AWS CloudFormation路由表关联报错:不支持的路由目标问题
AWS CloudFormation路由表关联报错解决方案
问题详情
我刚开始使用AWS CloudFormation,尝试创建一个将流量从Internet Gateway路由到NLB,再到目标组中实例的栈,但MyRouteTableAssociation资源持续报错,错误信息如下:
资源处理程序返回消息:"路由表包含不支持的路由目标。该不支持的路由目标比VPC本地CIDR更不具体或不重叠。(Service: Ec2, Status Code: 400, Request ID: 312fc883-6f1e-4cf3-8e90-87bf386ae819)"(RequestToken: cc0f8b6e-dfb0-4576-f2c8-c3456cd38b74, HandlerErrorCode: GeneralServiceException)
我的CloudFormation模板如下:
Resources: MyVPC: Type: AWS::EC2::VPC Properties: CidrBlock: "174.10.12.0/24" EnableDnsHostnames: true EnableDnsSupport: true Tags: - Key: "Name" Value: "TestVPC" PrivateSubnet: Type: AWS::EC2::Subnet Properties: AvailabilityZone: !Select [0, !GetAZs "us-east-1"] CidrBlock: "174.10.12.0/25" VpcId: !Ref MyVPC Tags: - Key: "Name" Value: "PrivateSubnet" PublicSubnet: Type: AWS::EC2::Subnet Properties: AvailabilityZone: !Select [1, !GetAZs "us-east-1"] CidrBlock: "174.10.12.128/25" VpcId: !Ref MyVPC Tags: - Key: "Name" Value: "PublicSubnet" TestInternetGateway: Type: AWS::EC2::InternetGateway Properties: Tags: - Key: Name Value: TestIGW AttachGateway: Type: AWS::EC2::VPCGatewayAttachment Properties: VpcId: !Ref MyVPC InternetGatewayId: !Ref TestInternetGateway MyRouteTable: Type: AWS::EC2::RouteTable Properties: VpcId: !Ref MyVPC Tags: - Key: Name Value: TestRT InternetRoute: Type: AWS::EC2::Route DependsOn: AttachGateway Properties: RouteTableId: !Ref MyRouteTable DestinationCidrBlock: '0.0.0.0/0' GatewayId: !Ref TestInternetGateway MyRouteTableAssociation: Type: AWS::EC2::GatewayRouteTableAssociation Properties: GatewayId: !Ref TestInternetGateway RouteTableId: !Ref MyRouteTable MySubnetRouteTableAssociation: Type: AWS::EC2::SubnetRouteTableAssociation Properties: RouteTableId: !Ref MyRouteTable SubnetId: !Ref PrivateSubnet NLBAPIInstanceSecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: Allow Access from InternetGateway VpcId: !Ref MyVPC SecurityGroupIngress: - IpProtocol: tcp FromPort: 80 ToPort: 80 CidrIp: 0.0.0.0/0 SecurityGroupEgress: - IpProtocol: tcp FromPort: 80 ToPort: 80 DestinationSecurityGroupId: !Ref TestInstanceSecurityGroup TestInstanceSecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: Allow Access from Network Load Balancer VpcId: !Ref MyVPC TestInstanceGroupIngress: Type: AWS::EC2::SecurityGroupIngress Properties: GroupId: !Ref TestInstanceSecurityGroup IpProtocol: tcp FromPort: 80 ToPort: 80 SourceSecurityGroupId: !Ref NLBAPIInstanceSecurityGroup MyLoadBalancer: Type: AWS::ElasticLoadBalancingV2::LoadBalancer Properties: Type: network Scheme: internal Subnets: - !Ref PrivateSubnet Tags: - Key: Name Value: TestNLB