Salta al contenuto

Come posso assegnare un tag a un volume root da un'istanza creata in CloudFormation?

6 minuti di lettura
0

Desidero assegnare un tag al volume root delle istanze Amazon Elastic Compute Cloud (Amazon EC2) che ho creato in AWS CloudFormation.

Risoluzione

Per assegnare un tag Amazon EC2 ai volumi collegati, aggiungi PropagateTagstoVolumeOnCreation nel modello CloudFormation e impostane il valore su True.

Per assegnare un tag a un volume root, completa i seguenti passaggi:

  1. Apri la console CloudFormation.

  2. Nella dashboard, scegli Crea stack - Con nuove risorse (standard).

  3. Nel modello Prerequisito - Prepara, seleziona Crea da Infrastructure Composer, quindi scegli Crea in Infrastructure Composer.

  4. Scegli Modello, quindi utilizza il modello YAML o JSON nell'editor di codice.
    Modello JSON:

    {
        "AWSTemplateFormatVersion": "2010-09-09",
        "Description": "AWS CloudFormation Sample Template Tagging Root Volumes of EC2 Instances: This template shows you how to automatically tag the root volume of the EC2 instances that are created through the AWS CloudFormation template. This is done through the UserData property of the AWS::EC2::Instance resource. **WARNING** This template creates two Amazon EC2 instances and an IAM role. You will be billed for the AWS resources used if you create a stack from this template.",
        "Parameters": {
            "KeyName": {
                "Type": "AWS::EC2::KeyPair::KeyName",
                "Description": "Name of an existing EC2 KeyPair to enable SSH access to the ECS instances."
            },
            "InstanceType": {
                "Description": "EC2 instance type",
                "Type": "String",
                "Default": "t2.micro",
                "AllowedValues": [
                    "t2.micro",
                    "t2.small",
                    "t2.medium",
                    "t2.large",
                    "m3.medium",
                    "m3.large",
                    "m3.xlarge",
                    "m3.2xlarge",
                    "m4.large",
                    "m4.xlarge",
                    "m4.2xlarge",
                    "m4.4xlarge",
                    "m4.10xlarge",
                    "c4.large",
                    "c4.xlarge",
                    "c4.2xlarge",
                    "c4.4xlarge",
                    "c4.8xlarge",
                    "c3.large",
                    "c3.xlarge",
                    "c3.2xlarge",
                    "c3.4xlarge",
                    "c3.8xlarge",
                    "r3.large",
                    "r3.xlarge",
                    "r3.2xlarge",
                    "r3.4xlarge",
                    "r3.8xlarge",
                    "i2.xlarge",
                    "i2.2xlarge",
                    "i2.4xlarge",
                    "i2.8xlarge"
                ],
                "ConstraintDescription": "Please choose a valid instance type."
            },
            "InstanceAZ": {
                "Description": "EC2 AZ.",
                "Type": "AWS::EC2::AvailabilityZone::Name",
                "ConstraintDescription": "Must be the name of an Availability Zone."
            },
            "WindowsAMIID": {
                "Description": "The Latest Windows 2016 AMI taken from the public Systems Manager Parameter Store",
                "Type": "AWS::SSM::Parameter::Value<String>",
                "Default": "/aws/service/ami-windows-latest/Windows_Server-2016-English-Full-Base"
            },
            "LinuxAMIID": {
                "Description": "The Latest Amazon Linux 2 AMI taken from the public Systems Manager Parameter Store",
                "Type": "AWS::SSM::Parameter::Value<String>",
                "Default": "/aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2"
            }
        },
        "Resources": {
            "WindowsInstance": {
                "Type": "AWS::EC2::Instance",
                "Properties": {
                    "ImageId": {
                        "Ref": "WindowsAMIID"
                    },
                    "InstanceType": {
                        "Ref": "InstanceType"
                    },
                    "AvailabilityZone": {
                        "Ref": "InstanceAZ"
                    },
                    "IamInstanceProfile": {
                        "Ref": "InstanceProfile"
                    },
                    "KeyName": {
                        "Ref": "KeyName"
                    },
                    "PropagateTagsToVolumeOnCreation": "true",
                    "Tags": [
                        {
                            "Key": "Name",
                            "Value": {
                                "Ref": "AWS::StackName"
