使用AWS::CodeDeploy::BlueGreen钩子时如何设置ALB监听器默认动作?
问题
遵循AWS CloudFormation官方的蓝绿部署模板示例操作时,将ALB监听器的DefaultActions从forward类型修改为fixed-response类型后,触发如下报错:
原forward类型配置:
DefaultActions: - Type: forward ForwardConfig: TargetGroups: - TargetGroupArn: !Ref ALBTargetGroupBlue Weight: 1
修改后的fixed-response类型配置:
DefaultActions: - Type: fixed-response FixedResponseConfig: StatusCode: "403" ContentType: "text/plain" MessageBody: "Access Denied"
报错信息:
Transform AWS::CodeDeployBlueGreen failed with: Failed to transform template. Only one Listener Action of type 'forward' is allowed for a listener. Found 0
尝试在ALBListenerProdRule与DefaultActions之间添加规则后,仍出现相同错误,寻求可行解决办法。
解决办法
- 必须保留
DefaultActions为forward类型,指向蓝/绿目标组,因为AWS::CodeDeployBlueGreen转换依赖该动作完成蓝绿部署的流量切换(调整蓝/绿目标组的权重),不允许完全替换为fixed-response。 - 如果需要实现特定场景下返回403固定响应,通过添加监听器规则来实现,示例配置如下:
DefaultActions: - Type: forward ForwardConfig: TargetGroups: - TargetGroupArn: !Ref ALBTargetGroupBlue Weight: 1 # 添加监听器规则,匹配指定条件时返回403 Rules: - Priority: 1 Conditions: - Field: path-pattern Values: - "/forbidden/*" Actions: - Type: fixed-response FixedResponseConfig: StatusCode: "403" ContentType: "text/plain" MessageBody: "Access Denied" - 若需默认返回403、仅允许特定流量转发到目标组,可调整规则优先级:将固定响应规则设为高优先级(如Priority:1)匹配所有请求,再添加低优先级规则(如Priority:2)转发合法流量到目标组。注意需确保转发规则的目标组配置符合蓝绿部署的要求,避免影响流量切换逻辑。
内容的提问来源于stack exchange,提问作者iriyano
相关产品推荐
相关产品推荐

