能否将参数JSON文件传入AWS::CloudFormation::Stack资源?
在AWS::CloudFormation::Stack资源中复用JSON参数文件的解决方案
AWS::CloudFormation::Stack(嵌套栈)的Parameters属性要求是键值对对象,而非命令行create-stack命令使用的数组格式。下面提供两种可行方案,帮你复用现有的JSON参数文件:
方案1:CLI转换参数格式后传递给父栈
先把你现有的数组格式参数文件转换成嵌套栈需要的键值对格式,再通过父栈传递给嵌套栈:
- 转换参数文件格式
用jq工具将数组格式的参数文件转为键值对JSON:
jq 'from_entries' VPC-parameters.json > nested-params.json
转换后的nested-params.json内容如下:
{ "VPCId": "demoVPC1ID", "GatewayId": "demoGatewayID" }
- 编写父栈模板
在父栈模板中定义参数,接收转换后的参数值并传递给嵌套栈:
# parent-stack.yml Parameters: VPCId: Type: String GatewayId: Type: String Resources: MyNestedVPCStack: Type: AWS::CloudFormation::Stack Properties: TemplateURL: https://s3.amazonaws.com/your-bucket/VPC.yml Parameters: VPCId: !Ref VPCId GatewayId: !Ref GatewayId
- 创建父栈并引用参数文件
用CLI创建父栈时,直接引用转换后的参数文件:
aws cloudformation create-stack --stack-name ParentVPCStack --template-body file://parent-stack.yml --parameters file://nested-params.json
方案2:通过Lambda自定义资源读取S3上的参数文件
如果想让CloudFormation自动读取S3存储的参数文件,无需手动转换格式,可以借助Lambda自定义资源实现:
- 编写父栈模板
模板中包含Lambda函数(用于读取解析S3参数文件)、自定义资源(调用Lambda)和嵌套栈(引用解析后的参数):
# parent-stack-with-lambda.yml Resources: ParamReaderLambda: Type: AWS::Lambda::Function Properties: Runtime: python3.11 Handler: index.lambda_handler Role: !GetAtt ParamReaderLambdaRole.Arn Code: ZipFile: | import json import boto3 import cfnresponse s3 = boto3.client('s3') def lambda_handler(event, context): try: bucket = event['ResourceProperties']['Bucket'] key = event['ResourceProperties']['Key'] response = s3.get_object(Bucket=bucket, Key=key) params_array = json.loads(response['Body'].read().decode('utf-8')) params_dict = {p['ParameterKey']: p['ParameterValue'] for p in params_array} cfnresponse.send(event, context, cfnresponse.SUCCESS, params_dict) except Exception as e: cfnresponse.send(event, context, cfnresponse.FAILED, {'Error': str(e)}) ParamReaderLambdaRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: lambda.amazonaws.com Action: sts:AssumeRole Policies: - PolicyName: S3ReadAccess PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: s3:GetObject Resource: arn:aws:s3:::your-s3-bucket-name/VPC-parameters.json GetParams: Type: Custom::ParameterReader Properties: ServiceToken: !GetAtt ParamReaderLambda.Arn Bucket: your-s3-bucket-name Key: VPC-parameters.json MyNestedVPCStack: Type: AWS::CloudFormation::Stack Properties: TemplateURL: https://s3.amazonaws.com/your-bucket/VPC.yml Parameters: !GetAtt GetParams.Data
- 创建父栈
直接执行CLI命令创建栈,CloudFormation会自动调用Lambda读取解析S3上的参数文件:
aws cloudformation create-stack --stack-name ParentVPCStack --template-body file://parent-stack-with-lambda.yml
方案对比
- 方案1简单高效,无需额外资源,适合大多数场景;
- 方案2实现全自动化参数读取,适合需要动态加载S3参数文件的场景,但需要管理Lambda及相关IAM权限。
内容的提问来源于stack exchange,提问作者Elsabath Puthumana
相关产品推荐
相关产品推荐

