使 VPC 创建成为可选项
Make VPC creation optional
我试图在我的 cloudformation 脚本中使 VPC 创建有条件。比如参数中提供了一个VPC id,那么我要创建这个VPC中的所有资源,否则就新建一个。
当我想重用现有的 VPC 时,问题就出现了,但我无法推断出我的资源之一需要的子网。所以我想,我必须提供它们作为参数。但是如果我将它们作为参数提供,在我想创建一个新 VPC 的情况下,它会抱怨,因为子网 ID 列表是空的,而且它必须是有效的。
错误是Parameter validation failed: parameter value for parameter name VpcPrivateSubnetIds does not exist. Rollback requested by user.
不可能给出任何虚拟值。有什么想法可以实现吗?
这是我的 CF 脚本:
VpcId:
Type: String
Description: Give the VPC id if you want to use an existing one. Leave empty for creating a new one.
VpcPublicSubnetIds:
Type: List<AWS::EC2::Subnet::Id>
Description: List of 3 public SubnetIds for the given VPC.
VpcPrivateSubnetIds:
Type: List<AWS::EC2::Subnet::Id>
Description: List of 3 private SubnetIds for the given VPC.
Conditions:
CreateVPC: !Equals [ !Ref VpcId, ""]
Resources:
(...)
Properties:
PrivateSubnetIds: !If
- CreateVPC
- !GetAtt VPCStack.Outputs.PrivateSubnets
- !Join [',', [!Select [0, !Ref VpcPrivateSubnetIds], !Select [1, !Ref VpcPrivateSubnetIds], !Select [2, !Ref VpcPrivateSubnetIds]]]
PublicSubnetIds: !If
- CreateVPC
- !GetAtt VPCStack.Outputs.PublicSubnets
- !Join [',', [!Select [0, !Ref VpcPublicSubnetIds], !Select [1, !Ref VpcPublicSubnetIds], !Select [2, !Ref VpcPublicSubnetIds]]]
一种解决方案是将 subnetId
参数视为字符串,然后将其保留为空。 (但是当存在 VPC 时,用户必须手动输入子网 ID 列表)。
如果列表不为空(要使用现有 VPC),请使用 Cloudformation custom resource lambda 将字符串(逗号分隔)转换为列表 & return 到 cloudformation 以用于资源创建。所以你的堆栈看起来像
Parameters:
VpcId:
Type: String
Description: Give the VPC id if you want to use an existing one. Leave empty for creating a new one.
VpcPublicSubnetIds:
Type: String
Description: List of 3 public SubnetIds for the given VPC.
Default: ''
VpcPrivateSubnetIds:
Type: String
Description: List of 3 private SubnetIds for the given VPC.
Default: ''
Conditions:
CreateVPC: !Equals [ !Ref VpcId, ""]
CreateList: !Not [!Equals [ !Ref VpcId, ""]]
Resources:
CreateList:
Type: AWS::CloudFormation::CustomResource
Condition: CreateList
Properties:
ServiceToken:<some token>
Public: !Ref VpcPublicSubnetIds
Private: !Ref VpcPrivateSubnetIds
SomeResource:
Properties:
PrivateSubnetIds: !If
- CreateVPC
- !GetAtt VPCStack.Outputs.PrivateSubnets
- !GetAtt CreateList.PrivateSubnetIds
PublicSubnetIds: !If
- CreateVPC
- !GetAtt VPCStack.Outputs.PublicSubnets
- !GetAtt CreateList.PublicSubnetIds
请注意我已验证此脚本,因此您可能需要进行一些更正。
我试图在我的 cloudformation 脚本中使 VPC 创建有条件。比如参数中提供了一个VPC id,那么我要创建这个VPC中的所有资源,否则就新建一个。
当我想重用现有的 VPC 时,问题就出现了,但我无法推断出我的资源之一需要的子网。所以我想,我必须提供它们作为参数。但是如果我将它们作为参数提供,在我想创建一个新 VPC 的情况下,它会抱怨,因为子网 ID 列表是空的,而且它必须是有效的。
错误是Parameter validation failed: parameter value for parameter name VpcPrivateSubnetIds does not exist. Rollback requested by user.
不可能给出任何虚拟值。有什么想法可以实现吗?
这是我的 CF 脚本:
VpcId:
Type: String
Description: Give the VPC id if you want to use an existing one. Leave empty for creating a new one.
VpcPublicSubnetIds:
Type: List<AWS::EC2::Subnet::Id>
Description: List of 3 public SubnetIds for the given VPC.
VpcPrivateSubnetIds:
Type: List<AWS::EC2::Subnet::Id>
Description: List of 3 private SubnetIds for the given VPC.
Conditions:
CreateVPC: !Equals [ !Ref VpcId, ""]
Resources:
(...)
Properties:
PrivateSubnetIds: !If
- CreateVPC
- !GetAtt VPCStack.Outputs.PrivateSubnets
- !Join [',', [!Select [0, !Ref VpcPrivateSubnetIds], !Select [1, !Ref VpcPrivateSubnetIds], !Select [2, !Ref VpcPrivateSubnetIds]]]
PublicSubnetIds: !If
- CreateVPC
- !GetAtt VPCStack.Outputs.PublicSubnets
- !Join [',', [!Select [0, !Ref VpcPublicSubnetIds], !Select [1, !Ref VpcPublicSubnetIds], !Select [2, !Ref VpcPublicSubnetIds]]]
一种解决方案是将 subnetId
参数视为字符串,然后将其保留为空。 (但是当存在 VPC 时,用户必须手动输入子网 ID 列表)。
如果列表不为空(要使用现有 VPC),请使用 Cloudformation custom resource lambda 将字符串(逗号分隔)转换为列表 & return 到 cloudformation 以用于资源创建。所以你的堆栈看起来像
Parameters:
VpcId:
Type: String
Description: Give the VPC id if you want to use an existing one. Leave empty for creating a new one.
VpcPublicSubnetIds:
Type: String
Description: List of 3 public SubnetIds for the given VPC.
Default: ''
VpcPrivateSubnetIds:
Type: String
Description: List of 3 private SubnetIds for the given VPC.
Default: ''
Conditions:
CreateVPC: !Equals [ !Ref VpcId, ""]
CreateList: !Not [!Equals [ !Ref VpcId, ""]]
Resources:
CreateList:
Type: AWS::CloudFormation::CustomResource
Condition: CreateList
Properties:
ServiceToken:<some token>
Public: !Ref VpcPublicSubnetIds
Private: !Ref VpcPrivateSubnetIds
SomeResource:
Properties:
PrivateSubnetIds: !If
- CreateVPC
- !GetAtt VPCStack.Outputs.PrivateSubnets
- !GetAtt CreateList.PrivateSubnetIds
PublicSubnetIds: !If
- CreateVPC
- !GetAtt VPCStack.Outputs.PublicSubnets
- !GetAtt CreateList.PublicSubnetIds
请注意我已验证此脚本,因此您可能需要进行一些更正。