You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CloudFormation负载均衡器与S3 Bucket配置故障排查

问题解决方案

一、负载均衡器与VPC网关配置问题

1. 互联网网关与VPC关联缺失修复

CloudFormation栈创建失败核心原因是VPC未关联互联网网关,导致公网负载均衡器无法获取公网访问能力。需在模板中补充以下资源配置:

  • 创建互联网网关
  • 将网关与目标VPC关联
  • 给VPC的公网子网路由表添加指向网关的默认路由

示例代码:

# 创建互联网网关
MyInternetGateway:
  Type: AWS::EC2::InternetGateway

# 关联网关到目标VPC
VPCGatewayAttachment:
  Type: AWS::EC2::VPCGatewayAttachment
  Properties:
    VpcId: !Ref MyVPC  # 替换为你的VPC资源引用
    InternetGatewayId: !Ref MyInternetGateway

# 公网路由表
PublicRouteTable:
  Type: AWS::EC2::RouteTable
  Properties:
    VpcId: !Ref MyVPC

# 添加默认路由到互联网网关
DefaultPublicRoute:
  Type: AWS::EC2::Route
  DependsOn: VPCGatewayAttachment
  Properties:
    RouteTableId: !Ref PublicRouteTable
    DestinationCidrBlock: 0.0.0.0/0
    GatewayId: !Ref MyInternetGateway

# 关联公网子网到路由表
Subnet1RouteTableAssociation:
  Type: AWS::EC2::SubnetRouteTableAssociation
  Properties:
    SubnetId: !Ref Subnet1
    RouteTableId: !Ref PublicRouteTable

Subnet2RouteTableAssociation:
  Type: AWS::EC2::SubnetRouteTableAssociation
  Properties:
    SubnetId: !Ref Subnet2
    RouteTableId: !Ref PublicRouteTable

2. TargetGroup错误修复

无效ID“VPC”问题

TargetGroup的VpcId属性必须引用实际VPC资源(格式为vpc-xxx),不能直接写字符串"VPC"。需使用!Ref或!ImportValue关联你的VPC资源,示例:

VpcId: !Ref MyVPC  # 正确写法
# VpcId: "VPC"     # 错误写法,会触发无效ID提示

必须指定协议问题

Protocol是TargetGroup的必填属性,需明确设置为合法值(如HTTP、HTTPS、TCP等)。示例:

MyTargetGroup:
  Type: AWS::ElasticLoadBalancingV2::TargetGroup
  Properties:
    VpcId: !Ref MyVPC
    Protocol: HTTP  # 必填项,根据业务场景选择
    Port: 80
    TargetType: instance
    HealthCheckProtocol: HTTP

负载均衡器子网配置确认

  • 确保Subnet1/Subnet2为公网子网(已关联带互联网网关默认路由的路由表)
  • 若为公共负载均衡器,需将Scheme属性设为internet-facing
  • Subnets属性正确引用子网资源,示例:
    MyLoadBalancer:
      Type: AWS::ElasticLoadBalancingV2::LoadBalancer
      Properties:
        Scheme: internet-facing
        Subnets: [!Ref Subnet1, !Ref Subnet2]
        SecurityGroups: [!Ref MyLBSecurityGroup]
    

二、S3 Bucket访问控制配置问题

“仅1个子模式匹配”的枚举验证错误,是因为AccessControl属性的值必须是AWS预定义的枚举类型,不能使用自定义参数或拼写错误。

修复步骤:

  1. 使用AWS允许的合法枚举值,常见有效值包括:
    • Private(默认,仅桶所有者可访问)
    • PublicRead(公网可读,桶所有者可读写)
    • AuthenticatedRead(所有AWS认证用户可读)
  2. 正确配置示例:
    MyS3Bucket:
      Type: AWS::S3::Bucket
      Properties:
        AccessControl: Private  # 使用合法枚举值
        # 其他桶配置...
    

额外建议:

AWS目前推荐使用Bucket Policy代替AccessControl管理S3桶权限,这种方式更灵活且易于维护,可避免枚举值相关错误。示例私有访问的Bucket Policy配置:

MyS3BucketPolicy:
  Type: AWS::S3::BucketPolicy
  Properties:
    Bucket: !Ref MyS3Bucket
    PolicyDocument:
      Version: '2012-10-17'
      Statement:
        - Effect: Allow
          Principal:
            AWS: !Sub arn:aws:iam::${AWS::AccountId}:root
          Action: s3:*
          Resource:
            - !Sub arn:aws:s3:::${MyS3Bucket}
            - !Sub arn:aws:s3:::${MyS3Bucket}/*

内容的提问来源于stack exchange,提问作者Data Science Analytics Manager

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 05:33:22