You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CloudFormation路由表关联报错:不支持的路由目标问题

AWS CloudFormation路由表关联报错解决方案

问题详情

我刚开始使用AWS CloudFormation,尝试创建一个将流量从Internet Gateway路由到NLB,再到目标组中实例的栈,但MyRouteTableAssociation资源持续报错,错误信息如下:

资源处理程序返回消息:"路由表包含不支持的路由目标。该不支持的路由目标比VPC本地CIDR更不具体或不重叠。(Service: Ec2, Status Code: 400, Request ID: 312fc883-6f1e-4cf3-8e90-87bf386ae819)"(RequestToken: cc0f8b6e-dfb0-4576-f2c8-c3456cd38b74, HandlerErrorCode: GeneralServiceException)

我的CloudFormation模板如下:

Resources:
  MyVPC:
    Type: AWS::EC2::VPC
    Properties:
      CidrBlock: "174.10.12.0/24"
      EnableDnsHostnames: true
      EnableDnsSupport: true
      Tags:
        - Key: "Name"
          Value: "TestVPC"

  PrivateSubnet:
    Type: AWS::EC2::Subnet
    Properties:
      AvailabilityZone: !Select [0, !GetAZs "us-east-1"]
      CidrBlock: "174.10.12.0/25"
      VpcId: !Ref MyVPC
      Tags:
        - Key: "Name"
          Value: "PrivateSubnet"

  PublicSubnet:
    Type: AWS::EC2::Subnet
    Properties:
      AvailabilityZone: !Select [1, !GetAZs "us-east-1"]
      CidrBlock: "174.10.12.128/25"
      VpcId: !Ref MyVPC
      Tags:
        - Key: "Name"
          Value: "PublicSubnet"

  TestInternetGateway:
    Type: AWS::EC2::InternetGateway
    Properties:
      Tags:
        - Key: Name
          Value: TestIGW
  
  AttachGateway:
    Type: AWS::EC2::VPCGatewayAttachment
    Properties:
      VpcId: !Ref MyVPC
      InternetGatewayId: !Ref TestInternetGateway

  MyRouteTable:
    Type: AWS::EC2::RouteTable
    Properties:
      VpcId: !Ref MyVPC
      Tags:
        - Key: Name
          Value: TestRT

  InternetRoute:
    Type: AWS::EC2::Route
    DependsOn: AttachGateway
    Properties:
      RouteTableId: !Ref MyRouteTable
      DestinationCidrBlock: '0.0.0.0/0'
      GatewayId: !Ref TestInternetGateway

  MyRouteTableAssociation:
    Type: AWS::EC2::GatewayRouteTableAssociation
    Properties:
      GatewayId: !Ref TestInternetGateway
      RouteTableId: !Ref MyRouteTable

  MySubnetRouteTableAssociation:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      RouteTableId: !Ref MyRouteTable
      SubnetId: !Ref PrivateSubnet

  NLBAPIInstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow Access from InternetGateway
      VpcId: !Ref MyVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          DestinationSecurityGroupId: !Ref TestInstanceSecurityGroup

  TestInstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow Access from Network Load Balancer
      VpcId: !Ref MyVPC

  TestInstanceGroupIngress:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      GroupId: !Ref TestInstanceSecurityGroup
      IpProtocol: tcp
      FromPort: 80
      ToPort: 80
      SourceSecurityGroupId: !Ref NLBAPIInstanceSecurityGroup

  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancingV2::LoadBalancer
    Properties:
      Type: network
      Scheme: internal
      Subnets:
        - !Ref PrivateSubnet
      Tags:
        - Key: Name
          Value: TestNLB

  MyLoadBalancerListener:
    Type: AWS::ElasticLoadBalancingV2::Listener
    Properties:
      DefaultActions:
        - Type: forward
          TargetGroupArn: !Ref MyTargetGroup
      LoadBalancerArn: !Ref MyLoadBalancer
      Port: 80
      Protocol: TCP

