使用云形成将文件从 S3 存储桶复制到 EC2 主目录

问题描述 投票:0回答:2

我正在尝试将文件从 S3 存储桶复制到 EC2 主目录。我使用这个 SOF Answer

的帮助编写了一个脚本

但是在我的情况下,脚本执行时没有任何错误,但我无法看到文件在我的实例中被复制。 有人可以帮我弄清楚我错过了什么吗?

云形成脚本:

Properties:
  ImageId: !FindInMap [Region2AMI, !Ref 'AWS::Region', 'AMI']
  InstanceType: t2.micro
  SecurityGroups:
    - !Ref WebserverSecurityGroup
  Tags:
    - Key: Name
      Value: Amazon Linux w/ nginx included -2
  KeyName: !Ref KeyName
  UserData:
    'Fn::Base64': !Sub |
      #!/bin/bash -x
      yum update -y aws-cfn-bootstrap
      sudo yum install git -y
      sudo yum update -y
      sudo yum install nginx -y
      sudo service nginx enable
      sudo service nginx start
      mkdir /home/ec2-user/s3-dist
      aws s3 cp s3://ai-dashboard-bucket/dist.zip /tmp
      unzip -d /home/ec2-user/s3-dist /tmp/dist.zip
      /opt/aws/bin/cfn-init -v --stack ${AWS::StackName} --resource EC2Instance --region ${AWS::Region}  --configSets InstallAndConfig

编辑:我检查了日志文件,这是我收到的错误。 我检查了日志,发现以下错误

aws s3 同步 s3://ai-dashboard-bucket/dist.zip /home/ec2-user fatal 错误:无法找到凭据

如何传递凭证?

感谢您的帮助。

amazon-web-services amazon-s3 amazon-ec2 aws-cloudformation
2个回答
1
投票

看起来 IAM 实例配置文件没有访问

ai-dashboard-bucket
中的对象的权限。

尝试将 IAM 实例配置文件添加到您的 EC2 实例

Resources:
  InstanceRole:
    Type: AWS::IAM::Role
    Properties: 
      AssumeRolePolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Principal:
              Service:
                - ec2.amazonaws.com
            Action:
              - 'sts:AssumeRole'
      Policies: 
        - PolicyName: root
          PolicyDocument:
            Version: "2012-10-17"
            Statement:
              - Effect: Allow
                Action: 's3:Get*'
                Resource: !Sub 'arn:${AWS::Partition}:s3:::ai-dashboard-bucket/*'

  InstanceProfile:
    Type: AWS::IAM::InstanceProfile
    Properties:
      Roles: 
        - !Ref InstanceRole
  Ec2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: !FindInMap [Region2AMI, !Ref 'AWS::Region', 'AMI']
      InstanceType: t2.micro
      IamInstanceProfile: !GetAtt InstanceRole.Arn  # Using the role created above
      SecurityGroups:
        - !Ref WebserverSecurityGroup
      Tags:
        - Key: Name
          Value: Amazon Linux w/ nginx included -2
      KeyName: !Ref KeyName
      UserData:
        'Fn::Base64': !Sub |
          #!/bin/bash -x
          yum update -y aws-cfn-bootstrap
          sudo yum install git -y
          sudo yum update -y
          sudo yum install nginx -y
          sudo service nginx enable
          sudo service nginx start
          mkdir /home/ec2-user/s3-dist
          aws s3 cp s3://ai-dashboard-bucket/dist.zip /tmp
          unzip -d /home/ec2-user/s3-dist /tmp/dist.zip
          /opt/aws/bin/cfn-init -v --stack ${AWS::StackName} --resource EC2Instance --region ${AWS::Region}  --configSets InstallAndConfig


0
投票

如果我想通过在区域映射中给出存储桶名称来作为参考,如何在用户数据中给出存储桶名称?

© www.soinside.com 2019 - 2024. All rights reserved.