You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CloudFormation模板中引用AWS CLI输出的Lambda Layer ARN

在CloudFormation中引用Lambda Layer ARN的正确方式

CloudFormation本身无法直接执行AWS CLI命令,直接写入模板会被当作字符串处理,你可以通过以下几种方式实现需求:

方法1:参数传递(最直接)

先手动执行CLI获取ARN,再通过参数传入CloudFormation模板:

  1. 执行CLI命令拿到纯ARN字符串(加--output text避免引号干扰):
aws lambda list-layer-versions --layer-name my-custom-lambda-layer --region us-east-1 --query 'LayerVersions[0].LayerVersionArn' --output text
  1. 在CloudFormation模板中定义参数:
Parameters:
  CustomLayerArn:
    Type: String
    Description: ARN of the custom Lambda Layer
  1. 在Lambda函数的Layers字段引用该参数:
Resources:
  TargetLambdaFunction:
    Type: AWS::Lambda::Function
    Properties:
      # 其他配置(运行时、代码、角色等)
      Layers:
        - !Ref CustomLayerArn
  1. 部署栈时传入参数值(也可以直接把CLI命令结果嵌入部署命令):
aws cloudformation deploy --stack-name my-target-stack --template-file template.yaml --parameter-overrides CustomLayerArn="$(aws lambda list-layer-versions --layer-name my-custom-lambda-layer --region us-east-1 --query 'LayerVersions[0].LayerVersionArn' --output text)" --region us-east-1

方法2:自定义资源(自动获取最新ARN)

如果想让CloudFormation自动拉取最新的Layer ARN,可以用自定义资源实现:

  1. 创建一个用于获取Layer ARN的Lambda函数:
import boto3
import cfnresponse

lambda_client = boto3.client('lambda', region_name='us-east-1')

def handler(event, context):
    try:
        layer_name = event['ResourceProperties']['LayerName']
        resp = lambda_client.list_layer_versions(LayerName=layer_name)
        latest_arn = resp['LayerVersions'][0]['LayerVersionArn']
        cfnresponse.send(event, context, cfnresponse.SUCCESS, {'LayerArn': latest_arn})
    except Exception as e:
        cfnresponse.send(event, context, cfnresponse.FAILED, {'ErrorMsg': str(e)})
  1. 在CloudFormation模板中定义自定义资源并引用其输出:
Resources:
  # 自定义资源的执行Lambda
  LayerArnFetcher:
    Type: AWS::Lambda::Function
    Properties:
      Runtime: python3.11
      Handler: index.handler
      Role: !Sub arn:aws:iam::${AWS::AccountId}:role/lambda-custom-resource-role
      Code:
        ZipFile: |
          # 粘贴上面的Python代码
  # 自定义资源,用于获取Layer ARN
  FetchLatestLayerArn:
    Type: Custom::GetLayerArn
    Properties:
      ServiceToken: !GetAtt LayerArnFetcher.Arn
      LayerName: my-custom-lambda-layer
  # 目标Lambda函数
  TargetLambdaFunction:
    Type: AWS::Lambda::Function
    Properties:
      # 其他配置
      Layers:
        - !GetAtt FetchLatestLayerArn.LayerArn

注意:需要给lambda-custom-resource-role角色添加lambda:ListLayerVersions权限。

方法3:使用AWS SAM(简化流程)

如果用AWS SAM模板,可以结合参数和CLI命令预生成版本号:

Parameters:
  LatestLayerVersion:
    Type: String
    Default: !Sub "$(aws lambda list-layer-versions --layer-name my-custom-lambda-layer --region ${AWS::Region} --query 'LayerVersions[0].Version' --output text)"

Resources:
  TargetLambdaFunction:
    Type: AWS::Serverless::Function
    Properties:
      # 其他配置
      Layers:
        - !Sub arn:aws:lambda:${AWS::Region}:${AWS::AccountId}:layer:my-custom-lambda-layer:${LatestLayerVersion}

部署时SAM会自动解析CLI命令结果作为参数值。


内容的提问来源于stack exchange,提问作者SUBHASHC37

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 06:30:50