                            }
                        }
                    ],
                    "BlockDeviceMappings": [
                        {
                            "DeviceName": "/dev/sdm",
                            "Ebs": {
                                "VolumeType": "io1",
                                "Iops": "200",
                                "DeleteOnTermination": "true",
                                "VolumeSize": "10"
                            }
                        }
                    ]
                }
            },
            "LinuxInstance": {
                "Type": "AWS::EC2::Instance",
                "Properties": {
                    "ImageId": {
                        "Ref": "LinuxAMIID"
                    },
                    "InstanceType": {
                        "Ref": "InstanceType"
                    },
                    "AvailabilityZone": {
                        "Ref": "InstanceAZ"
                    },
                    "IamInstanceProfile": {
                        "Ref": "InstanceProfile"
                    },
                    "KeyName": {
                        "Ref": "KeyName"
                    },
                    "PropagateTagsToVolumeOnCreation": "true",
                    "Tags": [
                        {
                            "Key": "Name",
                            "Value": {
                                "Ref": "AWS::StackName"
                            }
                        }
                    ],
                    "BlockDeviceMappings": [
                        {
                            "DeviceName": "/dev/sdm",
                            "Ebs": {
                                "VolumeType": "io1",
                                "Iops": "200",
                                "DeleteOnTermination": "true",
                                "VolumeSize": "10"
                            }
                        }
                    ]
                }
            },
            "InstanceRole": {
                "Type": "AWS::IAM::Role",
                "Properties": {
                    "AssumeRolePolicyDocument": {
                        "Version": "2012-10-17",
                        "Statement": [
                            {
                                "Effect": "Allow",
                                "Principal": {
                                    "Service": [
                                        "ec2.amazonaws.com"
                                    ]
                                },
                                "Action": [
                                    "sts:AssumeRole"
                                ]
                            }
                        ]
                    },
                    "Path": "/",
                    "Policies": [
                        {
                            "PolicyName": "taginstancepolicy",
                            "PolicyDocument": {
                                "Version": "2012-10-17",
                                "Statement": [
                                    {
                                        "Effect": "Allow",
                                        "Action": [
                                            "ec2:Describe*"
                                        ],
                                        "Resource": "*"
                                    },
                                    {
                                        "Effect": "Allow",
                                        "Action": [
                                            "ec2:CreateTags"
                                        ],
                                        "Resource": [
                                            {
                                                "Fn::Sub": "arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:volume/*"
                                            },
                                            {
                                                "Fn::Sub": "arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:instance/*"
                                            }
                                        ]
                                    }
                                ]
                            }
                        }
                    ]
                }
            },
            "InstanceProfile": {
                "Type": "AWS::IAM::InstanceProfile",
                "Properties": {
                    "Path": "/",
                    "Roles": [
                        {
                            "Ref": "InstanceRole"
                        }
                    ]
                }
            }
        }
    }

