You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudFormation部署异常:EC2无法识别VPC且无法启动

问题分析与修复方案

我帮你排查了CloudFormation模板和可能的问题点,主要有几个关键问题导致EC2实例无法在VPC中启动:

1. VPC租户类型与实例类型不兼容

你的VPC设置了InstanceTenancy: dedicated(专用租户),但你选择的t2.micro实例类型不支持专用租户模式。AWS的专用租户VPC仅支持特定实例类型(比如C5、M5等系列的部分实例),t2系列属于共享租户实例,无法在专用租户VPC中启动,这是导致实例启动失败的核心原因之一。

2. 过时的AMI ID

你使用的ami-c29e1cb8是一个旧的Amazon Linux AMI,这个镜像在us-east-1区域已经被AWS移除或不再可用。使用无效的AMI ID会直接导致EC2实例无法创建。

3. 可选优化:资源定义顺序(非致命但建议调整)

虽然CloudFormation会自动解析资源依赖,但你的AppNode(EC2实例)定义在AppNodeSG(安全组)之前,建议将安全组定义放在实例前面,让模板结构更清晰,避免潜在的依赖解析问题。


修复后的完整模板

AWSTemplateFormatVersion: '2010-09-09'
Resources:
  # VPC 创建 - 修改租户类型为默认共享
  VPC:
    Type: AWS::EC2::VPC
    Properties:
      CidrBlock: 10.0.0.0/16
      EnableDnsSupport: 'true'
      EnableDnsHostnames: 'true'
      InstanceTenancy: default  # 改为默认共享租户,适配t2.micro
      Tags:
        - Key: test
          Value: test1
  # 互联网网关创建
  InternetGateway:
    Type: AWS::EC2::InternetGateway
  VPCGatewayAttachment:
    Type: AWS::EC2::VPCGatewayAttachment
    Properties:
      VpcId: !Ref VPC
      InternetGatewayId: !Ref InternetGateway
  SubnetA:
    Type: AWS::EC2::Subnet
    Properties:
      AvailabilityZone: us-east-1a
      VpcId: !Ref VPC
      CidrBlock: 10.0.0.0/20
      MapPublicIpOnLaunch: true
  SubnetB:
    Type: AWS::EC2::Subnet
    Properties:
      AvailabilityZone: us-east-1b
      VpcId: !Ref VPC
      CidrBlock: 10.0.16.0/20
      MapPublicIpOnLaunch: true
  SubnetC:
    Type: AWS::EC2::Subnet
    Properties:
      AvailabilityZone: us-east-1c
      VpcId: !Ref VPC
      CidrBlock: 10.0.32.0/20
      MapPublicIpOnLaunch: true
  RouteTable:
    Type: AWS::EC2::RouteTable
    Properties:
      VpcId: !Ref VPC
  InternetRoute:
    Type: AWS::EC2::Route
    DependsOn: InternetGateway
    Properties:
      DestinationCidrBlock: 0.0.0.0/0
      GatewayId: !Ref InternetGateway
      RouteTableId: !Ref RouteTable
  SubnetARouteTableAssociation:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      RouteTableId: !Ref RouteTable
      SubnetId: !Ref SubnetA
  SubnetBRouteTableAssociation:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      RouteTableId: !Ref RouteTable
      SubnetId: !Ref SubnetB
  SubnetCRouteTableAssociation:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      RouteTableId: !Ref RouteTable
      SubnetId: !Ref SubnetC
  # 先定义安全组,再定义EC2实例
  AppNodeSG:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Test Ec2 ssh and VPC
      VpcId: !Ref VPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          CidrIp: 0.0.0.0/0
          FromPort: '22'
          ToPort: '22'
        - IpProtocol: tcp
          CidrIp: 0.0.0.0/0
          FromPort: '80'
          ToPort: '80'
  # EC2实例 - 更新为us-east-1区域可用的Amazon Linux 2 AMI
  AppNode:
    Type: AWS::EC2::Instance
    Properties:
      InstanceType: t2.micro
      ImageId: ami-0c7217cdde317cfec  # us-east-1区域的Amazon Linux 2 AMI(建议按需验证最新AMI)
      KeyName: test_devops_east_1
      AvailabilityZone: us-east-1c
      SecurityGroupIds:
        - !Ref AppNodeSG
      SubnetId: !Ref SubnetC

执行命令说明

你的创建命令是正确的,修复模板后可以直接使用:

aws cloudformation create-stack --stack-name test --template-body file://~/Downloads/CFT/stack.yml --profile devops --region us-east-1

如果之前的栈创建失败,建议先删除旧栈再重新创建:

aws cloudformation delete-stack --stack-name test --profile devops --region us-east-1

额外提示

  • AMI ID会随时间更新,你可以通过AWS控制台或aws ec2 describe-images命令获取us-east-1区域最新的Amazon Linux 2 AMI ID。
  • 如果你确实需要使用专用租户VPC,请更换为支持专用租户的实例类型(比如t3.small及以上部分实例,或C5/M5系列)。

内容的提问来源于stack exchange,提问作者user9075162

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:40:41