AWS RDS Aurora MySQL跨区域只读副本:CLI/Boto3实现及Lambda触发咨询
Hey there! Let's break this down for you—you're not missing a trick here, but there's an important architectural detail about Aurora that explains why you're only finding cluster-level replication options.
The Key Context: Aurora's Cluster-Centric Model
Aurora operates as a cluster-based service, not an instance-based one like traditional RDS. When you create a cross-region read replica via the AWS Console, the UI is actually wrapping two underlying actions for you:
- Creating a read-only Aurora cluster in the target region (Oregon,
us-west-2) that replicates from your source cluster. - Provisioning a read instance within that new target cluster to handle traffic.
This is why you won't find instance-level CLI/Boto3 commands for cross-region Aurora replicas—all cross-region replication operations are tied to the cluster, not individual instances.
Implementing This with Boto3 in Lambda
Here's how to build your automation to create a cross-region read replica cluster (and associated instance) whenever a new Aurora MySQL instance is created:
Step 1: Lambda Code Example
This code will trigger on a new Aurora instance creation event, spin up a cross-region cluster replica, and add a read instance to it:
import boto3 def lambda_handler(event, context): # Extract critical details from the EventBridge/RDS event event_details = event['detail'] source_cluster_id = event_details['DBClusterIdentifier'] source_region = event_details['awsRegion'] source_account_id = event_details['userIdentity']['accountId'] # Define target region and resource names target_region = 'us-west-2' # Oregon target_cluster_name = f"{source_cluster_id}-oregon-replica" target_instance_name = f"{target_cluster_name}-instance-1" # Initialize RDS client for target region rds_target = boto3.client('rds', region_name=target_region) # 1. Create cross-region read-only cluster replica try: source_cluster_arn = f"arn:aws:rds:{source_region}:{source_account_id}:cluster:{source_cluster_id}" cluster_response = rds_target.create_db_cluster( DBClusterIdentifier=target_cluster_name, Engine='aurora-mysql', SourceDBClusterIdentifier=source_cluster_arn, DeletionProtection=False, CopyTagsToSnapshot=True, # Add your pre-configured VPC/subnet/security group details for Oregon DBSubnetGroupName='your-oregon-db-subnet-group', VpcSecurityGroupIds=['sg-1234567890'] ) print(f"Initiated cross-region cluster replica: {cluster_response['DBCluster']['DBClusterIdentifier']}") except Exception as e: print(f"Failed to create cluster replica: {str(e)}") raise # 2. Provision a read instance in the target cluster try: instance_response = rds_target.create_db_instance( DBInstanceIdentifier=target_instance_name, DBClusterIdentifier=target_cluster_name, Engine='aurora-mysql', DBInstanceClass='db.t3.small', # Match your source instance class or adjust as needed AvailabilityZone=f"{target_region}a", PubliclyAccessible=False ) print(f"Started provisioning read instance: {instance_response['DBInstance']['DBInstanceIdentifier']}") except Exception as e: print(f"Failed to create read instance: {str(e)}") raise return { 'statusCode': 200, 'body': f"Cross-region replication initiated: Cluster {target_cluster_name}, Instance {target_instance_name}" }
Step 2: Configure Event Trigger
Set up an EventBridge Rule to trigger the Lambda when a new Aurora MySQL instance is fully created:
- Event Pattern:
{ "source": ["aws.rds"], "detail-type": ["RDS DB Instance Event"], "detail": { "eventName": ["CreateDBInstance"], "engine": ["aurora-mysql"], "state": ["available"] } } - This ensures the Lambda runs only after the source instance is ready, avoiding race conditions.
Step 3: Lambda Execution Role Permissions
Make sure your Lambda role has these permissions (adjust resource ARNs as needed):
rds:CreateDBCluster(in Oregon region)rds:CreateDBInstance(in Oregon region)rds:DescribeDBClusters(in source region)- Basic logging permissions (e.g.,
logs:CreateLogGroup,logs:CreateLogStream,logs:PutLogEvents)
Critical Notes
- Pre-requisites: You'll need pre-configured DB subnet groups and security groups in the Oregon region that align with your source VPC's networking requirements.
- Cluster Replication Behavior: The target cluster will automatically replicate all data from the source cluster—you don't need to replicate individual instances. Adding multiple instances to the target cluster lets you scale read capacity.
- Console vs. CLI/Boto3: The Console hides the cluster-level step, making it feel like an instance-level operation, but the underlying API calls are identical to what we're using here.
内容的提问来源于stack exchange,提问作者Shirish Shukla

