使用AWS CLI对比跨账号安全组时排序不一致问题求助
解决跨AWS账号同名安全组对比的JSON排序不一致问题
AWS CLI返回的describe-security-groups结果中,IpPermissions、IpPermissionsEgress这类数组的元素顺序不固定,且部分字段可能存在null值,这会导致直接对比或使用sort_by时出错。以下是可行的解决步骤:
1. 导出两个账号的安全组数据
分别在两个账号的CLI环境下执行命令,导出目标安全组的JSON数据:
# 账号1导出MainSG数据 aws ec2 describe-security-groups --group-names MainSG > sg-acc1.json # 账号2导出MainSG数据 aws ec2 describe-security-groups --group-names MainSG > sg-acc2.json
2. 用jq深度标准化排序
使用jq递归处理所有数组,同时处理null值避免报错,确保相同配置的元素顺序完全一致:
# 标准化账号1的输出 jq ' def sort_sg_arrays: if type == "array" then if length == 0 then . else if .[0] | type == "object" then # 按安全组规则核心字段排序,null值转为默认值规避类型错误 sort_by( .IpProtocol // ""; .FromPort // -1; .ToPort // -1; .CidrIp // ""; .PrefixListId // ""; .GroupId // "" ) | map(if type == "object" then walk(if type == "array" then sort_sg_arrays else . end) else . end) else sort end end elif type == "object" then walk(if type == "array" then sort_sg_arrays else . end) else . end; sort_sg_arrays ' sg-acc1.json > sg-acc1-sorted.json # 同样处理账号2的输出 jq ' def sort_sg_arrays: if type == "array" then if length == 0 then . else if .[0] | type == "object" then sort_by( .IpProtocol // ""; .FromPort // -1; .ToPort // -1; .CidrIp // ""; .PrefixListId // ""; .GroupId // "" ) | map(if type == "object" then walk(if type == "array" then sort_sg_arrays else . end) else . end) else sort end end elif type == "object" then walk(if type == "array" then sort_sg_arrays else . end) else . end; sort_sg_arrays ' sg-acc2.json > sg-acc2-sorted.json
3. 对比标准化后的文件
用diff命令直接对比两个排序后的文件,无输出则表示两个安全组配置完全一致:
diff sg-acc1-sorted.json sg-acc2-sorted.json
关键细节说明
walk函数递归遍历JSON所有节点,确保所有嵌套数组都被排序//操作符处理null值,将其转为空字符串或-1,避免sort_by抛出「值类型无效」的报错- 针对安全组规则的核心字段(协议、端口、CIDR、关联安全组ID等)排序,保证相同规则的顺序完全统一
内容的提问来源于stack exchange,提问作者Zak25
相关产品推荐
相关产品推荐

