AWS Lambda无法读取EC2实例列表,如何排查原因?
我遇到了AWS Lambda函数无法读取EC2实例列表的问题,请求帮助排查原因,具体情况如下:
这段代码没有抛出任何错误,仅返回空结果:
import os import boto3 ec2 = boto3.resource('ec2',region) for ins in ec2.instances.all(): ip = ins.private_ip_address state_name = ins.state['Name'] print("ip:{}, state:{}".format(ip, state_name))
CloudWatch也没有任何日志输出。我尝试添加try/catch捕获异常,但没有效果……什么都没有。
Lambda与EC2实例属于同一个VPC,Lambda绑定到私有子网,且与EC2实例使用相同的安全组。
权限模拟器显示分配给Lambda的角色对EC2操作具备正常权限。可能我在配置中遗漏了某些内容,但该如何排查问题?
更新1:完整代码与运行日志
为避免混淆,我提供完整代码如下:
import os import boto3 def get_ec2_instances(region, project, state): ec2_instances = [] ec2 = boto3.resource('ec2', region_name=region) filters = [ { 'Name': 'tag:project', 'Values': [project] }, { 'Name': 'instance-state-name', 'Values': [state] } ] for ins in ec2.instances.all(): ip = ins.private_ip_address state_name = ins.state['Name'] print("ip:{}, state:{}".format(ip, state_name)) // 此处无输出 for instance in ec2.instances.filter(Filters=filters): ip = instance.private_ip_address state_name = instance.state['Name'] print("ip:{}, state:{}".format(ip, state_name)) ec2_instances.append(instance) return ec2_instances def start_ec2_instance(region, project): instances_to_start = get_ec2_instances(region, project, 'stopped') instance_state_changed = 0 for instance in instances_to_start: instance.start() instance_state_changed += 1 return instance_state_changed def stop_ec2_instance(region, project): instances_to_stop = get_ec2_instances(region, project, "running") instance_state_changed = 0 for instance in instances_to_stop: instance.stop() instance_state_changed += 1 return instance_state_changed def describe_ec2_instances(region, project): instances = get_ec2_instances(region, project, "running") for instance in instances: print("Instance ID: {}, IP: {}, State: {}".format(instance.id, instance.private_ip_address, instance.state['Name'])) def lambda_handler(event, context): region = os.getenv('REGION', 'eu-central-1') project = os.getenv('PROJECT', 'ec2-instance') instance_state_changed = 0 if event.get('action') == 'start': instance_state_changed = start_ec2_instance(region, project) elif event.get('action') == 'stop': instance_state_changed = stop_ec2_instance(region, project) elif event.get('action') == 'describe': describe_ec2_instances(region, project) return instance_state_changed
运行函数后得到如下输出:
Test Event Name
StartResponse
{
"errorMessage": "2023-06-16T16:17:37.510Z 75118795-2ffd-46ab-84e6-.... Task timed out after 3.02 seconds"
}Function Logs
START RequestId: 75118795-2ffd-46ab-84e6-... Version: $LATEST
2023-06-16T16:17:37.510Z 75118795-2ffd-46ab-84e6-... Task timed out after 3.02 secondsEND RequestId: 75118795-2ffd-46ab-84e6-...
REPORT RequestId: 75118795-2ffd-46ab-84e6-... Duration: 3018.80 ms Billed Duration: 3000 ms Memory Size: 128 MB Max Memory Used: 83 MB Init Duration: 293.49 msRequest ID
75118795-2ffd-46ab-84e6-...
更新2:VPC配置截图

内容的提问来源于stack exchange,提问作者Anthony