MyLoadBalancerListener: Type: AWS::ElasticLoadBalancingV2::Listener Properties: DefaultActions: - Type: forward TargetGroupArn: !Ref MyTargetGroup LoadBalancerArn: !Ref MyLoadBalancer Port: 80 Protocol: TCP MyTestInstance: Type: AWS::EC2::Instance Properties: ImageId: ami-0230bd60aa48260c6 KeyName: Lala InstanceType: t2.micro NetworkInterfaces: - AssociatePublicIpAddress: true SubnetId: !Ref PrivateSubnet DeviceIndex: 0 GroupSet: - !Ref TestInstanceSecurityGroup Tags: - Key: Name Value: TestEc2Instance UserData: Fn::Base64: !Sub | #!/bin/bash yum update -y yum install httpd -y systemctl start httpd systemctl enable httpd echo "<html><h1>Hello from $(hostname -f)</h1></html>" > /var/www/html/index.html MyTargetGroup: Type: AWS::ElasticLoadBalancingV2::TargetGroup Properties: HealthCheckIntervalSeconds: 30 HealthCheckProtocol: HTTP HealthCheckTimeoutSeconds: 5 HealthyThresholdCount: 2 Matcher: HttpCode: 200 Name: TestTargetGroup Port: 80 Protocol: TCP UnhealthyThresholdCount: 2 TargetType: instance Targets: - Id: !Ref MyTestInstance Port: 80 VpcId: !Ref MyVPC Tags: - Key: Name Value: TestTargetGroup Outputs: VPCID: Description: Output VPCs ID Value: !Ref MyVPC PublicSubnetID: Description: Output Public Subnet ID Value: !Ref PublicSubnet PrivateSubnetID: Description: Output Public Subnet ID Value: !Ref PrivateSubnet
问题根源
- 错误使用资源类型:
AWS::EC2::GatewayRouteTableAssociation是用来关联路由表到**虚拟专用网关(VPN Gateway)**的,和Internet Gateway无关。IGW不需要这种关联操作,只需要在路由表中添加指向IGW的路由,再将路由表绑定到子网即可。 - 路由表逻辑冲突:你把包含
0.0.0.0/0默认路由的表绑定到私有子网,同时错误尝试用GatewayRouteTableAssociation绑定IGW,违反了EC2的路由规则。 - 实例配置矛盾:私有子网内的实例开启
AssociatePublicIpAddress: true无效,私有子网默认不会自动分配公网IP,且该配置和私有子网的定位冲突。 - 输出描述错误:
PrivateSubnetID的描述误写为"Output Public Subnet ID"。
修复步骤
- 删除错误资源:完全移除
MyRouteTableAssociation这个AWS::EC2::GatewayRouteTableAssociation类型的资源,IGW不需要该关联。 - 调整路由表关联:由于你的NLB是内部型(
Scheme: internal),私有子网的路由表不需要0.0.0.0/0指向IGW的路由——内部NLB的流量来自VPC内,若实例需要外网访问,应配置NAT网关而非直接绑定IGW路由表。 - 修正实例公网IP设置:私有子网内的实例将
AssociatePublicIpAddress改为false,若需要外网访问,可将实例移至公有子网或配置NAT网关。 - 修正输出描述:将
PrivateSubnetID的描述改为"Output Private Subnet ID"。
修复后的关键代码片段
# 移除MyRouteTableAssociation资源 # 修正子网路由关联(若私有子网无需外网,可同时移除InternetRoute资源) MySubnetRouteTableAssociation: Type: AWS::EC2::SubnetRouteTableAssociation Properties: RouteTableId: !Ref MyRouteTable SubnetId: !Ref PrivateSubnet # 修正实例的公网IP设置 MyTestInstance: Type: AWS::EC2::Instance Properties: ... NetworkInterfaces: - AssociatePublicIpAddress: false SubnetId: !Ref PrivateSubnet ... # 修正输出描述 Outputs: ... PrivateSubnetID: Description: Output Private Subnet ID Value: !Ref PrivateSubnet
内容的提问来源于stack exchange,提问作者wanicedude
相关产品推荐
相关产品推荐

