You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CloudFormation中基于参数项数生成动态RDS Proxy Auth配置?

可行,以下是具体实现方案

你可以通过CloudFormation的!ForEach内置函数,基于传入的逗号分隔密钥ARN列表动态生成Auth配置块,无需手动逐个添加。

修改后的CloudFormation模板片段

Parameters:
  SecretManagerArn:
    Type: CommaDelimitedList
    Description: ARN of the AWS Secrets Manager secret containing DB connection parameters
Resources:
  RDSProxy:
    Type: AWS::RDS::DBProxy
    Properties:
      Auth:
        !ForEach [SecretArn, !Ref SecretManagerArn, {
          AuthScheme: SECRETS,
          IAMAuth: REQUIRED,
          SecretArn: !Ref SecretArn
        }]
      DBProxyName: "supersecretname"
      EngineFamily: POSTGRESQL
      RequireTLS: true
      RoleArn: !GetAtt IAMRole.Arn
      VpcSubnetIds: !Ref VpcSubnetIds
      VpcSecurityGroupIds: !Ref VpcSGIds

关键说明

  • !ForEach会遍历SecretManagerArn参数传入的逗号分隔列表,为每个ARN生成一个独立的Auth配置块
  • 循环变量SecretArn会依次取列表中的每个ARN值,填入对应Auth块的SecretArn字段
  • 该功能需要CloudFormation版本支持!ForEach(AWS在2022年之后的版本已全面支持)

如果你的环境暂不支持!ForEach,也可以通过!Split结合!Map实现等效逻辑,但!ForEach的可读性和简洁性更优。

内容的提问来源于stack exchange,提问作者PegaChucho

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 08:35:04