You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求可获取公网IP、VPC、实例状态及名称的AWS CLI审计命令

AWS EC2 Describe Instances: Filter Running Instances & Add VPC, State, Name Details

Got it, let's get this sorted for your audit work—here's exactly what you need, broken down step by step:

Final Working Command

aws ec2 describe-instances \
  --filter "Name=instance-state-name,Values=running" \
  --query "Reservations[*].Instances[*].[PublicIpAddress, VpcId, State.Name, Tags[?Key=='Name'].Value|[0]]" \
  --output=text

Let's Break This Down:

  1. Adding the --filter for Running Instances
    The --filter flag uses the format Name=FIELD_NAME,Values=TARGET_VALUE. For instance state, the field is instance-state-name, and we want the value running. You can place this flag right after describe-instances (the order of flags like --filter and --query doesn't matter much, but this is the most intuitive placement).

  2. Expanding the --query to Include Your Required Fields
    We updated the query to pull 4 key pieces of info for your audit:

    • PublicIpAddress: Your original public IP field
    • VpcId: The ID of the VPC the instance belongs to
    • State.Name: The instance state (we already filtered for running, but including this makes the audit output explicit)
    • Tags[?Key=='Name'].Value|[0]: Extracts the instance's "Name" tag. The |[0] ensures we get a single value instead of an array (even if the instance has no Name tag, it'll return an empty string instead of a blank array).
  3. Output Format
    Keeping --output=text ensures the results are space-separated, which is easy to parse into spreadsheets or audit tools. If you prefer a more human-readable format for quick checks, swap it with --output=table.

Bonus Tip: Handling Instances Without Public IPs

If you want to exclude instances that don't have a public IP (common in private subnets), tweak the query to filter those out:

aws ec2 describe-instances \
  --filter "Name=instance-state-name,Values=running" \
  --query "Reservations[*].Instances[?PublicIpAddress != null].[PublicIpAddress, VpcId, State.Name, Tags[?Key=='Name'].Value|[0]]" \
  --output=text

内容的提问来源于stack exchange,提问作者Craigus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 09:13:17