如何在Cloud Custodian合规策略中为AWS资源添加ARN标签?
解决Cloud Custodian动态添加资源ARN标签的问题
你当前的策略里用静态占位符<arn of current AWS resource>无法动态获取资源ARN,Cloud Custodian支持通过Jinja2模板语法引用资源本身的属性来实现动态标签值填充,同时过滤器里的ARN合规检查也需要对应调整,以下是修正后的完整策略:
- name: xray-rule-tag-compliance resource: xray-rule filters: - or: - not: - "tag:ID": 12345678 - not: - "tag:Resource Owner": me@example.org - not: - "tag:Technical Contact": you@example.org - not: - "tag:Account ID": 123456789012 - not: - expr: "tag.get('ARN') == resource.arn" actions: - type: tag tags: FACTS ID: f0d0d593db408014384ce6ab0b96196c Resource Owner: me@example.org Technical Contact: you@example.org Account ID: 123456789012 ARN: "{{ resource.arn }}"
关键修改说明:
- 动作部分:将
ARN标签的值改为"{{ resource.arn }}",Jinja2模板会自动替换为当前处理的X-Ray规则的实际ARN。 - 过滤器部分:把原有的静态ARN检查替换为
expr表达式,tag.get('ARN') == resource.arn用来判断资源的ARN标签值是否与自身实际ARN一致,not则筛选出标签不匹配的资源。
如果你的Cloud Custodian版本不支持expr过滤器,也可以用neq过滤器实现相同逻辑:
- not: - "tag:ARN": eq: "{{ resource.arn }}"
内容的提问来源于stack exchange,提问作者elster
相关产品推荐
相关产品推荐

