You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在新CloudFormation栈中引用已有或其他栈的安全组?

Answers to Your CloudFormation Security Group Questions

Let’s tackle both of your questions clearly—they’re closely tied to referencing existing security groups in CloudFormation (CFN) stacks, so I’ll break down the best practices for each scenario:

1. Can I reference a security group from a previous CloudFormation stack in a new stack?

Absolutely! The cleanest, most maintainable way to do this uses CloudFormation’s built-in export/import system:

  • First, in your original stack, add an Output section that exports the security group’s ID (or ARN, depending on your needs). Here’s a YAML example:
    Outputs:
      SharedProductionSG:
        Value: !Ref MyOriginalSecurityGroup
        Export:
          Name: "VPC-Prod-Shared-SecurityGroup-ID"
    
    Important: The export name must be unique across your AWS region—you can’t have two stacks exporting the same name.
  • Then, in your new stack, use !ImportValue to pull that exported ID into your EC2 instance configuration:
    Resources:
      NewWebServerEC2:
        Type: AWS::EC2::Instance
        Properties:
          SecurityGroups:
            - !ImportValue "VPC-Prod-Shared-SecurityGroup-ID"
          ImageId: ami-0c55b159cbfafe1f0 # Replace with your region's AMI
          InstanceType: t2.micro
    
    Note: Both stacks must live in the same AWS region for this to work.

2. Can I reference pre-created security groups (not part of the same stack) when building an EC2 stack?

Yes, you’ve got two flexible options here, depending on how reusable you want your template to be:

This keeps your template adaptable to different environments. Define a parameter that accepts a valid security group ID, then reference it across your EC2 resources:

Parameters:
  PreCreatedSGID:
    Type: AWS::EC2::SecurityGroup::Id
    Description: "Enter the ID of your pre-existing security group (e.g., sg-0123456789abcdef0)"

Resources:
  FrontendEC2:
    Type: AWS::EC2::Instance
    Properties:
      SecurityGroups:
        - !Ref PreCreatedSGID
      ImageId: ami-0c55b159cbfafe1f0
      InstanceType: t2.micro
  BackendEC2:
    Type: AWS::EC2::Instance
    Properties:
      SecurityGroups:
        - !Ref PreCreatedSGID
      ImageId: ami-0c55b159cbfafe1f0
      InstanceType: t2.micro

CloudFormation will automatically validate that the ID you input is a valid security group in your account/region when you deploy the stack.

Option 2: Hardcode the security group ID (One-Off Use Only)

If you’re working on a temporary or single-purpose stack and know the exact SG ID, you can directly specify it:

Resources:
  TempEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      SecurityGroups:
        - sg-0123456789abcdef0 # Replace with your actual SG ID
      ImageId: ami-0c55b159cbfafe1f0
      InstanceType: t2.micro

Just keep in mind this makes your template inflexible—if the SG ID changes later, you’ll have to edit the template manually.

Quick Checks for Both Scenarios

  • Ensure the security group is in the same VPC as your EC2 instances (VPC-specific SGs won’t work across different VPCs).
  • Verify the IAM role/user deploying the stack has permissions to describe and attach the target security group to EC2 instances.

内容的提问来源于stack exchange,提问作者swap709

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 06:57:14