如何在CloudFormation中获取Route53所需的VPC Endpoint DNS名称
解决CloudFormation中VPC Endpoint与Route53 RecordSet的关联问题
问题根源
你之前的写法出错,核心原因是对VPC Endpoint的DnsEntries结构理解偏差:它并非冒号分隔的字符串列表,而是对象列表,每个对象包含DnsName和HostedZoneId两个独立属性,不是你误以为的冒号拼接字符串。
正确实现方式
直接通过索引访问第一个DnsEntry的DnsName属性即可,无需Split操作。修正后的RecordSet定义如下:
Domain: Type: AWS::Route53::RecordSet Properties: AliasTarget: DNSName: !GetAtt VPCEndpoint.DnsEntries[0].DnsName HostedZoneId: !GetAtt VPCEndpoint.DnsEntries[0].HostedZoneId HostedZoneId: !Ref HostedZoneId Name: !Ref DomainName Type: A
如果需要兼容旧版CloudFormation语法,也可以用函数组合写法:
Domain: Type: AWS::Route53::RecordSet Properties: AliasTarget: DNSName: !Select [0, !GetAtt VPCEndpoint.DnsEntries] HostedZoneId: !Select [0, !GetAtt VPCEndpoint.HostedZoneIds] HostedZoneId: !Ref HostedZoneId Name: !Ref DomainName Type: A
补充说明
- VPC Endpoint的
DnsEntries每个元素结构为{ "DnsName": "xxx", "HostedZoneId": "yyy" },因此可以直接通过.DnsEntries[0].DnsName提取第一个条目域名 - AliasTarget的
HostedZoneId建议使用VPC Endpoint对应条目的HostedZoneId,而非自定义的HostedZoneId(特殊场景除外)
内容的提问来源于stack exchange,提问作者user4093955
相关产品推荐
相关产品推荐

