Passer au contenu

Comment puis-je identifier un volume racine à partir d'une instance créée par CloudFormation ?

Lecture de 6 minute(s)
0

Je souhaite identifier le volume racine des instances Amazon Elastic Compute Cloud (Amazon EC2) que j’ai créées dans AWS CloudFormation.

Résolution

Pour ajouter des identifications Amazon EC2 aux volumes attachés, ajoutez PropagateTagstoVolumeOnCreation dans le modèle CloudFormation et définissez sa valeur sur Vrai.

Pour identifier un volume racine, procédez comme suit :

  1. Ouvrez la console CloudFormation.

  2. Sur le tableau de bord, sélectionnez Créer une pile - Avec de nouvelles ressources (standard).

  3. Dans le modèle Prérequis - Préparer, sélectionnez Créer à partir d'Infrastructure Composer, puis Créer dans Infrastructure Composer.

  4. Choisissez Modèle, puis utilisez le modèle YAML ou JSON dans votre éditeur de code.
    Modèle JSON :

    {
        "AWSTemplateFormatVersion": "2010-09-09",
        "Description": "AWS CloudFormation Sample Template Tagging Root Volumes of EC2 Instances: This template shows you how to automatically tag the root volume of the EC2 instances that are created through the AWS CloudFormation template. This is done through the UserData property of the AWS::EC2::Instance resource. **WARNING** This template creates two Amazon EC2 instances and an IAM role. You will be billed for the AWS resources used if you create a stack from this template.",
        "Parameters": {
            "KeyName": {
                "Type": "AWS::EC2::KeyPair::KeyName",
                "Description": "Name of an existing EC2 KeyPair to enable SSH access to the ECS instances."
            },
            "InstanceType": {
                "Description": "EC2 instance type",
                "Type": "String",
                "Default": "t2.micro",
                "AllowedValues": [
                    "t2.micro",
                    "t2.small",
                    "t2.medium",
                    "t2.large",
                    "m3.medium",
                    "m3.large",
                    "m3.xlarge",
                    "m3.2xlarge",
                    "m4.large",
                    "m4.xlarge",
                    "m4.2xlarge",
                    "m4.4xlarge",
                    "m4.10xlarge",
                    "c4.large",
                    "c4.xlarge",
                    "c4.2xlarge",
                    "c4.4xlarge",
                    "c4.8xlarge",
                    "c3.large",
                    "c3.xlarge",
                    "c3.2xlarge",
                    "c3.4xlarge",
                    "c3.8xlarge",
                    "r3.large",
                    "r3.xlarge",
                    "r3.2xlarge",
                    "r3.4xlarge",
                    "r3.8xlarge",
                    "i2.xlarge",
                    "i2.2xlarge",
                    "i2.4xlarge",
                    "i2.8xlarge"
                ],
                "ConstraintDescription": "Please choose a valid instance type."
            },
            "InstanceAZ": {
                "Description": "EC2 AZ.",
                "Type": "AWS::EC2::AvailabilityZone::Name",
                "ConstraintDescription": "Must be the name of an Availability Zone."
            },
            "WindowsAMIID": {
                "Description": "The Latest Windows 2016 AMI taken from the public Systems Manager Parameter Store",
                "Type": "AWS::SSM::Parameter::Value<String>",
                "Default": "/aws/service/ami-windows-latest/Windows_Server-2016-English-Full-Base"
            },
            "LinuxAMIID": {
                "Description": "The Latest Amazon Linux 2 AMI taken from the public Systems Manager Parameter Store",
                "Type": "AWS::SSM::Parameter::Value<String>",
                "Default": "/aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2"
            }
        },
        "Resources": {
            "WindowsInstance": {
                "Type": "AWS::EC2::Instance",
                "Properties": {
                    "ImageId": {
                        "Ref": "WindowsAMIID"
                    },
                    "InstanceType": {
                        "Ref": "InstanceType"
                    },
                    "AvailabilityZone": {
                        "Ref": "InstanceAZ"
                    },
                    "IamInstanceProfile": {
                        "Ref": "InstanceProfile"
                    },
                    "KeyName": {
                        "Ref": "KeyName"
                    },
                    "PropagateTagsToVolumeOnCreation": "true",
                    "Tags": [
                        {
                            "Key": "Name",
                            "Value": {
