You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CloudFormation中复用Secrets Manager配置到多个AWS Batch任务

解决AWS CloudFormation中复用Batch作业Secrets配置的方法

因为CloudFormation原生不支持YAML锚点/别名,你可以用以下几种方式实现Secrets配置的复用:

方法1:使用CloudFormation的AWS::Include变换

这个方法适合把重复的配置片段单独抽成文件,在主模板里引用,避免重复代码。

  1. 把Secrets配置单独存成一个YAML文件(比如batch-secrets.yaml):
- Name: DB_USER
  ValueFrom: arn:aws:secretsmanager:us-east-1:123456789012:secret:db-user-xxxxxx
- Name: DB_PASS
  ValueFrom: arn:aws:secretsmanager:us-east-1:123456789012:secret:db-pass-xxxxxx
  1. 主模板里启用AWS::Include变换,然后在每个Batch作业的Secrets字段引用这个文件:
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Include
Parameters:
  SecretsS3Path:
    Type: String
    Default: s3://your-bucket/path/to/batch-secrets.yaml

Resources:
  BatchJob1:
    Type: AWS::Batch::JobDefinition
    Properties:
      JobDefinitionName: job-1
      Type: container
      ContainerProperties:
        Image: your-image:v1
        Secrets: !Include
          Location: !Ref SecretsS3Path
          # 本地开发用SAM CLI时,可改用相对路径:./batch-secrets.yaml

  BatchJob2:
    Type: AWS::Batch::JobDefinition
    Properties:
      JobDefinitionName: job-2
      Type: container
      ContainerProperties:
        Image: your-image:v2
        Secrets: !Include
          Location: !Ref SecretsS3Path

注意:生产环境下AWS::Include引用的文件需放在S3桶中,本地开发可直接使用相对路径配合SAM CLI部署。

方法2:使用CloudFormation宏(Macro)

自定义宏可以动态生成重复的配置片段,适合需要动态调整参数的场景。

  1. 创建生成Secrets配置的Lambda函数(示例代码):
import json

def handler(event, context):
    # 返回固定Secrets配置,也可根据输入参数动态生成
    secrets_config = [
        {"Name": "DB_USER", "ValueFrom": "arn:aws:secretsmanager:us-east-1:123456789012:secret:db-user-xxxxxx"},
        {"Name": "DB_PASS", "ValueFrom": "arn:aws:secretsmanager:us-east-1:123456789012:secret:db-pass-xxxxxx"}
    ]
    return {
        "requestId": event["requestId"],
        "status": "success",
        "fragment": secrets_config
    }
  1. 在CloudFormation模板里定义宏并调用:
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  SecretMacroLambda:
    Type: AWS::Lambda::Function
    Properties:
      Runtime: python3.11
      Handler: index.handler
      Code:
        ZipFile: |
          import json
          def handler(event, context):
              secrets_config = [
                  {"Name": "DB_USER", "ValueFrom": "arn:aws:secretsmanager:us-east-1:123456789012:secret:db-user-xxxxxx"},
                  {"Name": "DB_PASS", "ValueFrom": "arn:aws:secretsmanager:us-east-1:123456789012:secret:db-pass-xxxxxx"}
              ]
              return {
                  "requestId": event["requestId"],
                  "status": "success",
                  "fragment": secrets_config
              }
      Role: !GetAtt SecretMacroLambdaRole.Arn

  SecretMacroLambdaRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service: lambda.amazonaws.com
            Action: sts:AssumeRole
      ManagedPolicyArns:
        - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole

  SecretMacro:
    Type: AWS::CloudFormation::Macro
    Properties:
      Name: GetBatchSecrets
      FunctionName: !Ref SecretMacroLambda

  BatchJob1:
    Type: AWS::Batch::JobDefinition
    Properties:
      JobDefinitionName: job-1
      Type: container
      ContainerProperties:
        Image: your-image:v1
        Secrets: !GetBatchSecrets {}

  BatchJob2:
    Type: AWS::Batch::JobDefinition
    Properties:
      JobDefinitionName: job-2
      Type: container
      ContainerProperties:
        Image: your-image:v2
        Secrets: !GetBatchSecrets {}

部署模板后,宏会自动在每个Batch作业的Secrets字段插入预定义配置。

方法3:使用嵌套栈输出复用

把Secrets配置定义在嵌套栈的输出里,主栈中的每个Batch作业直接引用该输出。

  1. 嵌套栈模板(batch-secrets-nested.yaml):
AWSTemplateFormatVersion: '2010-09-09'
Outputs:
  BatchSecrets:
    Value:
      - Name: DB_USER
        ValueFrom: arn:aws:secretsmanager:us-east-1:123456789012:secret:db-user-xxxxxx
      - Name: DB_PASS
        ValueFrom: arn:aws:secretsmanager:us-east-1:123456789012:secret:db-pass-xxxxxx
    Export:
      Name: BatchSharedSecrets
  1. 主栈模板:
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  SecretsNestedStack:
    Type: AWS::CloudFormation::Stack
    Properties:
      TemplateURL: s3://your-bucket/path/to/batch-secrets-nested.yaml

  BatchJob1:
    Type: AWS::Batch::JobDefinition
    Properties:
      JobDefinitionName: job-1
      Type: container
      ContainerProperties:
        Image: your-image:v1
        Secrets: !GetAtt SecretsNestedStack.Outputs.BatchSecrets

  BatchJob2:
    Type: AWS::Batch::JobDefinition
    Properties:
      JobDefinitionName: job-2
      Type: container
      ContainerProperties:
        Image: your-image:v2
        Secrets: !GetAtt SecretsNestedStack.Outputs.BatchSecrets

这种方法适合需要在多个独立栈之间复用配置的场景。

内容的提问来源于stack exchange,提问作者luan nguyen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 03:27:36