Ir para o conteúdo

Como faço para adicionar uma tag a um volume raiz de uma instância criada pelo CloudFormation?

6 minuto de leitura
0

Quero adicionar uma tag ao volume raiz das minhas instâncias do Amazon Elastic Compute Cloud (Amazon EC2) que criei no AWS CloudFormation.

Resolução

Para adicionar tags do Amazon EC2 aos seus volumes anexados, adicione PropagateTagstoVolumeOnCreation no modelo do CloudFormation e defina seu valor como True.

Para adicionar uma tag a um volume raiz, conclua as seguintes etapas:

  1. Abra o console do CloudFormation.

  2. No painel, clique em Criar pilha - Com novos recursos (padrão).

  3. No modelo Pré-requisito - Preparar, selecione Construir a partir do Infrastructure Composer e, em seguida, clique em Criar no Infrastructure Composer.

  4. Selecione Modelo e, em seguida, use o modelo YAML ou JSON em seu editor de código.
    Modelo JSON:

    {
        "AWSTemplateFormatVersion": "2010-09-09",
        "Description": "AWS CloudFormation Sample Template Tagging Root Volumes of EC2 Instances: This template shows you how to automatically tag the root volume of the EC2 instances that are created through the AWS CloudFormation template. This is done through the UserData property of the AWS::EC2::Instance resource. **WARNING** This template creates two Amazon EC2 instances and an IAM role. You will be billed for the AWS resources used if you create a stack from this template.",
        "Parameters": {
            "KeyName": {
                "Type": "AWS::EC2::KeyPair::KeyName",
                "Description": "Name of an existing EC2 KeyPair to enable SSH access to the ECS instances."
            },
            "InstanceType": {
                "Description": "EC2 instance type",
                "Type": "String",
                "Default": "t2.micro",
                "AllowedValues": [
                    "t2.micro",
                    "t2.small",
                    "t2.medium",
                    "t2.large",
                    "m3.medium",
                    "m3.large",
                    "m3.xlarge",
                    "m3.2xlarge",
                    "m4.large",
                    "m4.xlarge",
                    "m4.2xlarge",
                    "m4.4xlarge",
                    "m4.10xlarge",
                    "c4.large",
                    "c4.xlarge",
                    "c4.2xlarge",
                    "c4.4xlarge",
                    "c4.8xlarge",
                    "c3.large",
                    "c3.xlarge",
                    "c3.2xlarge",
                    "c3.4xlarge",
                    "c3.8xlarge",
                    "r3.large",
                    "r3.xlarge",
                    "r3.2xlarge",
                    "r3.4xlarge",
                    "r3.8xlarge",
                    "i2.xlarge",
                    "i2.2xlarge",
                    "i2.4xlarge",
                    "i2.8xlarge"
                ],
                "ConstraintDescription": "Please choose a valid instance type."
            },
            "InstanceAZ": {
                "Description": "EC2 AZ.",
                "Type": "AWS::EC2::AvailabilityZone::Name",
                "ConstraintDescription": "Must be the name of an Availability Zone."
            },
            "WindowsAMIID": {
                "Description": "The Latest Windows 2016 AMI taken from the public Systems Manager Parameter Store",
                "Type": "AWS::SSM::Parameter::Value<String>",
                "Default": "/aws/service/ami-windows-latest/Windows_Server-2016-English-Full-Base"
            },
            "LinuxAMIID": {
                "Description": "The Latest Amazon Linux 2 AMI taken from the public Systems Manager Parameter Store",
                "Type": "AWS::SSM::Parameter::Value<String>",
                "Default": "/aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2"
            }
        },
        "Resources": {
            "WindowsInstance": {
                "Type": "AWS::EC2::Instance",
                "Properties": {
                    "ImageId": {
                        "Ref": "WindowsAMIID"
                    },
                    "InstanceType": {
                        "Ref": "InstanceType"
                    },
                    "AvailabilityZone": {
                        "Ref": "InstanceAZ"
                    },
                    "IamInstanceProfile": {
                        "Ref": "InstanceProfile"
                    },
                    "KeyName": {
                        "Ref": "KeyName"
                    },
                    "PropagateTagsToVolumeOnCreation": "true",
                    "Tags": [
                        {
                            "Key": "Name",
                            "Value": {
                                "Ref": "AWS::StackName"