                                "Ref": "AWS::StackName"
                            }
                        }
                    ],
                    "BlockDeviceMappings": [
                        {
                            "DeviceName": "/dev/sdm",
                            "Ebs": {
                                "VolumeType": "io1",
                                "Iops": "200",
                                "DeleteOnTermination": "true",
                                "VolumeSize": "10"
                            }
                        }
                    ]
                }
            },
            "LinuxInstance": {
                "Type": "AWS::EC2::Instance",
                "Properties": {
                    "ImageId": {
                        "Ref": "LinuxAMIID"
                    },
                    "InstanceType": {
                        "Ref": "InstanceType"
                    },
                    "AvailabilityZone": {
                        "Ref": "InstanceAZ"
                    },
                    "IamInstanceProfile": {
                        "Ref": "InstanceProfile"
                    },
                    "KeyName": {
                        "Ref": "KeyName"
                    },
                    "PropagateTagsToVolumeOnCreation": "true",
                    "Tags": [
                        {
                            "Key": "Name",
                            "Value": {
                                "Ref": "AWS::StackName"
                            }
                        }
                    ],
                    "BlockDeviceMappings": [
                        {
                            "DeviceName": "/dev/sdm",
                            "Ebs": {
                                "VolumeType": "io1",
                                "Iops": "200",
                                "DeleteOnTermination": "true",
                                "VolumeSize": "10"
                            }
                        }
                    ]
                }
            },
            "InstanceRole": {
                "Type": "AWS::IAM::Role",
                "Properties": {
                    "AssumeRolePolicyDocument": {
                        "Version": "2012-10-17",
                        "Statement": [
                            {
                                "Effect": "Allow",
                                "Principal": {
                                    "Service": [
                                        "ec2.amazonaws.com"
                                    ]
                                },
                                "Action": [
                                    "sts:AssumeRole"
                                ]
                            }
                        ]
                    },
                    "Path": "/",
                    "Policies": [
                        {
                            "PolicyName": "taginstancepolicy",
                            "PolicyDocument": {
                                "Version": "2012-10-17",
                                "Statement": [
                                    {
                                        "Effect": "Allow",
                                        "Action": [
                                            "ec2:Describe*"
                                        ],
                                        "Resource": "*"
                                    },
                                    {
                                        "Effect": "Allow",
                                        "Action": [
                                            "ec2:CreateTags"
                                        ],
                                        "Resource": [
                                            {
                                                "Fn::Sub": "arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:volume/*"
                                            },
                                            {
                                                "Fn::Sub": "arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:instance/*"
                                            }
                                        ]
                                    }
                                ]
                            }
                        }
                    ]
                }
            },
            "InstanceProfile": {
                "Type": "AWS::IAM::InstanceProfile",
                "Properties": {
                    "Path": "/",
                    "Roles": [
                        {
                            "Ref": "InstanceRole"
                        }
                    ]
                }
            }
        }
    }

