Home >Backend Development >Golang >Neptune throws bad handshake error when connecting to IAM enabled Neptune instance
It is a common problem for Neptune to throw an error handshake error when connecting to an IAM-enabled Neptune instance. IAM (Identity and Access Management) is a feature of Amazon Web Services (AWS) that manages and controls access to AWS resources. However, you may encounter handshake errors when trying to connect to an IAM-enabled Neptune instance. This error may be caused by incorrect permissions on the IAM role or the Neptune instance being set up incorrectly. In response to this problem, this article will introduce in detail how to solve this error to ensure a smooth connection to the IAM-enabled Neptune instance.
I have an aws neptune instance with iam enabled, I am able to perform CRUD operations without authentication, but when I enable authentication, it Throws error in handshake error log.
Note: The lambda function has full neptune permissions
package main import ( "fmt" "log" "net/http" "os" "time" "github.com/aws/aws-lambda-go/events" "github.com/aws/aws-lambda-go/lambda" gremlingo "github.com/apache/tinkerpop/gremlin-go/v3/driver" "github.com/aws/aws-sdk-go/aws/session" v4 "github.com/aws/aws-sdk-go/aws/signer/v4" ) func main() { lambda.Start(lambdaHandler) } func lambdaHandler(ctx context.Context, request events.APIGatewayProxyRequest) (events.APIGatewayProxyResponse, error) { driverConn, g = connect() result, err = g.AddV("User").Property("userId", "Check").Next() if err != nil { fmt.Println(err) } } func connect() { awsSess, err := session.NewSesionWithOptions(session.Options{ SharedCondfigState: session.SharedConfigEnable, }), if err != nil { log.Fatalf("Failed to creating session: %s", err) } db_endpoint := os.Genenv("DB_ENDPOINT") connString := "wss://" +db_endpoint+":8182/gremlin" // Signing Request req, _ := http.NewRequest(http.MethodGet, connString, nil) signer := v4.NewSigner(awsSess.Config.Credentials) headerToUse, err := signer.Sign(req, nil, "neptune", *awsSess.Config.Region, time.Now()) driverRemoteConnection, err := gremlingo.NewDriverRemoteConnection(connString, func(settings *gremlingo.driverRemoteConnectionSettings) { settings.TraversalSource = "g" settings.AuthInfo.Header = headerToUse }) return driverRemoteConnection, traversalSource(driverRemoteConnection) } func traversalSource(driverConn *gremlingo.DriverRemoteConnection) *gremlingo.GraphTraversalSource { return gremlingo.Traversal_().WithRemote(driverConn) }
Error log: Unable to instantiate new connection; setting connection status to closed. Error creating new connection for connection pool: websocket: handshake error 'e0104: Unable to establish successful connection: websocket: handshake error'
NOTE: I can execute queries if iam authentication is disabled. please help.
An attempt to sign the request failed but authentication failed.
There are some issues in the code that need to be fixed to make it work with neptune iam if all necessary permissions are granted.
neptune-db
, not neptune
. *gremlingo.driverremoteconnectionsettings
should be *gremlingo.driverremoteconnectionsettings
. settings.authinfo.header
The header used is not actually the header returned by the signer, but the header of the original request, so it should be settings.authinfo.header = req. header
. Putting it all together, the block of code under //signing request
will look like this:
// Signing Request req, _ := http.NewRequest(http.MethodGet, connString, nil) signer := v4.NewSigner(awsSess.Config.Credentials) _, err := signer.Sign(req, nil, "neptune-db", *awsSess.Config.Region, time.Now()) driverRemoteConnection, err := gremlingo.NewDriverRemoteConnection(connString, func(settings *gremlingo.DriverRemoteConnectionSettings) { settings.TraversalSource = "g" settings.AuthInfo.Header = req.Header })
One thing to note is that gremlin-go currently has no way to allow automatic refresh of authentication tokens, which means that a new connection must be established after expiration.
Hope this helps.
The above is the detailed content of Neptune throws bad handshake error when connecting to IAM enabled Neptune instance. For more information, please follow other related articles on the PHP Chinese website!