如何在新CloudFormation栈中引用已有或其他栈的安全组?
Let’s tackle both of your questions clearly—they’re closely tied to referencing existing security groups in CloudFormation (CFN) stacks, so I’ll break down the best practices for each scenario:
1. Can I reference a security group from a previous CloudFormation stack in a new stack?
Absolutely! The cleanest, most maintainable way to do this uses CloudFormation’s built-in export/import system:
- First, in your original stack, add an
Outputsection that exports the security group’s ID (or ARN, depending on your needs). Here’s a YAML example:
Important: The export name must be unique across your AWS region—you can’t have two stacks exporting the same name.Outputs: SharedProductionSG: Value: !Ref MyOriginalSecurityGroup Export: Name: "VPC-Prod-Shared-SecurityGroup-ID" - Then, in your new stack, use
!ImportValueto pull that exported ID into your EC2 instance configuration:
Note: Both stacks must live in the same AWS region for this to work.Resources: NewWebServerEC2: Type: AWS::EC2::Instance Properties: SecurityGroups: - !ImportValue "VPC-Prod-Shared-SecurityGroup-ID" ImageId: ami-0c55b159cbfafe1f0 # Replace with your region's AMI InstanceType: t2.micro
2. Can I reference pre-created security groups (not part of the same stack) when building an EC2 stack?
Yes, you’ve got two flexible options here, depending on how reusable you want your template to be:
Option 1: Use a parameter for the security group ID (Recommended)
This keeps your template adaptable to different environments. Define a parameter that accepts a valid security group ID, then reference it across your EC2 resources:
Parameters: PreCreatedSGID: Type: AWS::EC2::SecurityGroup::Id Description: "Enter the ID of your pre-existing security group (e.g., sg-0123456789abcdef0)" Resources: FrontendEC2: Type: AWS::EC2::Instance Properties: SecurityGroups: - !Ref PreCreatedSGID ImageId: ami-0c55b159cbfafe1f0 InstanceType: t2.micro BackendEC2: Type: AWS::EC2::Instance Properties: SecurityGroups: - !Ref PreCreatedSGID ImageId: ami-0c55b159cbfafe1f0 InstanceType: t2.micro
CloudFormation will automatically validate that the ID you input is a valid security group in your account/region when you deploy the stack.
Option 2: Hardcode the security group ID (One-Off Use Only)
If you’re working on a temporary or single-purpose stack and know the exact SG ID, you can directly specify it:
Resources: TempEC2Instance: Type: AWS::EC2::Instance Properties: SecurityGroups: - sg-0123456789abcdef0 # Replace with your actual SG ID ImageId: ami-0c55b159cbfafe1f0 InstanceType: t2.micro
Just keep in mind this makes your template inflexible—if the SG ID changes later, you’ll have to edit the template manually.
Quick Checks for Both Scenarios
- Ensure the security group is in the same VPC as your EC2 instances (VPC-specific SGs won’t work across different VPCs).
- Verify the IAM role/user deploying the stack has permissions to describe and attach the target security group to EC2 instances.
内容的提问来源于stack exchange,提问作者swap709

