Serverless部署WAFv2 WebACLAssociation遇ARN无效问题求助
问题分析与解决方案
你遇到的问题核心在于资源创建顺序不匹配以及Serverless默认创建的Stage未被CloudFormation资源显式依赖,导致WebACLAssociation尝试关联一个还未创建的Stage资源。
主要原因
- Stage资源未显式定义:Serverless框架会自动创建
devStage,但这个Stage不属于你在serverless.yml中定义的CloudFormation资源,CloudFormation无法感知它的创建状态,导致Association在Stage创建前就执行关联操作,触发"Resource doesn't exist"或ARN无效错误。 - 依赖关系缺失:即使ARN格式正确,如果WebACLAssociation没有明确依赖Stage资源,CloudFormation会并行创建所有资源,导致关联时机过早。
解决方案
1. 显式定义API Gateway Stage资源
在serverless.yml中添加Stage资源,明确关联你的RestApi,并让WebACLAssociation依赖这个Stage,确保创建顺序正确。
2. 修正WebACLAssociation的ResourceArn和依赖
使用显式定义的Stage的ARN,或者通过!Sub正确生成,并添加DependsOn确保依赖顺序。
完整配置示例
MyWafIPSetIPv4: Type: 'AWS::WAFv2::IPSet' Properties: Name: 'WhitelistedIPsIPv4' Scope: 'REGIONAL' IPAddressVersion: IPV4 Addresses: - "192.168.0.0/24" # 替换为你的白名单IP MyWafIPSetIPv6: Type: 'AWS::WAFv2::IPSet' Properties: Name: 'WhitelistedIPsIPv6' Scope: 'REGIONAL' IPAddressVersion: IPV6 Addresses: - "2001:db8::/32" # 替换为你的白名单IP MyWafWebACL: Type: 'AWS::WAFv2::WebACL' Properties: Name: 'WhitelistedIPsWebACL' Scope: 'REGIONAL' DefaultAction: Allow: {} Rules: - Name: 'AllowWhitelistedIPsIPv4' Priority: 0 Action: Allow: {} Statement: IPSetReferenceStatement: ARN: !GetAtt MyWafIPSetIPv4.Arn VisibilityConfig: SampledRequestsEnabled: true CloudWatchMetricsEnabled: true MetricName: 'AllowWhitelistedIPsIPv4Metric' - Name: 'AllowWhitelistedIPsIPv6' Priority: 1 Action: Allow: {} Statement: IPSetReferenceStatement: ARN: !GetAtt MyWafIPSetIPv6.Arn VisibilityConfig: SampledRequestsEnabled: true CloudWatchMetricsEnabled: true MetricName: 'AllowWhitelistedIPsIPv6Metric' VisibilityConfig: SampledRequestsEnabled: true CloudWatchMetricsEnabled: true MetricName: 'WhitelistedIPsMetric' ApiGatewayRestApi: Type: 'AWS::ApiGateway::RestApi' Properties: Name: 'ApiGatewayRestApi' Description: 'Standard REST gateway' # 显式定义Stage资源 ApiGatewayStage: Type: 'AWS::ApiGateway::Stage' Properties: StageName: 'dev' RestApiId: !Ref ApiGatewayRestApi DeploymentId: !Ref ApiGatewayDeployment # Serverless默认创建的Deployment资源,若名称不符可自行调整 Description: 'Dev stage' MyWafWebACLAssociation: Type: 'AWS::WAFv2::WebACLAssociation' Properties: WebAclArn: !Ref MyWafWebACL ResourceArn: !Sub "arn:aws:apigateway:${AWS::Region}::/restapis/${ApiGatewayRestApi}/stages/dev" DependsOn: - ApiGatewayStage # 明确依赖Stage,确保Stage创建完成后再执行关联
补充说明
- 如果Serverless自动创建的Deployment资源名称不是
ApiGatewayDeployment,可以通过部署后的CloudFormation控制台查看实际资源名称,或者显式定义Deployment资源来避免依赖问题。 - 确保WebACL的
Scope为REGIONAL(对应区域型API Gateway),若使用边缘型API需改为CLOUDFRONT。
内容的提问来源于stack exchange,提问作者leon
相关产品推荐
相关产品推荐

