You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Serverless部署WAFv2 WebACLAssociation遇ARN无效问题求助

问题分析与解决方案

你遇到的问题核心在于资源创建顺序不匹配以及Serverless默认创建的Stage未被CloudFormation资源显式依赖,导致WebACLAssociation尝试关联一个还未创建的Stage资源。

主要原因

  1. Stage资源未显式定义:Serverless框架会自动创建dev Stage,但这个Stage不属于你在serverless.yml中定义的CloudFormation资源,CloudFormation无法感知它的创建状态,导致Association在Stage创建前就执行关联操作,触发"Resource doesn't exist"或ARN无效错误。
  2. 依赖关系缺失:即使ARN格式正确,如果WebACLAssociation没有明确依赖Stage资源,CloudFormation会并行创建所有资源,导致关联时机过早。

解决方案

1. 显式定义API Gateway Stage资源

在serverless.yml中添加Stage资源,明确关联你的RestApi,并让WebACLAssociation依赖这个Stage,确保创建顺序正确。

2. 修正WebACLAssociation的ResourceArn和依赖

使用显式定义的Stage的ARN,或者通过!Sub正确生成,并添加DependsOn确保依赖顺序。

完整配置示例

MyWafIPSetIPv4:
  Type: 'AWS::WAFv2::IPSet'
  Properties:
    Name: 'WhitelistedIPsIPv4'
    Scope: 'REGIONAL'
    IPAddressVersion: IPV4
    Addresses:
      - "192.168.0.0/24" # 替换为你的白名单IP

MyWafIPSetIPv6:
  Type: 'AWS::WAFv2::IPSet'
  Properties:
    Name: 'WhitelistedIPsIPv6'
    Scope: 'REGIONAL'
    IPAddressVersion: IPV6
    Addresses:
      - "2001:db8::/32" # 替换为你的白名单IP

MyWafWebACL:
  Type: 'AWS::WAFv2::WebACL'
  Properties:
    Name: 'WhitelistedIPsWebACL'
    Scope: 'REGIONAL'
    DefaultAction:
      Allow: {}
    Rules:
      - Name: 'AllowWhitelistedIPsIPv4'
        Priority: 0
        Action:
          Allow: {}
        Statement:
          IPSetReferenceStatement:
            ARN: !GetAtt MyWafIPSetIPv4.Arn
        VisibilityConfig:
          SampledRequestsEnabled: true
          CloudWatchMetricsEnabled: true
          MetricName: 'AllowWhitelistedIPsIPv4Metric'
      - Name: 'AllowWhitelistedIPsIPv6'
        Priority: 1
        Action:
          Allow: {}
        Statement:
          IPSetReferenceStatement:
            ARN: !GetAtt MyWafIPSetIPv6.Arn
        VisibilityConfig:
          SampledRequestsEnabled: true
          CloudWatchMetricsEnabled: true
          MetricName: 'AllowWhitelistedIPsIPv6Metric'
    VisibilityConfig:
      SampledRequestsEnabled: true
      CloudWatchMetricsEnabled: true
      MetricName: 'WhitelistedIPsMetric'

ApiGatewayRestApi:
  Type: 'AWS::ApiGateway::RestApi'
  Properties:
    Name: 'ApiGatewayRestApi'
    Description: 'Standard REST gateway'

# 显式定义Stage资源
ApiGatewayStage:
  Type: 'AWS::ApiGateway::Stage'
  Properties:
    StageName: 'dev'
    RestApiId: !Ref ApiGatewayRestApi
    DeploymentId: !Ref ApiGatewayDeployment # Serverless默认创建的Deployment资源,若名称不符可自行调整
    Description: 'Dev stage'

MyWafWebACLAssociation:
  Type: 'AWS::WAFv2::WebACLAssociation'
  Properties:
    WebAclArn: !Ref MyWafWebACL
    ResourceArn: !Sub "arn:aws:apigateway:${AWS::Region}::/restapis/${ApiGatewayRestApi}/stages/dev"
  DependsOn: 
    - ApiGatewayStage # 明确依赖Stage,确保Stage创建完成后再执行关联

补充说明

  • 如果Serverless自动创建的Deployment资源名称不是ApiGatewayDeployment,可以通过部署后的CloudFormation控制台查看实际资源名称,或者显式定义Deployment资源来避免依赖问题。
  • 确保WebACL的Scope为REGIONAL(对应区域型API Gateway),若使用边缘型API需改为CLOUDFRONT。

内容的提问来源于stack exchange,提问作者leon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 14:13:12