我有一个非常简单的 AWS Lambda 函数,该函数每隔几秒就会触发一次,连续 3 个月没有失败
import boto3
shadow_client = boto3.client('iot-data')
def lambda_handler(event, context):
response = shadow_client.list_named_shadows_for_thing(thingName='XXXXXX')
...
Run Code Online (Sandbox Code Playgroud)
截至 2021-01-26T18:53:05.415+00:00,这已在 3000 毫秒后开始超时
我还突然收到 SSL 错误的通知。
我从boto3发布历史中看到,昨天(2021-01-26)是boto3 1.16.60发布的。也许无关。与此同时,截至 2021 年 1 月 26 日,有人报告了 SSL错误。他们指出 AWS 可能会从一个 boto3 版本切换到另一个版本。
对任何 boto3.client('iot-data') 函数的任何调用都会在 3000 毫秒后超时:
boto3.client('iot-data').list_named_shadows_for_thing()
boto3.client('iot-data').get_thing_shadow()
Run Code Online (Sandbox Code Playgroud)
谁能帮我:
错误日志:
[错误] SSLError: https://data.iot.eu-central-1.amazonaws.com/things/XXXX/shadow的 SSL 验证失败 [SSL:CERTIFICATE_VERIFY_FAILED] 证书验证失败:无法获取本地颁发者证书 (_ssl. c:1091) 回溯(最近一次调用):文件“/var/task/lambda_function.py”,第 37 行,在 lambda_handler client_shadow = get_shadow(clientID)['state']['desired'] 文件“/var/ task/lambda_function.py”,第 94 行,在 get_shadow 中 响应 = iot_data_client.get_thing_shadow(thingName=thing_name) 文件“/var/runtime/botocore/client.py”,第 357 行,在 _api_call 中 return self._make_api_call(operation_name, kwargs)文件“/var/runtime/botocore/client.py”,第 663 行,在 _make_api_call
operation_model、request_dict、request_context) 文件“/var/runtime/botocore/client.py”,第 682 行,在 _make_request
返回 self._endpoint.make_request (操作模型,request_dict)
文件“/var/runtime/botocore/endpoint.py”,第102行,在make_request中
返回self._send_request(request_dict,操作_模型)文件“/var/runtime/botocore/endpoint.py”,第137行,在 _send_request
success_response 中,异常):文件“/var/runtime/botocore/endpoint.py”,第 256 行,在 _needs_retry
catch_exception=caught_exception,request_dict=request_dict)文件“/var/runtime/botocore/hooks.py”,第 356 行,在发出返回 self._emitter.emit(aliased_event_name, **kwargs) 文件“/var/runtime/botocore/hooks.py”,第 228 行,在发出返回 self._emit(event_name, kwargs) 文件“/var/runtime” /botocore/hooks.py”,第 211 行,在 _emit response = handler(**kwargs) 文件“/var/runtime/botocore/retryhandler.py”,第 183 行,调用if self._checker(attempts, response, catch_exception ):文件“/var/runtime/botocore/retryhandler.py”,第251行,在调用 catch_exception中) 文件“/var/runtime/botocore/retryhandler.py”,第277行,在_should_retry中
返回self._checker(attempt_number,response) ,catch_exception)
文件“/var/runtime/botocore/retryhandler.py”,第317行,调用catch_exception
)文件“/var/runtime/botocore/retryhandler.py”,第223行,调用attempt_number ,catch_exception)文件“/ var/runtime/botocore/retryhandler.py”,第 359 行,在 _check_caught_exception 中引发 catch_exception 文件“/var/runtime/botocore/endpoint.py”,第 200 行,在 _do_get_response
http_response = self._send(request) 文件“/var/ runtime/botocore/endpoint.py”,第 269 行,在 _send 返回 self.http_session.send(request) 文件“/var/runtime/botocore/httpsession.py”,第 281 行,在 send 中引发 SSLError(endpoint_url=request.url ,错误=e)@时间戳1611687531606
实际上,超时是默默发生的,只能通过搜索超时从日志中看到
ingestionTime
1611687185615日志535942143265:/aws/lambda/XXXXXXXXXXX logStream
2021/01/26/[$LATEST]xxxxxxxxxxxxxxxxxxxxx消息2021-01-26T18:53:05.415Z 0b454f65-1366-4525-8288-940 d6f667e6c 任务在 3.00 秒 requestId 后超时
0b454f65-1366-4525-8288-940d6f667e6c时间戳
1611687185415
解决了。
据亚马逊称..
对于由此带来的不便,我们深表歉意。根本原因可能是较新版本的 boto3 导入了最新版本的底层安全模块 certifi,以进行证书验证。在 certifi 的 12 月版本中,他们删除了对 VeriSign 根 CA 的信任,该根 CA 为 boto3 使用的默认 iotdata 端点签署了证书。修复方法是将 iotdata 端点设置为使用客户特定的 iot 核心 ATS URL。您可以通过在 CLI 中或从 IoT Core 控制台的设置菜单中调用“aws iot describe-endpoint --endpoint-type iot:data-ats”来找到此信息。我们正在努力在未来的 boto3 版本中解决这个问题。
这是修复的简单版本
#EDIT THIS LINE TO USE ENDPOINT URL
client = boto3.client('iot-data', region_name='eu-central-1', endpoint_url='https://xxxxxxxxxxxxxx-ats.iot.eu-central-1.amazonaws.com')
Run Code Online (Sandbox Code Playgroud)
其中 xxxxxxxxxxxxxx-ats.iot.eu-central-1.amazonaws.com 是来自 AWS 的终端节点
| 归档时间: |
|
| 查看次数: |
2777 次 |
| 最近记录: |