You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CloudFormation模板创建RDS失败:安全组引用错误排查修复

问题分析与修复方案

Hey there, let's break down what's causing your CloudFormation deployment to fail and how to fix it.

错误原因

Looking at your error log:

Invalid id: "patheindirectory-WebServerSecurityGroup-9KMFVDEWRVSF" (expecting "sg-...")

This happens because your security groups are being created in EC2 Classic Network (you didn't specify a VpcId in your security group resources, so CloudFormation defaults to classic network). In classic network mode, you can't reference another security group using SourceSecurityGroupId—that field is reserved for VPC security groups (which use the sg-xxxxxx ID format). Classic network security groups require you to reference by name instead, and you need to specify your AWS account ID to ensure you're targeting your own security group.

Alternatively, you could switch to using VPC security groups (the recommended approach, since EC2 Classic is being phased out), where SourceSecurityGroupId works correctly.


修复方案

Modern AWS infrastructure should use VPCs, so this is the best long-term fix. Here's how to adjust your template:

  1. Add a VpcId parameter to let you specify the target VPC (you can use your default VPC if you don't have a custom one):
Parameters:
  # ... keep all your existing parameters ...
  VpcId:
    Type: AWS::EC2::VPC::Id
    Description: The VPC where you want to deploy your resources
  1. Update both security groups to include the VpcId property:
WebServerSecurityGroup:
  Type: AWS::EC2::SecurityGroup
  Properties:
    GroupDescription: Security Group for EC2 instances
    VpcId: !Ref VpcId # Add this line
    SecurityGroupIngress:
      - IpProtocol: tcp
        FromPort: '80'
        ToPort: '80'
        CidrIp: 0.0.0.0/0
      - IpProtocol: tcp
        FromPort: '22'
        ToPort: '22'
        CidrIp: !Ref SSHLocation

DBSecurityGroup:
  Type: AWS::EC2::SecurityGroup
  Properties:
    GroupDescription: Database security group
    VpcId: !Ref VpcId # Add this line
    SecurityGroupIngress:
      - IpProtocol: tcp
        FromPort: '3306'
        ToPort: '3306'
        SourceSecurityGroupId: !Ref WebServerSecurityGroup # This works in VPC mode

When you deploy this, CloudFormation will create VPC security groups (with sg-xxxxxx IDs), and the SourceSecurityGroupId reference will resolve correctly.


If you need to stick with classic network, modify the DBSecurityGroup ingress rule to use the security group name and your account ID:

DBSecurityGroup:
  Type: AWS::EC2::SecurityGroup
  Properties:
    GroupDescription: Database security group
    SecurityGroupIngress:
      - IpProtocol: tcp
        FromPort: '3306'
        ToPort: '3306'
        SourceSecurityGroupName: !Ref WebServerSecurityGroup # Use name instead of ID
        SourceSecurityGroupOwnerId: !Ref AWS::AccountId # Specify your account ID to avoid ambiguity

This tells AWS to allow traffic from your WebServerSecurityGroup (by name) in your own account, which will resolve the malformed ID error.


Final Note

I strongly recommend going with Option 1—VPCs offer better security, isolation, and functionality compared to EC2 Classic. Plus, EC2 Classic is being deprecated in most regions, so moving to VPC will future-proof your infrastructure.

内容的提问来源于stack exchange,提问作者Wai Yan Hein

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 22:22:43