使用CloudFormation部署Fargate:是否需单独网络栈?单栈能否兼顾参数与自建网络?
CloudFormation部署Fargate网络资源相关问题解答
问题背景
我计划用CloudFormation将Fargate实例部署到子网,希望允许用户通过参数选择部署目标的VPC ID和子网ID,参数定义如下:
Parameters: VPCSubnets: Type: List<AWS::EC2::Subnet::Id> Description: Provide the subnets you wish to deploy into. VPCInformation: Type: AWS::EC2::VPC::Id Description: Provide the VPC ID that resources will be deployed into.
该参数将用于ECS及任务定义的网络配置。同时我想在模板的参数下方添加自建的网络资源,示例如下:
MyVpc: Type: AWS::EC2::VPC Description: VPC for the cluster and fargate instances Properties: CidrBlock: 10.0.0.0/26 EnableDnsSupport: true EnableDnsHostnames: true Tags: - Key: interviewchallenge-vpc Value: !Join ['', [!Ref "AWS::Region", "conversion-challenge-VPC" ]] PublicSubnet1: Type: AWS::EC2::Subnet Properties: VpcId: Ref: myVPC CidrBlock: 10.0.0.0/28 AvailabilityZone: "us-east-1a" Tags: - Key: interviewchallenge-vpc-subnet1 Value: !Join ['', [!Ref "AWS::Region", "conversion-challenge-az1" ]]
问题列表
- 是否需要单独创建网络堆栈才能让该CloudFormation YAML文件生效?
- 能否在单个堆栈中同时实现让用户选择已有网络资源和创建新网络资源的需求?
- 在模板中定义这些网络资源时,它们是否尚未创建?
解答
1. 是否需要单独创建网络堆栈?
不需要单独创建网络堆栈。当前模板直接部署的话,CloudFormation会尝试创建你定义的MyVpc和PublicSubnet1,但同时又要求用户输入已有VPC和子网参数,这会导致逻辑冲突——模板既会新建网络资源,又试图使用用户指定的已有资源,最终部署会失败。但核心结论是不需要单独堆栈就能让文件生效,只是当前模板的逻辑存在矛盾,需要调整。
2. 能否在单个堆栈中同时支持选择已有资源和创建新资源?
完全可以实现。你需要添加一个模式选择参数,让用户指定是使用已有网络还是创建新网络,再结合CloudFormation的**条件判断(Conditions)**和Fn::If函数来控制资源的创建和引用:
- 当用户选择创建新网络时,模板自动生成
MyVpc和PublicSubnet1,并将Fargate的网络配置指向这些新建资源; - 当用户选择使用已有网络时,模板跳过新建网络资源的步骤,直接使用用户输入的
VPCInformation和VPCSubnets参数。
示例配置片段如下:
Parameters: # 新增模式选择参数 NetworkDeploymentMode: Type: String Default: CreateNew AllowedValues: - CreateNew - UseExisting # 原有参数添加条件,仅在使用已有网络时必填 VPCSubnets: Type: List<AWS::EC2::Subnet::Id> Description: Provide the subnets you wish to deploy into. Condition: UseExistingNetwork VPCInformation: Type: AWS::EC2::VPC::Id Description: Provide the VPC ID that resources will be deployed into. Condition: UseExistingNetwork Conditions: CreateNewNetwork: !Equals [!Ref NetworkDeploymentMode, CreateNew] UseExistingNetwork: !Equals [!Ref NetworkDeploymentMode, UseExisting] Resources: MyVpc: Type: AWS::EC2::VPC Condition: CreateNewNetwork # 保留原有Properties配置... PublicSubnet1: Type: AWS::EC2::Subnet Condition: CreateNewNetwork # 保留原有Properties配置... # ECS服务的网络配置通过Fn::If动态选择资源 ECSClusterService: Type: AWS::ECS::Service Properties: NetworkConfiguration: AwsvpcConfiguration: Subnets: !If - CreateNewNetwork - [!Ref PublicSubnet1] - !Ref VPCSubnets VpcId: !If - CreateNewNetwork - !Ref MyVpc - !Ref VPCInformation
3. 模板中定义的网络资源是否尚未创建?
是的。模板里的资源定义只是声明性的配置描述,只有当你执行CloudFormation堆栈创建或更新操作时,CloudFormation才会根据模板定义在你的AWS账户中实际创建这些资源。在堆栈部署完成前,这些资源都不存在;如果部署失败,CloudFormation会自动回滚清理已创建的部分资源。
内容的提问来源于stack exchange,提问作者masafood
相关产品推荐
相关产品推荐

