You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CloudFormation栈集成VPC求助:RDS实例需VPC部署

Fixing RDS VPC Deployment Error in AWS CloudFormation

Hey Abdul, let's get your CloudFormation stack sorted out—those RDS instance types you're using mandate a VPC deployment (EC2-Classic support was dropped for them a while back). Since you already have a VPC in your company account, here's a step-by-step guide to tie your stack to it properly:

1. Add VPC & Subnet Parameters to Your Template

First, make your template flexible by adding parameters to let you select your target VPC and its subnets (critical since you have multiple VPCs). This avoids hardcoding IDs, which is better for reusability.

Parameters:
  VpcId:
    Type: AWS::EC2::VPC::Id
    Description: Select the existing VPC where you want to deploy resources
  PrivateSubnetIds:
    Type: List<AWS::EC2::Subnet::Id>
    Description: Select at least two private subnets (in different AZs) for RDS
  PublicSubnetId:
    Type: AWS::EC2::Subnet::Id
    Description: Select a public subnet for EC2 (if you need public access)

2. Configure RDS to Use the VPC

You need to create a DBSubnetGroup (required for VPC-based RDS) and link it to your VPC's subnets. Also, specify VPC security groups and disable public access (unless you explicitly need it).

Resources:
  MyDBSubnetGroup:
    Type: AWS::RDS::DBSubnetGroup
    Properties:
      DBSubnetGroupDescription: Subnet group for RDS instance
      SubnetIds: !Ref PrivateSubnetIds
      Tags:
        - Key: Name
          Value: MyRDSSubnetGroup

  MyMySQLRDS:
    Type: AWS::RDS::DBInstance
    Properties:
      DBInstanceClass: db.t2.micro # Or db.m1.small
      Engine: MySQL
      EngineVersion: 8.0
      DBInstanceIdentifier: MyMySQLInstance
      MasterUsername: admin
      MasterUserPassword: YourStrongPassword123 # Use a parameter with NoEcho: true in production!
      DBSubnetGroupName: !Ref MyDBSubnetGroup
      VPCSecurityGroups:
        - !Ref MyRDSSecurityGroup
      PubliclyAccessible: false # Keep RDS private for security
      AllocatedStorage: 20

3. Deploy EC2 to the Same VPC

Make sure your EC2 instance is in the same VPC so it can communicate with RDS. Attach it to a subnet in the VPC and link it to a security group that can access RDS.

MyEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      InstanceType: t2.micro
      ImageId: ami-0c55b159cbfafe1f0 # Update to your region's Amazon Linux 2 AMI
      SubnetId: !Ref PublicSubnetId
      SecurityGroups:
        - !Ref MyEC2SecurityGroup
      Tags:
        - Key: Name
          Value: MyEC2Instance

  # Security Groups for Network Access
  MyEC2SecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow outbound access to RDS and SSH (if needed)
      VpcId: !Ref VpcId
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 3306
          ToPort: 3306
          DestinationSecurityGroupId: !Ref MyRDSSecurityGroup
        - IpProtocol: tcp
          FromPort: 22
          ToPort: 22
          CidrIp: 0.0.0.0/0 # Restrict this to your IP in production!

  MyRDSSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow inbound MySQL from EC2
      VpcId: !Ref VpcId
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 3306
          ToPort: 3306
          SourceSecurityGroupId: !Ref MyEC2SecurityGroup

4. Deploy the Stack with Your VPC Details

When launching the stack in the AWS Console:

  • In the Parameters section, select your target VPC from the dropdown for VpcId
  • Choose at least two private subnets (from different Availability Zones) for PrivateSubnetIds—RDS requires multi-AZ subnets for high availability
  • Pick a public subnet (if you need EC2 to have public IP) for PublicSubnetId
  • Review and launch the stack—this should resolve the VPC-related error

Quick Extra Tips

  • S3 Buckets: S3 is a global service and doesn't live in a VPC, but if you want your VPC resources to access S3 without going through the public internet, you can add a AWS::EC2::VPCEndpoint (Gateway type) for S3 to your template.
  • Passwords: Never hardcode passwords in your template—use CloudFormation parameters with NoEcho: true or AWS Secrets Manager for production.

内容的提问来源于stack exchange,提问作者Abdul Salam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:33:05