AWS没有提供官方的CloudFormation资源来创建S3存储桶内的对象。但是,您可以使用AWS SDK创建一个
基于Lambda的自定义资源来执行此功能,实际上
gilt/cloudformation-helpers GitHub存储库提供了一个现成的自定义资源来完成这个任务。
与任何自定义资源一样,设置有点冗长,因为您需要首先部署Lambda函数和IAM权限,然后在堆栈模板中将其作为自定义资源引用。
首先,在堆栈模板中添加
Lambda :: Function
和相关的
IAM :: Role
资源:
"S3PutObjectFunctionRole": {
"Type": "AWS::IAM::Role",
"Properties": {
"AssumeRolePolicyDocument": {
"Version" : "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": [ "lambda.amazonaws.com" ]
},
"Action": [ "sts:AssumeRole" ]
}
]
},
"ManagedPolicyArns": [
{ "Ref": "RoleBasePolicy" }
],
"Policies": [
{
"PolicyName": "S3Writer",
"PolicyDocument": {
"Version" : "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:DeleteObject",
"s3:ListBucket",
"s3:PutObject"
],
"Resource": "*"
}
]
}
}
]
}
},
"S3PutObjectFunction": {
"Type": "AWS::Lambda::Function",
"Properties": {
"Code": {
"S3Bucket": "com.gilt.public.backoffice",
"S3Key": "lambda_functions/cloudformation-helpers.zip"
},
"Description": "Used to put objects into S3.",
"Handler": "aws/s3.putObject",
"Role": {"Fn::GetAtt" : [ "S3PutObjectFunctionRole", "Arn" ] },
"Runtime": "nodejs",
"Timeout": 30
},
"DependsOn": [
"S3PutObjectFunctionRole"
]
},
然后,您可以将Lambda函数用作自定义资源来创建S3对象:
"MyFolder": {
"Type": "Custom::S3PutObject",
"Properties": {
"ServiceToken": { "Fn::GetAtt" : ["S3PutObjectFunction", "Arn"] },
"Bucket": "mybucket",
"Key": "myfolder/"
}
},
您也可以使用相同的自定义资源来编写基于字符串的S3对象,只需在Bucket
和Key
之外添加一个Body
参数即可(请参阅文档)。