You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Serverless为自动生成的自定义资源Lambda添加标签与配置VPC

解决Serverless自动生成的Lambda的标签与VPC配置问题

你提到的这个自动命名Lambda是Serverless框架为处理APIGateway CloudWatch日志角色配置生成的CloudFormation自定义资源(Custom Resource),这类框架内部的辅助资源默认不会继承provider下的标签和VPC配置,以下是具体的配置方案:

一、添加自定义标签

方案1:给栈内所有资源统一加标签

在serverless.yml的custom字段中配置cloudFormation.resourceTags,该配置会对栈内所有资源(包括这个自动Lambda)生效:

custom:
  cloudFormation:
    resourceTags:
      Environment: production
      Project: my-api-service

方案2:仅给该自动Lambda单独加标签

通过resources.Resources覆盖框架生成的Lambda资源逻辑,添加专属标签。该自动Lambda的逻辑ID为CustomDashResourceDashApiDashGatewayDashAccountDashCloudWatchDashRoleLambdaFunction(由你提供的Lambda代码中handlerWrapper的参数生成):

resources:
  Resources:
    CustomDashResourceDashApiDashGatewayDashAccountDashCloudWatchDashRoleLambdaFunction:
      Properties:
        Tags:
          - Key: Owner
            Value: dev-team
          - Key: ResourceType
            Value: serverless-custom-resource

二、配置VPC

同样需要通过resources.Resources覆盖Lambda的VPC配置,provider.vpc仅对业务Lambda生效。配置时注意:该Lambda需要访问IAM和APIGateway服务,若使用私有子网需配置NAT网关或对应AWS服务的VPC端点,否则会导致部署失败。

resources:
  Resources:
    CustomDashResourceDashApiDashGatewayDashAccountDashCloudWatchDashRoleLambdaFunction:
      Properties:
        VpcConfig:
          SecurityGroupIds:
            - sg-xxxxxxxxx
          SubnetIds:
            - subnet-xxxxxxxxx
            - subnet-yyyyyyyyy

说明:为何provider下的配置不生效?

Serverless框架的provider.tags和provider.vpc默认仅作用于你显式定义的业务Lambda(即functions字段下配置的资源),框架自动生成的辅助资源属于内部管理的基础设施组件,不会继承这些全局配置,必须通过上述方式单独配置。

内容的提问来源于stack exchange,提问作者Joey Yi Zhao

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 05:55:40