AWS CDK创建OpenSearch域时VPC子网CIDR冲突问题解决
问题
在AWS CDK的VPC中创建OpenSearch域时遇到CIDR冲突问题,代码如下:
var vpc = new Vpc(scope, "Vpc"); var subnet = new Subnet(scope, "Subnet", new SubnetProps { VpcId = vpc.VpcId, CidrBlock = "10.0.1.0/24", AvailabilityZone = "us-east-1a" }); var domain = new Domain(scope, "Domain", new DomainProps { Vpc = vpc, VpcSubnets = new SubnetSelection[] { new SubnetSelection { Subnets = new Subnet[] { subnet } } }, SecurityGroups = new SecurityGroup[] { new SecurityGroup(scope, "SecurityGroup", new SecurityGroupProps { Vpc = vpc }) }, // other property initializations are omitted }
收到错误提示:The CIDR '10.0.1.0/24' conflicts with another subnet。明明创建的是全新VPC且仅手动创建了一个子网,却出现冲突,推测存在隐式创建的子网,需要解决该问题,且无需多可用区部署,只需将域部署在单个子网中。
解决方案
冲突原因:使用
new Vpc(scope, "Vpc")默认创建VPC时,CDK会自动在每个可用区生成公有、私有、隔离三类子网,这些隐式子网已经占用了10.0.1.0/24这类常规CIDR段,导致手动创建的子网CIDR冲突。解决方法1:禁用自动子网,手动定义单可用区子网
创建Vpc时通过配置关闭自动子网生成,仅定义单个可用区的目标子网:var vpc = new Vpc(scope, "Vpc", new VpcProps { MaxAzs = 1, // 限制为单个可用区 SubnetConfiguration = new List<SubnetConfiguration> { new SubnetConfiguration { Name = "OpenSearchSubnet", SubnetType = SubnetType.PRIVATE_ISOLATED, // OpenSearch建议用隔离/私有子网 CidrMask = 24 } } });之后直接引用该子网部署OpenSearch,无需手动创建
Subnet实例:var domain = new Domain(scope, "Domain", new DomainProps { Vpc = vpc, VpcSubnets = new[] { new SubnetSelection { SubnetType = SubnetType.PRIVATE_ISOLATED // 匹配上面定义的子网类型 } }, SecurityGroups = new[] { new SecurityGroup(scope, "SecurityGroup", new SecurityGroupProps { Vpc = vpc }) }, // 其他配置项 });解决方法2:复用CDK默认子网,指定单可用区
若无需自定义CIDR,直接复用CDK默认创建的子网,限制可用区数量并指定子网类型即可:var vpc = new Vpc(scope, "Vpc", new VpcProps { MaxAzs = 1 // 仅使用1个可用区 }); var domain = new Domain(scope, "Domain", new DomainProps { Vpc = vpc, VpcSubnets = new[] { new SubnetSelection { AvailabilityZones = new[] { "us-east-1a" }, SubnetType = SubnetType.PRIVATE_ISOLATED } }, // 其他配置项 });注意事项:OpenSearch域部署到VPC时,不能使用公有子网,必须选择私有子网或隔离子网,确保子网类型符合要求。
内容的提问来源于stack exchange,提问作者user246392
相关产品推荐
相关产品推荐

