amazon-web-services amazon-cloudformation amazon-ecs

amazon web services - Creando un grupo objetivo ALB en CloudFormation



amazon-web-services amazon-cloudformation (1)

Estoy tratando de crear una aplicación Load Balancer en CloudFormation, con un grupo objetivo que reenvía el tráfico a las instancias de EC2. Aquí está el fragmento relevante, donde se pasan como parámetros ELBSubnets, ECSCluster, taskdefinition y VpcId:

"EcsElasticLoadBalancer" : { "Type" : "AWS::ElasticLoadBalancingV2::LoadBalancer", "Properties" : { "Subnets" : { "Ref" : "ELBSubnets" }, "SecurityGroups": [ { "Ref": "ELBAccessSecurityGroup" } ] } }, "LoadBalancerListener": { "Type": "AWS::ElasticLoadBalancingV2::Listener", "Properties": { "DefaultActions": [{ "Type": "forward", "TargetGroupArn": { "Ref": "TargetGroup" } }], "LoadBalancerArn": { "Ref": "EcsElasticLoadBalancer" }, "Port": 80, "Protocol": "HTTP" } }, "TargetGroup": { "Type": "AWS::ElasticLoadBalancingV2::TargetGroup", "Properties": { "Name": { "Fn::Join": [ "-", [ { "Ref": "AWS::StackName" }, "TargetGroup" ] ] }, "Port": 80, "Protocol": "HTTP", "VpcId": { "Ref": "VpcId" } }, "DependsOn": [ "EcsElasticLoadBalancer" ] }, "service": { "Type": "AWS::ECS::Service", "Properties" : { "Cluster": { "Ref": "ECSCluster" }, "DesiredCount": "1", "LoadBalancers": [ { "ContainerName": "main-app", "ContainerPort": 3000, "TargetGroupArn": { "Ref": "TargetGroup" } } ], "Role" : {"Ref":"ECSServiceRole"}, "TaskDefinition" : {"Ref":"taskdefinition"} } }, "ECSServiceRole": { "Type": "AWS::IAM::Role", "Properties": { "AssumeRolePolicyDocument": { "Statement": [ { "Effect": "Allow", "Principal": { "Service": [ "ecs.amazonaws.com" ] }, "Action": [ "sts:AssumeRole" ] } ] }, "Path": "/", "Policies": [ { "PolicyName": "ecs-service", "PolicyDocument": { "Statement": [ { "Effect": "Allow", "Action": [ "elasticloadbalancing:Describe*", "elasticloadbalancing:DeregisterInstancesFromLoadBalancer", "elasticloadbalancing:RegisterInstancesWithLoadBalancer", "ec2:Describe*", "ec2:AuthorizeSecurityGroupIngress" ], "Resource": "*" } ] } } ] } }

Recibo el siguiente error al crear el servicio:

El grupo objetivo con targetGroupArn arn: aws: elasticloadbalancing: us-east-1: xxxxxxxx: targetgroup / AlbServiceStack-TargetGroup / 6ba9c037c26cdb36 no tiene un equilibrador de carga asociado.

¿Qué me estoy perdiendo? En la documentación no parece haber una manera de especificar un equilibrador de carga para el grupo objetivo.


Lo tengo funcionando - el problema era doble:

  1. Las siguientes líneas faltaban en el Role PolicyDocument:
    • "elasticloadbalancing:DeregisterTargets"
    • "elasticloadbalancing:RegisterTargets"
  2. El servicio necesitaba "DependsOn": [ "LoadBalancerListener" ] como un atributo adicional.

La plantilla actualizada se ve así:

"EcsElasticLoadBalancer" : { "Type" : "AWS::ElasticLoadBalancingV2::LoadBalancer", "Properties" : { "Subnets" : { "Ref" : "ELBSubnets" }, "SecurityGroups": [ { "Ref": "ELBAccessSecurityGroup" } ] } }, "LoadBalancerListener": { "Type": "AWS::ElasticLoadBalancingV2::Listener", "Properties": { "DefaultActions": [{ "Type": "forward", "TargetGroupArn": { "Ref": "TargetGroup" } }], "LoadBalancerArn": { "Ref": "EcsElasticLoadBalancer" }, "Port": 80, "Protocol": "HTTP" } }, "TargetGroup": { "Type": "AWS::ElasticLoadBalancingV2::TargetGroup", "Properties": { "Name": { "Fn::Join": [ "-", [ { "Ref": "AWS::StackName" }, "TargetGroup" ] ] }, "Port": 80, "Protocol": "HTTP", "VpcId": { "Ref": "VpcId" } }, "DependsOn": [ "EcsElasticLoadBalancer" ] }, "service": { "Type": "AWS::ECS::Service", "DependsOn": [ "LoadBalancerListener" ], "Properties" : { "Cluster": { "Ref": "ECSCluster" }, "DesiredCount": "1", "LoadBalancers": [ { "ContainerName": "main-app", "ContainerPort": 3000, "TargetGroupArn": { "Ref": "TargetGroup" } } ], "Role" : {"Ref":"ECSServiceRole"}, "TaskDefinition" : {"Ref":"taskdefinition"} } }, "ECSServiceRole": { "Type": "AWS::IAM::Role", "Properties": { "AssumeRolePolicyDocument": { "Statement": [ { "Effect": "Allow", "Principal": { "Service": [ "ecs.amazonaws.com" ] }, "Action": [ "sts:AssumeRole" ] } ] }, "Path": "/", "Policies": [ { "PolicyName": "ecs-service", "PolicyDocument": { "Statement": [ { "Effect": "Allow", "Action": [ "elasticloadbalancing:Describe*", "elasticloadbalancing:DeregisterInstancesFromLoadBalancer", "elasticloadbalancing:RegisterInstancesWithLoadBalancer", "ec2:Describe*", "ec2:AuthorizeSecurityGroupIngress", "elasticloadbalancing:DeregisterTargets", "elasticloadbalancing:RegisterTargets" ], "Resource": "*" } ] } } ] } }