【问题标题】:CloudFormation - always use latest AMICloudFormation - 始终使用最新的 AMI
【发布时间】:2019-08-24 02:02:07
【问题描述】:

博文Query for the latest Amazon Linux AMI IDs using AWS Systems Manager Parameter Store | AWS Compute Blog 描述了如何始终在 CloudFormation 模板中引用最新版本的发行版。

# Use public Systems Manager Parameter
Parameters:
  LatestAmiId:
    Type: 'AWS::SSM::Parameter::Value<AWS::EC2::Image::Id>'
    Default: '/aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2'

Resources:
 Instance:
    Type: 'AWS::EC2::Instance'
    Properties:
      ImageId: !Ref LatestAmiId

这对于 RedHat 和 CentOS 等其他发行版如何工作? 要使用的参数存储路径是什么?

【问题讨论】:

    标签: amazon-web-services amazon-cloudformation amazon-ami ssm


    【解决方案1】:

    正如@John Rotenstein 所说,SSM 似乎只有 Amazon Linux AMI。但是您仍然可以通过DescribeImages 获得其他人。然后,您可以创建一个自定义资源来为您查询它并将结果用作 AMI 值。

    Resources:
      DescribeImagesRole:
        Type: AWS::IAM::Role
        Properties:
          AssumeRolePolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Action: sts:AssumeRole
                Effect: Allow
                Principal:
                  Service: lambda.amazonaws.com
          ManagedPolicyArns:
            - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole
          Policies:
            - PolicyName: DescribeImages
              PolicyDocument:
                Version: '2012-10-17'
                Statement:
                  - Action: ec2:DescribeImages
                    Effect: Allow
                    Resource: "*"
      GetLatestAMI:
        Type: AWS::Lambda::Function
        Properties:
          Runtime: python3.6
          Handler: index.handler
          Role: !Sub ${DescribeImagesRole.Arn}
          Timeout: 60
          Code:
            ZipFile: |
              import boto3
              import cfnresponse
              import json
              import traceback
    
              def handler(event, context):
                try:
                  response = boto3.client('ec2').describe_images(
                      Owners=[event['ResourceProperties']['Owner']],
                      Filters=[
                        {'Name': 'name', 'Values': [event['ResourceProperties']['Name']]},
                        {'Name': 'architecture', 'Values': [event['ResourceProperties']['Architecture']]},
                        {'Name': 'root-device-type', 'Values': ['ebs']},
                      ],
                  )
    
                  amis = sorted(response['Images'],
                                key=lambda x: x['CreationDate'],
                                reverse=True)
                  id = amis[0]['ImageId']
    
                  cfnresponse.send(event, context, cfnresponse.SUCCESS, {}, id)
                except:
                  traceback.print_last()
                  cfnresponse.send(event, context, cfnresponse.FAIL, {}, "ok")
      CentOSAmi:
        Type: Custom::FindAMI
        Properties:
          ServiceToken: !Sub ${GetLatestAMI.Arn}
          Owner: "679593333241"
          Name: "CentOS Linux 7 x86_64 HVM EBS *"
          Architecture: "x86_64"
    

    您将更新 CentOSAmi 中的值,以便找到正确的 AMI,然后将输出用于:

    ImageId: !Ref CentOSAmi
    

    【讨论】:

      【解决方案2】:

      这些参数存储 AMI 值似乎是由 AWS 手动管理的。我只找到了以下参考:

      【讨论】:

        猜你喜欢
        • 2020-02-27
        • 2020-11-10
        • 2019-06-09
        • 1970-01-01
        • 1970-01-01
        • 2020-12-10
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        相关资源
        最近更新 更多