  MyTestInstance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: ami-0230bd60aa48260c6
      KeyName: Lala
      InstanceType: t2.micro
      NetworkInterfaces:
        - AssociatePublicIpAddress: true
          SubnetId: !Ref PrivateSubnet
          DeviceIndex: 0
          GroupSet:
            - !Ref TestInstanceSecurityGroup
      Tags:
        - Key: Name
          Value: TestEc2Instance
      UserData:
        Fn::Base64: !Sub |
          #!/bin/bash
          yum update -y
          yum install httpd -y
          systemctl start httpd
          systemctl enable httpd
          echo "<html><h1>Hello from $(hostname -f)</h1></html>" > /var/www/html/index.html

  MyTargetGroup:
    Type: AWS::ElasticLoadBalancingV2::TargetGroup
    Properties:
      HealthCheckIntervalSeconds: 30
      HealthCheckProtocol: HTTP
      HealthCheckTimeoutSeconds: 5
      HealthyThresholdCount: 2
      Matcher:
        HttpCode: 200
      Name: TestTargetGroup
      Port: 80
      Protocol: TCP
      UnhealthyThresholdCount: 2
      TargetType: instance
      Targets:
        - Id: !Ref MyTestInstance
          Port: 80
      VpcId: !Ref MyVPC
      Tags:
        - Key: Name
          Value: TestTargetGroup

Outputs:
  VPCID:
    Description: Output VPCs ID
    Value: !Ref MyVPC
  PublicSubnetID:
    Description: Output Public Subnet ID
    Value: !Ref PublicSubnet
  PrivateSubnetID:
    Description: Output Public Subnet ID
    Value: !Ref PrivateSubnet

问题根源

  • 错误使用资源类型:AWS::EC2::GatewayRouteTableAssociation是用来关联路由表到**虚拟专用网关(VPN Gateway)**的,和Internet Gateway无关。IGW不需要这种关联操作,只需要在路由表中添加指向IGW的路由,再将路由表绑定到子网即可。
  • 路由表逻辑冲突:你把包含0.0.0.0/0默认路由的表绑定到私有子网,同时错误尝试用GatewayRouteTableAssociation绑定IGW,违反了EC2的路由规则。
  • 实例配置矛盾:私有子网内的实例开启AssociatePublicIpAddress: true无效,私有子网默认不会自动分配公网IP,且该配置和私有子网的定位冲突。
  • 输出描述错误:PrivateSubnetID的描述误写为"Output Public Subnet ID"。

修复步骤

  1. 删除错误资源:完全移除MyRouteTableAssociation这个AWS::EC2::GatewayRouteTableAssociation类型的资源,IGW不需要该关联。
  2. 调整路由表关联:由于你的NLB是内部型(Scheme: internal),私有子网的路由表不需要0.0.0.0/0指向IGW的路由——内部NLB的流量来自VPC内,若实例需要外网访问,应配置NAT网关而非直接绑定IGW路由表。
  3. 修正实例公网IP设置:私有子网内的实例将AssociatePublicIpAddress改为false,若需要外网访问,可将实例移至公有子网或配置NAT网关。
  4. 修正输出描述:将PrivateSubnetID的描述改为"Output Private Subnet ID"。

修复后的关键代码片段

# 移除MyRouteTableAssociation资源

# 修正子网路由关联(若私有子网无需外网,可同时移除InternetRoute资源)
MySubnetRouteTableAssociation:
  Type: AWS::EC2::SubnetRouteTableAssociation
  Properties:
    RouteTableId: !Ref MyRouteTable
    SubnetId: !Ref PrivateSubnet

# 修正实例的公网IP设置
MyTestInstance:
  Type: AWS::EC2::Instance
  Properties:
    ...
    NetworkInterfaces:
      - AssociatePublicIpAddress: false
        SubnetId: !Ref PrivateSubnet
        ...

# 修正输出描述
Outputs:
  ...
  PrivateSubnetID:
    Description: Output Private Subnet ID
    Value: !Ref PrivateSubnet

内容的提问来源于stack exchange,提问作者wanicedude

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 13:09:52