                            }
                        }
                    ],
                    "BlockDeviceMappings": [
                        {
                            "DeviceName": "/dev/sdm",
                            "Ebs": {
                                "VolumeType": "io1",
                                "Iops": "200",
                                "DeleteOnTermination": "true",
                                "VolumeSize": "10"
                            }
                        }
                    ]
                }
            },
            "LinuxInstance": {
                "Type": "AWS::EC2::Instance",
                "Properties": {
                    "ImageId": {
                        "Ref": "LinuxAMIID"
                    },
                    "InstanceType": {
                        "Ref": "InstanceType"
                    },
                    "AvailabilityZone": {
                        "Ref": "InstanceAZ"
                    },
                    "IamInstanceProfile": {
                        "Ref": "InstanceProfile"
                    },
                    "KeyName": {
                        "Ref": "KeyName"
                    },
                    "PropagateTagsToVolumeOnCreation": "true",
                    "Tags": [
                        {
                            "Key": "Name",
                            "Value": {
                                "Ref": "AWS::StackName"
                            }
                        }
                    ],
                    "BlockDeviceMappings": [
                        {
                            "DeviceName": "/dev/sdm",
                            "Ebs": {
                                "VolumeType": "io1",
                                "Iops": "200",
                                "DeleteOnTermination": "true",
                                "VolumeSize": "10"
                            }
                        }
                    ]
                }
            },
            "InstanceRole": {
                "Type": "AWS::IAM::Role",
                "Properties": {
                    "AssumeRolePolicyDocument": {
                        "Version": "2012-10-17",
                        "Statement": [
                            {
                                "Effect": "Allow",
                                "Principal": {
                                    "Service": [
                                        "ec2.amazonaws.com"
                                    ]
                                },
                                "Action": [
                                    "sts:AssumeRole"
                                ]
                            }
                        ]
                    },
                    "Path": "/",
                    "Policies": [
                        {
                            "PolicyName": "taginstancepolicy",
                            "PolicyDocument": {
                                "Version": "2012-10-17",
                                "Statement": [
                                    {
                                        "Effect": "Allow",
                                        "Action": [
                                            "ec2:Describe*"
                                        ],
                                        "Resource": "*"
                                    },
                                    {
                                        "Effect": "Allow",
                                        "Action": [
                                            "ec2:CreateTags"
                                        ],
                                        "Resource": [
                                            {
                                                "Fn::Sub": "arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:volume/*"
                                            },
                                            {
                                                "Fn::Sub": "arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:instance/*"
                                            }
                                        ]
                                    }
                                ]
                            }
                        }
                    ]
                }
            },
            "InstanceProfile": {
                "Type": "AWS::IAM::InstanceProfile",
                "Properties": {
                    "Path": "/",
                    "Roles": [
                        {
                            "Ref": "InstanceRole"
                        }
                    ]
                }
            }
        }
    }

