如何使用AWS CLI筛选仅绑定EC2实例的网络接口?
只筛选分配给EC2实例的弹性网络接口(ENI)
要过滤掉非EC2实例关联的ENI,你可以通过两种实用方式实现:
方法一:使用AWS CLI过滤器参数
利用EC2 API的原生过滤功能,先锁定关联EC2实例ID的ENI,再排除描述中包含指定非EC2资源标识的条目:
aws ec2 describe-network-interfaces \ --output json \ --filters \ "Name=attachment.instance-id,Values=*" \ "Name=description,Values=!*SageMaker Studio*" \ "Name=description,Values=!*EFS Mount Target*" \ "Name=description,Values=!*Route53 Resolver*" \ "Name=description,Values=!*Transit Gateway Attachment*" \ "Name=description,Values=!*VPC Endpoint*" \ "Name=description,Values=!*NAT Gateway*" \ "Name=description,Values=!*SageMaker Notebook*"
过滤条件说明:
attachment.instance-id,Values=*:仅保留关联了有效EC2实例ID的ENI——非EC2资源的ENI通常不会携带这个属性值- 每个
description,Values=!*xxx*:排除描述中包含指定资源关键词的ENI,!符号表示对匹配结果取反
方法二:使用JMESPath查询表达式
如果需要更灵活的筛选逻辑,可通过--query参数结合JMESPath语法,直接在返回的JSON结果中做本地过滤:
aws ec2 describe-network-interfaces \ --output json \ --query 'NetworkInterfaces[?Attachment.InstanceId != null && !contains(Description, `SageMaker Studio`) && !contains(Description, `EFS Mount Target`) && !contains(Description, `Route53 Resolver`) && !contains(Description, `Transit Gateway Attachment`) && !contains(Description, `VPC Endpoint`) && !contains(Description, `NAT Gateway`) && !contains(Description, `SageMaker Notebook`)]'
查询逻辑说明:
Attachment.InstanceId != null:确保ENI已关联到EC2实例!contains(Description,xxx):逐个排除描述中包含目标非EC2资源关键词的ENI
注意事项:
如果部分资源的ENI描述关键词与示例不匹配,可以先执行不带过滤的命令查看实际Description字段内容,再调整对应的关键词。
内容的提问来源于stack exchange,提问作者RubenLaguna
相关产品推荐
相关产品推荐

