You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Cloud Custodian合规策略中为AWS资源添加ARN标签?

解决Cloud Custodian动态添加资源ARN标签的问题

你当前的策略里用静态占位符<arn of current AWS resource>无法动态获取资源ARN,Cloud Custodian支持通过Jinja2模板语法引用资源本身的属性来实现动态标签值填充,同时过滤器里的ARN合规检查也需要对应调整,以下是修正后的完整策略:

- name: xray-rule-tag-compliance
  resource: xray-rule
  filters:
    - or:
      - not:
        - "tag:ID": 12345678
      - not:
        - "tag:Resource Owner": me@example.org
      - not:
        - "tag:Technical Contact": you@example.org
      - not:
        - "tag:Account ID": 123456789012
      - not:
        - expr: "tag.get('ARN') == resource.arn"

  actions:
    - type: tag
      tags:
        FACTS ID: f0d0d593db408014384ce6ab0b96196c
        Resource Owner: me@example.org
        Technical Contact: you@example.org
        Account ID: 123456789012
        ARN: "{{ resource.arn }}"

关键修改说明:

  • 动作部分:将ARN标签的值改为"{{ resource.arn }}",Jinja2模板会自动替换为当前处理的X-Ray规则的实际ARN。
  • 过滤器部分:把原有的静态ARN检查替换为expr表达式,tag.get('ARN') == resource.arn用来判断资源的ARN标签值是否与自身实际ARN一致,not则筛选出标签不匹配的资源。

如果你的Cloud Custodian版本不支持expr过滤器,也可以用neq过滤器实现相同逻辑:

- not:
        - "tag:ARN":
            eq: "{{ resource.arn }}"

内容的提问来源于stack exchange,提问作者elster

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 23:32:39