    Modèle YAML :

    AWSTemplateFormatVersion: 2010-09-09
    Description: >-
      AWS CloudFormation Sample Template Tagging Root Volumes of EC2 Instances: This
      template shows you how to automatically tag the root volume of the EC2
      instances that are created through the AWS CloudFormation template. This is
      done through the UserData property of the AWS::EC2::Instance resource.
      **WARNING** This template creates two Amazon EC2 instances and an IAM role.
      You will be billed for the AWS resources used if you create a stack from this
      template.
    Parameters:
      KeyName:
        Type: 'AWS::EC2::KeyPair::KeyName'
        Description: Name of an existing EC2 KeyPair to enable SSH access to the ECS instances.
      InstanceType:
        Description: EC2 instance type
        Type: String
        Default: t2.micro
        AllowedValues:
          - t2.micro
          - t2.small
          - t2.medium
          - t2.large
          - m3.medium
          - m3.large
          - m3.xlarge
          - m3.2xlarge
          - m4.large
          - m4.xlarge
          - m4.2xlarge
          - m4.4xlarge
          - m4.10xlarge
          - c4.large
          - c4.xlarge
          - c4.2xlarge
          - c4.4xlarge
          - c4.8xlarge
          - c3.large
          - c3.xlarge
          - c3.2xlarge
          - c3.4xlarge
          - c3.8xlarge
          - r3.large
          - r3.xlarge
          - r3.2xlarge
          - r3.4xlarge
          - r3.8xlarge
          - i2.xlarge
          - i2.2xlarge
          - i2.4xlarge
          - i2.8xlarge
        ConstraintDescription: Please choose a valid instance type.
      InstanceAZ:
        Description: EC2 AZ.
        Type: 'AWS::EC2::AvailabilityZone::Name'
        ConstraintDescription: Must be the name of an Availability Zone.
      WindowsAMIID:
        Description: >-
          The Latest Windows 2016 AMI taken from the public Systems Manager
          Parameter Store
        Type: 'AWS::SSM::Parameter::Value<String>'
        Default: /aws/service/ami-windows-latest/Windows_Server-2016-English-Full-Base
      LinuxAMIID:
        Description: >-
          The Latest Amazon Linux 2 AMI taken from the public Systems Manager
          Parameter Store
        Type: 'AWS::SSM::Parameter::Value<String>'
        Default: /aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2
    Resources:
      WindowsInstance:
        Type: 'AWS::EC2::Instance'
        Properties:
          ImageId: !Ref WindowsAMIID
          InstanceType: !Ref InstanceType
          AvailabilityZone: !Ref InstanceAZ
          IamInstanceProfile: !Ref InstanceProfile
          KeyName: !Ref KeyName
          PropagateTagsToVolumeOnCreation: 'true'
          Tags:
            - Key: Name
              Value: !Ref 'AWS::StackName'
          BlockDeviceMappings:
            - DeviceName: /dev/sdm
              Ebs:
                VolumeType: io1
                Iops: '200'
                DeleteOnTermination: 'true'
                VolumeSize: '10'
      LinuxInstance:
        Type: 'AWS::EC2::Instance'
        Properties:
          ImageId: !Ref LinuxAMIID
          InstanceType: !Ref InstanceType
          AvailabilityZone: !Ref InstanceAZ
          IamInstanceProfile: !Ref InstanceProfile
          KeyName: !Ref KeyName
          PropagateTagsToVolumeOnCreation: 'true'
          Tags:
            - Key: Name
              Value: !Ref 'AWS::StackName'
          BlockDeviceMappings:
            - DeviceName: /dev/sdm
              Ebs:
                VolumeType: io1
                Iops: '200'
                DeleteOnTermination: 'true'
                VolumeSize: '10'
      InstanceRole:
        Type: 'AWS::IAM::Role'
        Properties:
          AssumeRolePolicyDocument:
            Version: 2012-10-17
            Statement:
              - Effect: Allow
                Principal:
                  Service:
                    - ec2.amazonaws.com
                Action:
                  - 'sts:AssumeRole'
          Path: /
          Policies:
            - PolicyName: taginstancepolicy
              PolicyDocument:
                Version: 2012-10-17
                Statement:
                  - Effect: Allow
                    Action:
                      - 'ec2:Describe*'
                    Resource: '*'
                  - Effect: Allow
                    Action:
                      - 'ec2:CreateTags'
                    Resource:
                      - !Sub 'arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:volume/*'
                      - !Sub 'arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:instance/*'
      InstanceProfile:
        Type: 'AWS::IAM::InstanceProfile'
        Properties:
          Path: /
          Roles:
            - !Ref InstanceRole

    Important : ajoutez les identifications souhaitées dans la propriété Tags des identifications AWS::EC2::Instance.

  5. Sélectionnez Créer un modèle. Puis, confirmez et passez à CloudFormation.

  6. Sélectionnez Suivant.

  7. Pour Nom de la pile, saisissez le nom de la pile.

  8. Dans la section Paramètres, saisissez les informations appropriées selon les besoins de votre environnement, notamment votre type d’instance, votre paire de clés EC2 et votre Amazon Machine Image (AMI).

  9. Sélectionnez Suivant.

  10. Dans la section Options, saisissez les informations relatives à votre pile. Puis, sélectionnez Suivant.

  11. Activez la pile CloudFormation pour créer une ressource Gestion des identités et des accès AWS (AWS IAM). Si vous acceptez les conditions, cochez la case Je reconnais qu'AWS CloudFormation peut créer des ressources IAM.

  12. Sélectionnez Soumettre.

Identifier le volume racine des instances

Procédez comme suit :

  1. Ouvrez la console Amazon EC2.
  2. Dans le volet de navigation, dans la section Elastic Block Store, choisissez Volumes.
  3. Dans le champ Filtre, saisissez l’identification que vous avez définie dans la pile CloudFormation pour confirmer que le volume a été identifié.
AWS OFFICIELA mis à jour il y a un an