CloudFormation部署异常:EC2无法识别VPC且无法启动
问题分析与修复方案
我帮你排查了CloudFormation模板和可能的问题点,主要有几个关键问题导致EC2实例无法在VPC中启动:
1. VPC租户类型与实例类型不兼容
你的VPC设置了InstanceTenancy: dedicated(专用租户),但你选择的t2.micro实例类型不支持专用租户模式。AWS的专用租户VPC仅支持特定实例类型(比如C5、M5等系列的部分实例),t2系列属于共享租户实例,无法在专用租户VPC中启动,这是导致实例启动失败的核心原因之一。
2. 过时的AMI ID
你使用的ami-c29e1cb8是一个旧的Amazon Linux AMI,这个镜像在us-east-1区域已经被AWS移除或不再可用。使用无效的AMI ID会直接导致EC2实例无法创建。
3. 可选优化:资源定义顺序(非致命但建议调整)
虽然CloudFormation会自动解析资源依赖,但你的AppNode(EC2实例)定义在AppNodeSG(安全组)之前,建议将安全组定义放在实例前面,让模板结构更清晰,避免潜在的依赖解析问题。
修复后的完整模板
AWSTemplateFormatVersion: '2010-09-09' Resources: # VPC 创建 - 修改租户类型为默认共享 VPC: Type: AWS::EC2::VPC Properties: CidrBlock: 10.0.0.0/16 EnableDnsSupport: 'true' EnableDnsHostnames: 'true' InstanceTenancy: default # 改为默认共享租户,适配t2.micro Tags: - Key: test Value: test1 # 互联网网关创建 InternetGateway: Type: AWS::EC2::InternetGateway VPCGatewayAttachment: Type: AWS::EC2::VPCGatewayAttachment Properties: VpcId: !Ref VPC InternetGatewayId: !Ref InternetGateway SubnetA: Type: AWS::EC2::Subnet Properties: AvailabilityZone: us-east-1a VpcId: !Ref VPC CidrBlock: 10.0.0.0/20 MapPublicIpOnLaunch: true SubnetB: Type: AWS::EC2::Subnet Properties: AvailabilityZone: us-east-1b VpcId: !Ref VPC CidrBlock: 10.0.16.0/20 MapPublicIpOnLaunch: true SubnetC: Type: AWS::EC2::Subnet Properties: AvailabilityZone: us-east-1c VpcId: !Ref VPC CidrBlock: 10.0.32.0/20 MapPublicIpOnLaunch: true RouteTable: Type: AWS::EC2::RouteTable Properties: VpcId: !Ref VPC InternetRoute: Type: AWS::EC2::Route DependsOn: InternetGateway Properties: DestinationCidrBlock: 0.0.0.0/0 GatewayId: !Ref InternetGateway RouteTableId: !Ref RouteTable SubnetARouteTableAssociation: Type: AWS::EC2::SubnetRouteTableAssociation Properties: RouteTableId: !Ref RouteTable SubnetId: !Ref SubnetA SubnetBRouteTableAssociation: Type: AWS::EC2::SubnetRouteTableAssociation Properties: RouteTableId: !Ref RouteTable SubnetId: !Ref SubnetB SubnetCRouteTableAssociation: Type: AWS::EC2::SubnetRouteTableAssociation Properties: RouteTableId: !Ref RouteTable SubnetId: !Ref SubnetC # 先定义安全组,再定义EC2实例 AppNodeSG: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: Test Ec2 ssh and VPC VpcId: !Ref VPC SecurityGroupIngress: - IpProtocol: tcp CidrIp: 0.0.0.0/0 FromPort: '22' ToPort: '22' - IpProtocol: tcp CidrIp: 0.0.0.0/0 FromPort: '80' ToPort: '80' # EC2实例 - 更新为us-east-1区域可用的Amazon Linux 2 AMI AppNode: Type: AWS::EC2::Instance Properties: InstanceType: t2.micro ImageId: ami-0c7217cdde317cfec # us-east-1区域的Amazon Linux 2 AMI(建议按需验证最新AMI) KeyName: test_devops_east_1 AvailabilityZone: us-east-1c SecurityGroupIds: - !Ref AppNodeSG SubnetId: !Ref SubnetC
执行命令说明
你的创建命令是正确的,修复模板后可以直接使用:
aws cloudformation create-stack --stack-name test --template-body file://~/Downloads/CFT/stack.yml --profile devops --region us-east-1
如果之前的栈创建失败,建议先删除旧栈再重新创建:
aws cloudformation delete-stack --stack-name test --profile devops --region us-east-1
额外提示
- AMI ID会随时间更新,你可以通过AWS控制台或
aws ec2 describe-images命令获取us-east-1区域最新的Amazon Linux 2 AMI ID。 - 如果你确实需要使用专用租户VPC,请更换为支持专用租户的实例类型(比如
t3.small及以上部分实例,或C5/M5系列)。
内容的提问来源于stack exchange,提问作者user9075162
相关产品推荐
相关产品推荐

