CloudFormation覆盖参数后未回退默认值是否为预期行为?
Parameters:
AdminCIDR:
Description: Hole in firewall for SSH on port 22
Type: String
MinLength: '9'
MaxLength: '18'
Default: 127.0.0.1/32
AllowedPattern: (\d{1,3}).(\d{1,3}).(\d{1,3}).(\d{1,3})/(\d{1,2})
ConstraintDescription: must be a valid IP CIDR range of the form x.x.x.x/x.
Resources:
SSHSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Enable SSH access via port 22
SecurityGroupIngress:
- CidrIp: !Ref AdminCIDR
FromPort: 22
IpProtocol: tcp
ToPort: 22
我通过CLI部署栈时,覆盖了`AdminCIDR`参数: ```bash aws cloudformation deploy --stack-name ex1 --template ex1.yaml --parameter-overrides AdminCIDR=$(curl -s https://api.ipify.org)/32
之后再次部署时未指定参数覆盖,未检测到变更?预期行为应该是CIDR回退到默认值?
aws cloudformation deploy --stack-name ex1 --template ex1.yaml
该行为是否不符合预期?还是一旦使用过参数覆盖,就必须始终指定(即使要回退到默认值)?
这是CloudFormation的预期行为,并非异常。
核心原因
当你第一次通过--parameter-overrides设置自定义参数值后,CloudFormation会将这个值作为栈的当前参数状态持久保存。后续部署时如果不指定参数覆盖,CloudFormation会自动复用之前存储的参数值,而不会主动回退到模板中定义的默认值。这种设计是为了避免用户在修改模板其他资源时,意外覆盖已配置的自定义参数,确保栈配置的稳定性。
恢复默认值的方法
如果需要将参数恢复为模板里的默认值,必须显式指定参数值:
aws cloudformation deploy --stack-name ex1 --template ex1.yaml --parameter-overrides AdminCIDR=127.0.0.1/32
或者使用update-stack命令(适用于仅修改参数、不改动模板内容的场景):
aws cloudformation update-stack --stack-name ex1 --use-previous-template --parameters ParameterKey=AdminCIDR,ParameterValue=127.0.0.1/32
内容的提问来源于stack exchange,提问作者mckenzm

