You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudFormation模板创建安全组触发InvalidGroup.NotFound错误排查

故障分析

错误性质

该问题不属于循环依赖,是安全组所属VPC不匹配导致的配置错误。

错误原因

你收到的You have specified two resources that belong to different networks报错,根因是两个安全组被创建到了不同的VPC中:

  • IsolatedSecurityGroup的配置中明确指定了VpcId: !Ref VpcId,会按照你传入的VPC参数创建到目标VPC内。
  • ForensicSecurityGroup的配置中未指定VpcId属性,AWS CloudFormation创建安全组时如果未声明VpcId,会默认将安全组创建到当前区域的默认VPC中。
    当你传入的VpcId参数不是当前区域的默认VPC ID时,两个安全组分属不同网络,此时在IsolatedSecurityGroup的入站规则中直接引用另一个VPC的安全组ID作为访问源,就会触发EC2返回的InvalidGroup.NotFound错误。

修复方案

给ForensicSecurityGroup补充VpcId配置,和IsolatedSecurityGroup指定为同一个VPC即可,修改后的配置片段如下:

ForensicSecurityGroup:
  Type: AWS::EC2::SecurityGroup
  Properties:
    GroupDescription: Security group for forensic EC2 instances
    VpcId: !Ref VpcId # 新增该行,指定安全组所属VPC
    SecurityGroupIngress:
      - Description: Allow SSH from company ip address
        CidrIp: !Ref SSHLocation
        IpProtocol: tcp
        FromPort: 22
        ToPort: 22
    Tags:
      - Key: Purpose
        Value: !Ref PurposeTag

补充说明

如果确实需要跨VPC引用安全组作为访问源,需要先打通两个VPC的对等连接,且引用时填写完整的安全组ARN而非ID。你的取证基础设施场景下,两个安全组部署在同一个VPC即可满足需求。

内容的提问来源于stack exchange,提问作者abhinav singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.29 12:18:03