will automatically pick up these variables.

Quick Notes to Avoid Pitfalls

  • Make sure you’re using a compatible version of the AWS SDK for .NET with .NET Core 2.0—AWSSDK.Core 3.x versions work well here.
  • Never hardcode credentials directly in your code (it’s a huge security risk). Stick to config files, environment variables, or IAM roles.
  • Double-check that the application pool user has read access to any credential files you’re using (if you go that route).

内容的提问来源于stack exchange,提问作者Ertan Hasani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 11:04:15