You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从指定aws_vpc_endpoint_service获取allowed_principals列表?

获取VPC端点服务允许的主体列表的方法

方法一:使用AWS CLI直接查询

通过describe-vpc-endpoint-services命令,指定目标VPC端点服务的ID,即可返回包含AllowedPrincipals字段的结果:

aws ec2 describe-vpc-endpoint-services --service-ids svc-xxxxxx

在输出的ServiceDetails数组中,对应服务的AllowedPrincipals字段就是你需要的允许主体列表。

方法二:通过AWS SDK编写脚本查询

以Python的boto3 SDK为例,编写简单脚本获取列表:

import boto3

# 初始化EC2客户端
ec2_client = boto3.client('ec2')

# 指定目标服务ID
target_service_id = 'svc-xxxxxx'

# 查询服务详情
response = ec2_client.describe_vpc_endpoint_services(ServiceIds=[target_service_id])

# 提取并打印允许的主体列表
for service_detail in response['ServiceDetails']:
    print("允许的主体列表:", service_detail['AllowedPrincipals'])

方法三:在Terraform中使用外部数据源获取

如果是在Terraform环境中,由于aws_vpc_endpoint_service数据源不返回该字段,可以通过external数据源调用外部脚本获取:

Terraform配置示例

data "external" "vpc_endpoint_allowed_principals" {
  program = ["python3", "${path.module}/fetch_allowed_principals.py"]

  query = {
    service_id = "svc-xxxxxx"
  }
}

# 输出允许的主体列表
output "allowed_principals" {
  value = jsondecode(data.external.vpc_endpoint_allowed_principals.result).allowed_principals
}

对应的Python脚本(fetch_allowed_principals.py)

import json
import boto3
import sys

def main():
    # 读取Terraform传入的查询参数
    input_data = json.load(sys.stdin)
    service_id = input_data['service_id']

    ec2_client = boto3.client('ec2')
    response = ec2_client.describe_vpc_endpoint_services(ServiceIds=[service_id])
    
    # 提取允许的主体列表并返回JSON格式结果
    allowed_principals = response['ServiceDetails'][0]['AllowedPrincipals']
    print(json.dumps({"allowed_principals": allowed_principals}))

if __name__ == "__main__":
    main()

内容的提问来源于stack exchange,提问作者Leo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 01:31:03