You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudFormation部署含SSM代理的EC2报错:不支持VpcId属性

问题解决:CloudFormation模板中EC2资源的"VpcId"不支持错误

错误原因很明确:AWS::EC2::Instance资源的Properties字段里没有VpcId这个合法属性。当你为EC2实例指定SubnetId时,实例会自动继承该子网所属的VPC,无需单独声明VpcId。

修正后的模板代码

AWSTemplateFormatVersion: 2010-09-09

Description: This Template Create an EC2 in public subnet with SSM.

Parameters:
  VPCId:
    Type: AWS::EC2::VPC::Id
    Description: VpcId of your existing Virtual Private Cloud (VPC)
    Default: vpc-04ef73b29000f4f54 

  PublicSubnet01Block:
    Type: AWS::EC2::Subnet::Id
    Description: SubnetId of an existing subnet (for the primary network in your Virtual Private Cloud VPC)
    Default: subnet-0699037225107e8b2 

Resources:
  SSMIAMRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Statement:
        - Effect: Allow
          Principal:
            Service:
              - ec2.amazonaws.com
          Action:
            - sts:AssumeRole
      ManagedPolicyArns:
        - arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore


  EC2InstanceProfile:
    Type: AWS::IAM::InstanceProfile
    Properties:
      Path: /
      Roles:
        - !Ref SSMIAMRole

  Instance:
    Type: AWS::EC2::Instance
    Properties:
      IamInstanceProfile: !Ref EC2InstanceProfile
      ImageId: ami-0aa7d40eeae50c9a9
      SubnetId: !Ref PublicSubnet01Block
      InstanceType: t2.micro

额外说明

  • 你使用的Amazon Linux 2 AMI(ami-0aa7d40eeae50c9a9)默认已经预装了SSM代理,只要实例能访问SSM服务的端点(公网或VPC端点),就能被SSM管理。
  • 如果后续使用其他未预装SSM代理的系统(比如部分自定义镜像),可以在EC2资源的Properties里添加UserData字段来自动安装代理。

内容的提问来源于stack exchange,提问作者Geralt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 11:33:25