You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Lambda模板SubnetIds与SecurityGroupIds配置报错排查求助

问题分析与解决:SAM模板VPC配置验证错误

你遇到的问题其实是VpcConfig里的SubnetIds和SecurityGroupIds搞混了!

看错误提示就能找到关键:

Value '[subnet-061328bxxxxx]' at 'vpcConfig.securityGroupIds' failed to satisfy constraint: Member must satisfy regular expression pattern: ^sg-[0-9a-z]$
Value '[sg-03afd77xxxxx]' at 'vpcConfig.subnetIds' failed to satisfy constraint: Member must satisfy regular expression pattern: ^subnet-[0-9a-z]
$

简单来说,你把子网ID(subnet-xxx格式)放到了SecurityGroupIds字段里,把安全组ID(sg-xxx格式)放到了SubnetIds字段里,完全弄反了两者的对应关系,自然触发了正则约束的验证失败。

修正后的SAM模板

只需要把VpcConfig下两个字段的内容互换即可:

Resources:
  TagChangedFunction:
    Type: AWS::Serverless::Function
    Properties:
      CodeUri: tag_changed_function
      Handler: tag_changed/app.lambda_handler
      Runtime: python3.8
      Policies:
        - VPCAccessPolicy: {}
        - Statement:
            - Sid: EC2DescribeInstancesPolicy
              Effect: "Allow"
              Action:
                - ec2:DescribeInstances
              Resource: '*'
      VpcConfig:
        SubnetIds:
          - subnet-03afd77xxxxx  # 这里放置子网ID
        SecurityGroupIds:
          - sg-061328bxxxxx      # 这里放置安全组ID
      Events:
        TagChanged:
          Type: CloudWatchEvent
          Properties:
            Pattern:
              source:
                - aws.tag
              detail-type:
                - Tag Change on Resource

修正后每个字段的值都匹配了对应的格式要求,就能正常完成代码上传和部署了。

内容的提问来源于stack exchange,提问作者Ivan C Myrvold

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 12:07:30