    Modelo YAML:

    AWSTemplateFormatVersion: 2010-09-09
    Description: >-
      AWS CloudFormation Sample Template Tagging Root Volumes of EC2 Instances: This
      template shows you how to automatically tag the root volume of the EC2
      instances that are created through the AWS CloudFormation template. This is
      done through the UserData property of the AWS::EC2::Instance resource.
      **WARNING** This template creates two Amazon EC2 instances and an IAM role.
      You will be billed for the AWS resources used if you create a stack from this
      template.
    Parameters:
      KeyName:
        Type: 'AWS::EC2::KeyPair::KeyName'
        Description: Name of an existing EC2 KeyPair to enable SSH access to the ECS instances.
      InstanceType:
        Description: EC2 instance type
        Type: String
        Default: t2.micro
        AllowedValues:
          - t2.micro
          - t2.small
          - t2.medium
          - t2.large
          - m3.medium
          - m3.large
          - m3.xlarge
          - m3.2xlarge
          - m4.large
          - m4.xlarge
          - m4.2xlarge
          - m4.4xlarge
          - m4.10xlarge
          - c4.large
          - c4.xlarge
          - c4.2xlarge
          - c4.4xlarge
          - c4.8xlarge
          - c3.large
          - c3.xlarge
          - c3.2xlarge
          - c3.4xlarge
          - c3.8xlarge
          - r3.large
          - r3.xlarge
          - r3.2xlarge
          - r3.4xlarge
          - r3.8xlarge
          - i2.xlarge
          - i2.2xlarge
          - i2.4xlarge
          - i2.8xlarge
        ConstraintDescription: Please choose a valid instance type.
      InstanceAZ:
        Description: EC2 AZ.
        Type: 'AWS::EC2::AvailabilityZone::Name'
        ConstraintDescription: Must be the name of an Availability Zone.
      WindowsAMIID:
        Description: >-
          The Latest Windows 2016 AMI taken from the public Systems Manager
          Parameter Store
        Type: 'AWS::SSM::Parameter::Value<String>'
        Default: /aws/service/ami-windows-latest/Windows_Server-2016-English-Full-Base
      LinuxAMIID:
        Description: >-
          The Latest Amazon Linux 2 AMI taken from the public Systems Manager
          Parameter Store
        Type: 'AWS::SSM::Parameter::Value<String>'
        Default: /aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2
    Resources:
      WindowsInstance:
        Type: 'AWS::EC2::Instance'
        Properties:
          ImageId: !Ref WindowsAMIID
          InstanceType: !Ref InstanceType
          AvailabilityZone: !Ref InstanceAZ
          IamInstanceProfile: !Ref InstanceProfile
          KeyName: !Ref KeyName
          PropagateTagsToVolumeOnCreation: 'true'
          Tags:
            - Key: Name
              Value: !Ref 'AWS::StackName'
          BlockDeviceMappings:
            - DeviceName: /dev/sdm
              Ebs:
                VolumeType: io1
                Iops: '200'
                DeleteOnTermination: 'true'
                VolumeSize: '10'
      LinuxInstance:
        Type: 'AWS::EC2::Instance'
        Properties:
          ImageId: !Ref LinuxAMIID
          InstanceType: !Ref InstanceType
          AvailabilityZone: !Ref InstanceAZ
          IamInstanceProfile: !Ref InstanceProfile
          KeyName: !Ref KeyName
          PropagateTagsToVolumeOnCreation: 'true'
          Tags:
            - Key: Name
              Value: !Ref 'AWS::StackName'
          BlockDeviceMappings:
            - DeviceName: /dev/sdm
              Ebs:
                VolumeType: io1
                Iops: '200'
                DeleteOnTermination: 'true'
                VolumeSize: '10'
      InstanceRole:
        Type: 'AWS::IAM::Role'
        Properties:
          AssumeRolePolicyDocument:
            Version: 2012-10-17
            Statement:
              - Effect: Allow
                Principal:
                  Service:
                    - ec2.amazonaws.com
                Action:
                  - 'sts:AssumeRole'
          Path: /
          Policies:
            - PolicyName: taginstancepolicy
              PolicyDocument:
                Version: 2012-10-17
                Statement:
                  - Effect: Allow
                    Action:
                      - 'ec2:Describe*'
                    Resource: '*'
                  - Effect: Allow
                    Action:
                      - 'ec2:CreateTags'
                    Resource:
                      - !Sub 'arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:volume/*'
                      - !Sub 'arn:aws:ec2:${AWS::Region}:${AWS::AccountId}:instance/*'
      InstanceProfile:
        Type: 'AWS::IAM::InstanceProfile'
        Properties:
          Path: /
          Roles:
            - !Ref InstanceRole

    Importante: adicione as tags desejadas na propriedade Tags das tags AWS::EC2::Instance.

  5. Clique em Criar modelo. Em seguida, confirme e continue com o CloudFormation.

  6. Clique em Próximo.

  7. Em Nome da pilha, insira um nome para sua pilha.

  8. Na seção Parâmetros, insira as informações com base nas necessidades do seu ambiente, incluindo seu tipo de instância, par de chaves do EC2 e imagem de máquina da Amazon (AMI).

  9. Clique em Próximo.

  10. Na seção Opções, insira as informações da sua pilha. Em seguida, selecione Próximo.

  11. Ative a pilha do CloudFormation para criar um recurso do AWS Identity and Access Management (AWS IAM). Se você concordar com os termos, marque a caixa de seleção Eu reconheço que o AWS CloudFormation pode criar recursos do IAM.

  12. Clique em Enviar.

Adicione uma tag ao volume raiz da instância

Conclua as etapas a seguir:

  1. Abra o console do Amazon EC2.
  2. No painel de navegação, na seção Elastic Block Store, selecione Volumes.
  3. No campo Filtro, insira a tag que você definiu na pilha do CloudFormation para confirmar se a tag foi adicionada ao volume.
AWS OFICIALAtualizada há um ano