AWS CloudFormation栈集成VPC求助:RDS实例需VPC部署
Hey Abdul, let's get your CloudFormation stack sorted out—those RDS instance types you're using mandate a VPC deployment (EC2-Classic support was dropped for them a while back). Since you already have a VPC in your company account, here's a step-by-step guide to tie your stack to it properly:
1. Add VPC & Subnet Parameters to Your Template
First, make your template flexible by adding parameters to let you select your target VPC and its subnets (critical since you have multiple VPCs). This avoids hardcoding IDs, which is better for reusability.
Parameters: VpcId: Type: AWS::EC2::VPC::Id Description: Select the existing VPC where you want to deploy resources PrivateSubnetIds: Type: List<AWS::EC2::Subnet::Id> Description: Select at least two private subnets (in different AZs) for RDS PublicSubnetId: Type: AWS::EC2::Subnet::Id Description: Select a public subnet for EC2 (if you need public access)
2. Configure RDS to Use the VPC
You need to create a DBSubnetGroup (required for VPC-based RDS) and link it to your VPC's subnets. Also, specify VPC security groups and disable public access (unless you explicitly need it).
Resources: MyDBSubnetGroup: Type: AWS::RDS::DBSubnetGroup Properties: DBSubnetGroupDescription: Subnet group for RDS instance SubnetIds: !Ref PrivateSubnetIds Tags: - Key: Name Value: MyRDSSubnetGroup MyMySQLRDS: Type: AWS::RDS::DBInstance Properties: DBInstanceClass: db.t2.micro # Or db.m1.small Engine: MySQL EngineVersion: 8.0 DBInstanceIdentifier: MyMySQLInstance MasterUsername: admin MasterUserPassword: YourStrongPassword123 # Use a parameter with NoEcho: true in production! DBSubnetGroupName: !Ref MyDBSubnetGroup VPCSecurityGroups: - !Ref MyRDSSecurityGroup PubliclyAccessible: false # Keep RDS private for security AllocatedStorage: 20
3. Deploy EC2 to the Same VPC
Make sure your EC2 instance is in the same VPC so it can communicate with RDS. Attach it to a subnet in the VPC and link it to a security group that can access RDS.
MyEC2Instance: Type: AWS::EC2::Instance Properties: InstanceType: t2.micro ImageId: ami-0c55b159cbfafe1f0 # Update to your region's Amazon Linux 2 AMI SubnetId: !Ref PublicSubnetId SecurityGroups: - !Ref MyEC2SecurityGroup Tags: - Key: Name Value: MyEC2Instance # Security Groups for Network Access MyEC2SecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: Allow outbound access to RDS and SSH (if needed) VpcId: !Ref VpcId SecurityGroupEgress: - IpProtocol: tcp FromPort: 3306 ToPort: 3306 DestinationSecurityGroupId: !Ref MyRDSSecurityGroup - IpProtocol: tcp FromPort: 22 ToPort: 22 CidrIp: 0.0.0.0/0 # Restrict this to your IP in production! MyRDSSecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: Allow inbound MySQL from EC2 VpcId: !Ref VpcId SecurityGroupIngress: - IpProtocol: tcp FromPort: 3306 ToPort: 3306 SourceSecurityGroupId: !Ref MyEC2SecurityGroup
4. Deploy the Stack with Your VPC Details
When launching the stack in the AWS Console:
- In the Parameters section, select your target VPC from the dropdown for
VpcId - Choose at least two private subnets (from different Availability Zones) for
PrivateSubnetIds—RDS requires multi-AZ subnets for high availability - Pick a public subnet (if you need EC2 to have public IP) for
PublicSubnetId - Review and launch the stack—this should resolve the VPC-related error
Quick Extra Tips
- S3 Buckets: S3 is a global service and doesn't live in a VPC, but if you want your VPC resources to access S3 without going through the public internet, you can add a
AWS::EC2::VPCEndpoint(Gateway type) for S3 to your template. - Passwords: Never hardcode passwords in your template—use CloudFormation parameters with
NoEcho: trueor AWS Secrets Manager for production.
内容的提问来源于stack exchange,提问作者Abdul Salam

