CloudFormation模板参数配置错误排查:调用CreateStack遇ValidationError
问题排查与修复方案
错误原因拆解
- CloudFormation模板语法错误:模板中
Username参数的Default字段使用了非法语法!Ref ${ParameterValue},CloudFormation要求Default必须是字符串类型,该写法直接触发模板格式验证失败。 - Bash脚本变量赋值错误:脚本里
$stack_name="IAM-IA-Account"的写法不符合Bash语法,变量赋值时不能在变量名前加$,否则会被解析为命令执行而非变量赋值。 - IAM用户名称硬编码:模板中IAM用户的
UserName被固定为"iaaccount",无法根据传入的参数动态生成目标用户名,不符合需求。
修复步骤
1. 修正Bash脚本
移除变量名前的$,修正赋值语法:
#!/usr/bin/env bash stack_name="IAM-IA-Account" username=$1 echo "Creating CloudFormation..." aws cloudformation create-stack --stack-name $stack_name --parameters ParameterKey=Username,ParameterValue=$username --capabilities CAPABILITY_NAMED_IAM --template-body file://cloudformation/setup-iam.yaml
2. 修正CloudFormation模板
- 移除
Username参数中错误的Default字段(若无需默认值),或设置合法字符串默认值(例如"default-user"); - 将IAM用户的
UserName改为引用Username参数,实现动态生成用户名:
AWSTemplateFormatVersion: '2010-09-09' Description: 'Set up the IA user.' Parameters: Username: Type: String Description: New account username MinLength: '4' MaxLength: '512' ConstraintDescription: the username must be between 4 and 512 characters Resources: iaaccount: Type: AWS::IAM::User Properties: UserName: !Ref Username # 保留后续其他资源配置
测试验证
执行修正后的脚本并传入参数:
./ec2-setup.sh meesho
此时CloudFormation会正常创建栈,并生成名为meesho的IAM用户。
内容的提问来源于stack exchange,提问作者Mark Andrew
相关产品推荐
相关产品推荐

