AWS新手求助:CloudFormation模板无法从S3复制文件到Windows实例
Hey there! Let's figure out why your JDK installer isn't being copied to your Windows EC2 instance. I’ve gone through your template and spotted several key issues that are probably causing this, plus some steps to diagnose further.
Key Issues in Your Template
1. You’re not triggering cfn-init
The biggest problem: CloudFormation doesn’t automatically run the AWS::CloudFormation::Init metadata unless you explicitly call it via UserData. Your template defines the config, but there’s no instruction for the instance to execute it. Without running cfn-init, none of the files will be downloaded, and your install script won’t run.
2. Incorrect syntax for commands section
Your commands block is formatted wrong. CloudFormation expects each command to have a unique identifier (like a numbered key) instead of a generic command key. This would cause the install step to fail even if the files were copied.
3. Potential IAM & S3 Access Gaps
While you mentioned using an IAM role with S3 full access, double-check:
- The role is properly attached to the instance (sometimes typos in the profile name happen)
- The S3 bucket policy (if any) allows the role to perform
s3:GetObjecton the JDK file - The bucket isn’t in a different region than the EC2 instance (this can cause access issues)
Fixed Template Snippet
Here’s the corrected version of your instance resource, with the critical additions:
Resources: JavaSeleniumEC2Instance: Type: 'AWS::EC2::Instance' Properties: KeyName: 'windowskeypair' ImageId: ami-0093d2a4365944361 InstanceType: 't2.micro' IamInstanceProfile: <Existing IAM Role which has EC2 Full access to S3> # Add UserData to trigger cfn-init UserData: Fn::Base64: !Sub | <script> powershell.exe -ExecutionPolicy RemoteSigned -Command "cfn-init -v -s ${AWS::StackId} -r JavaSeleniumEC2Instance -c config --region ${AWS::Region}" </script> Metadata: 'AWS::CloudFormation::Init': config: files: c:\\jdk-11.0.9_windows-x64_bin.exe: source: "https://<mybucket>.s3.amazonaws.com/jdk-11.0.9_windows-x64_bin.exe" c:\\Install-Java-JDK.ps1: content: !Join - '' - - 'Set-Location C:\;' - '.\jdk-11.0.9_windows-x64_bin.exe /s' commands: # Unique identifier for the command 01_install_jdk: command: >- powershell.exe -ExecutionPolicy RemoteSigned -Command c:\\Install-Java-JDK.ps1 waitAfterCompletion: '60'
Troubleshooting Steps to Verify
If you still run into issues after updating the template, try these checks on the running instance:
- Check
cfn-initlogs: Look atC:\Program Files\Amazon\cfn-init\log\cfn-init.logfor errors related to downloading files or executing commands. - Test S3 access manually: Run this PowerShell command to see if the instance can reach the S3 file:
Invoke-WebRequest https://<mybucket>.s3.amazonaws.com/jdk-11.0.9_windows-x64_bin.exe -OutFile C:\test_jdk.exe - Confirm IAM role attachment: Run this to check if the instance has the correct role:
Get-EC2InstanceMetadata -Category IAM
内容的提问来源于stack exchange,提问作者user11833133

