You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否在AWS CloudFormation的!Sub内置函数中使用环境变量?

关于AWS CloudFormation !Sub函数读取Java环境变量的问题

!Sub函数无法直接读取Java项目的环境变量。

原因很直接:!Sub是AWS CloudFormation的内置函数,仅能解析CloudFormation上下文内的变量——包括模板定义的参数、伪参数(如AWS::REGION)、映射、栈输出等。它运行在AWS部署阶段,和本地Java项目的环境变量属于完全隔离的上下文,没法直接访问这类客户端/本地环境的变量。

可行的实现方法

1. 将TEST1作为CloudFormation参数传入

把Java环境变量的值作为参数传递给CloudFormation模板,再在!Sub中引用该参数:

示例模板:

Parameters:
  Test1Param:
    Type: String
    Description: 从Java环境变量TEST1传入的值

Resources:
  TargetIAMPolicy:
    Type: AWS::IAM::Policy
    Properties:
      PolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Action: "s3:*"
            Resource: !Sub 'arn:aws:s3:::example-${Test1Param}-${AWS::REGION}-test'
      # 关联到对应的IAM实体(用户/角色/组)
      Roles:
        - "MyTargetRole"

部署时传递参数:

通过AWS CLI部署时,直接把Java环境变量的值传给参数:

aws cloudformation deploy \
  --stack-name my-iam-policy-stack \
  --template-file your-template.yaml \
  --parameter-overrides Test1Param=$TEST1

2. 使用AWS CDK(基础设施即代码工具)

如果用AWS CDK管理IAM资源,可以直接在代码中读取Java环境变量,再生成对应的资源ARN:

示例Java CDK代码:

import software.amazon.awscdk.core.*;
import software.amazon.awscdk.services.iam.*;
import java.util.List;

public class IamPolicyStack extends Stack {
    public IamPolicyStack(final Construct scope, final String id) {
        this(scope, id, null);
    }

    public IamPolicyStack(final Construct scope, final String id, final StackProps props) {
        super(scope, id, props);

        // 读取本地Java环境变量TEST1
        String test1Value = System.getenv("TEST1");
        // 获取当前栈的AWS区域(等价于AWS::REGION伪参数)
        String awsRegion = Stack.of(this).getRegion();

        // 构建IAM策略语句
        PolicyStatement policyStmt = PolicyStatement.Builder.create()
                .effect(Effect.ALLOW)
                .actions(List.of("s3:*"))
                .resources(List.of(String.format("arn:aws:s3:::example-%s-%s-test", test1Value, awsRegion)))
                .build();

        // 创建IAM策略
        Policy.Builder.create(this, "ExampleS3Policy")
                .policyDocument(PolicyDocument.Builder.create()
                        .statements(List.of(policyStmt))
                        .build())
                .roles(List.of(Role.fromRoleName(this, "TargetRole", "MyTargetRole")))
                .build();
    }

    public static void main(final String[] args) {
        App app = new App();
        new IamPolicyStack(app, "IamPolicyStack");
        app.synth();
    }
}

运行CDK合成或部署时,会自动把TEST1环境变量的值注入到资源ARN中。

3. 通过部署脚本替换模板占位符

用Shell脚本先捕获Java环境变量的值,替换CloudFormation模板中的占位符后再部署:

示例脚本:

# 读取Java环境变量TEST1的值
TEST1_VAL=$TEST1

# 替换模板中的{{TEST1}}占位符(注意模板中不要用${TEST1}避免和CloudFormation变量冲突)
sed "s/{{TEST1}}/$TEST1_VAL/g" template-template.yaml > deploy-template.yaml

# 部署替换后的模板
aws cloudformation deploy \
  --stack-name my-stack \
  --template-file deploy-template.yaml

对应的模板片段:

Resource:
  - !Sub 'arn:aws:s3:::example-{{TEST1}}-${AWS::REGION}-test'

内容的提问来源于stack exchange,提问作者user19882964

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 03:30:50