    Modello YAML:

    AWSTemplateFormatVersion: 2010-09-09
    Description: >-
      AWS CloudFormation Sample Template Tagging Root Volumes of EC2 Instances: This
      template shows you how to automatically tag the root volume of the EC2
      instances that are created through the AWS CloudFormation template. This is
      done through the UserData property of the AWS::EC2::Instance resource.
      **WARNING** This template creates two Amazon EC2 instances and an IAM role.
      You will be billed for the AWS resources used if you create a stack from this
      template.
    Parameters:
      KeyName:
        Type: 'AWS::EC2::KeyPair::KeyName'
        Description: Name of an existing EC2 KeyPair to enable SSH access to the ECS instances.
      InstanceType:
        Description: EC2 instance type
        Type: String
        Default: t2.micro
        AllowedValues:
          - t2.micro
          - t2.small
          - t2.medium
          - t2.large
          - m3.medium
          - m3.large
          - m3.xlarge
          - m3.2xlarge
          - m4.large
          - m4.xlarge
          - m4.2xlarge
          - m4.4xlarge
          - m4.10xlarge
          - c4.large
          - c4.xlarge
          - c4.2xlarge
          - c4.4xlarge
          - c4.8xlarge
          - c3.large
          - c3.xlarge
          - c3.2xlarge
          - c3.4xlarge
          - c3.8xlarge
          - r3.large
          - r3.xlarge
          - r3.2xlarge
          - r3.4xlarge
          - r3.8xlarge
          - i2.xlarge
          - i2.2xlarge
          - i2.4xlarge
          - i2.8xlarge
        ConstraintDescription: Please choose a valid instance type.
      InstanceAZ:
        Description: EC2 AZ.
        Type: 'AWS::EC2::AvailabilityZone::Name'
        ConstraintDescription: Must be the name of an Availability Zone.
      WindowsAMIID:
        Description: >-
          The Latest Windows 2016 AMI taken from the public Systems Manager
          Parameter Store
        Type: 'AWS::SSM::Parameter::Value<String>'
        Default: /aws/service/ami-windows-latest/Windows_Server-2016-English-Full-Base
      LinuxAMIID:
        Description: >-
          The Latest Amazon Linux 2 AMI taken from the public Systems Manager
          Parameter Store
        Type: 'AWS::SSM::Parameter::Value<String>'
        Default: /aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2
    Resources:
      WindowsInstance:
        Type: 'AWS::EC2::Instance'
        Properties:
          ImageId: !Ref WindowsAMIID
          InstanceType: !Ref InstanceType
          AvailabilityZone: !Ref InstanceAZ
          IamInstanceProfile: !Ref InstanceProfile
          KeyName: !Ref KeyName
          PropagateTagsToVolumeOnCreation: 'true'
          Tags:
            - Key: Name
              Value: !Ref 'AWS::StackName'
          BlockDeviceMappings:
            - DeviceName: /dev/sdm
              Ebs:
                VolumeType: io1
                Iops: '200'
                DeleteOnTermination: 'true'
                VolumeSize: '10'
      LinuxInstance:
        Type: 'AWS::EC2::Instance'
        Properties:
          ImageId: !Ref LinuxAMIID
          InstanceType: !Ref InstanceType
          AvailabilityZone: !Ref InstanceAZ
          IamInstanceProfile: !Ref InstanceProfile
          KeyName: !Ref KeyName
          PropagateTagsToVolumeOnCreation: 'true'
          Tags:
            - Key: Name
              Value: !Ref 'AWS::StackName'
          BlockDeviceMappings:
            - DeviceName: /dev/sdm
              Ebs:
                VolumeType: io1
                Iops: '200'
                DeleteOnTermination: 'true'
                VolumeSize: '10'
      InstanceRole:
        Type: 'AWS::IAM::Role'
        Properties:
          AssumeRolePolicyDocument:
            Version: 2012-10-17
            Statement:
              - Effect: Allow
                Principal:
                  Service:
                    - ec2.amazonaws.com
                Action:
                  - 'sts:AssumeRole'
          Path: /
          Policies:
            - PolicyName: taginstancepolicy
              PolicyDocument:
                Version: 2012-10-17
                Statement:
                  - Effect: Allow
                    Action:
                      - 'ec2:Describe*'
                    Resource: '*'
                  - Effect: Allow
                    Action:
                      - 'ec2:CreateTags'
                    Resource:
                      - !Sub 'arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:volume/*'
                      - !Sub 'arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:instance/*'
      InstanceProfile:
        Type: 'AWS::IAM::InstanceProfile'
        Properties:
          Path: /
          Roles:
            - !Ref InstanceRole

    Importante: aggiungi i tag desiderati nella proprietà Tag dei tag AWS::EC2::Instance.

  5. Scegli Crea modello. Quindi conferma e continua in CloudFormation.

  6. Scegli Avanti.

  7. In Nome stack, inserisci un nome per lo stack.

  8. Nella sezione Parametri, inserisci le informazioni in base alle esigenze dell'ambiente, tra cui il tipo di istanza, la coppia di chiavi EC2 e l'Amazon Machine Image (AMI).

  9. Scegli Avanti.

  10. Nella sezione Opzioni, inserisci le informazioni per lo stack. Quindi scegli Avanti.

  11. Attiva lo stack di CloudFormation per creare una risorsa AWS Identity and Access Management (AWS IAM). Se accetti i termini, seleziona la casella di controllo I acknowledge that AWS CloudFormation might create IAM resources (Accetto che AWS CloudFormation potrebbe creare risorse IAM).

  12. Scegli Invia.

Assegna tag al volume root dell'istanza

Completa i seguenti passaggi:

  1. Apri la console Amazon EC2.
  2. Nel pannello di navigazione, nella sezione Elastic Block Store, scegli Volumi.
  3. Nel campo Filtro, inserisci il tag che hai impostato nello stack di CloudFormation per confermare che al volume è stato assegnato un tag.
AWS UFFICIALEAggiornata un anno fa