-
Notifications
You must be signed in to change notification settings - Fork 35
/
forward-entry.yml
135 lines (135 loc) · 3.1 KB
/
forward-entry.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
ROSTemplateFormatVersion: '2015-09-01'
Description:
zh-cn: 创建VPC、子网、安全组、NAT网关、ECS实例、EIP并关联,配置TCP转发规则,实现ECS端口22的公网访问。
en: Create a VPC, subnets, security groups, NAT Gateway, ECS instances, and EIP,
then associate them, configure TCP forwarding rules to enable public access to
port 22 on the ECS instance.
Parameters:
VpcName:
Type: String
VSwitchName:
Type: String
NatGatewayName:
Type: String
ImageId:
Type: String
Default: centos_7
SecurityGroupName:
Type: String
InstancePassword:
Type: String
InstanceType:
Type: String
Default: ecs.c5.large
SystemDiskCategory:
Type: String
Description: Category of system disk. Default is cloud_efficiency. support cloud|cloud_efficiency|cloud_ssd|cloud_essd|ephemeral_ssd.Old
instances will not be changed.
Default: cloud_essd
AllowedValues:
- cloud
- cloud_efficiency
- cloud_ssd
- cloud_essd
- ephemeral_ssd
ZoneId:
Type: String
Label:
en: Zone ID
zh-cn: 可用区ID
AssociationProperty: ALIYUN::ECS::Instance::ZoneId
Resources:
Vpc:
Type: ALIYUN::ECS::VPC
Properties:
VpcName:
Ref: VpcName
CidrBlock: 192.168.0.0/16
VSwitch:
Type: ALIYUN::ECS::VSwitch
Properties:
ZoneId:
Ref: ZoneId
VpcId:
Ref: Vpc
VSwitchName:
Ref: VSwitchName
CidrBlock: 192.168.0.0/16
SecurityGroup:
Type: ALIYUN::ECS::SecurityGroup
Properties:
VpcId:
Ref: Vpc
SecurityGroupName:
Ref: SecurityGroupName
NatGateway:
Type: ALIYUN::VPC::NatGateway
Properties:
VpcId:
Fn::GetAtt:
- Vpc
- VpcId
VSwitchId:
Ref: VSwitch
NatGatewayName:
Ref: NatGatewayName
Ecs:
Type: ALIYUN::ECS::Instance
Properties:
VpcId:
Ref: Vpc
VSwitchId:
Ref: VSwitch
SecurityGroupId:
Fn::GetAtt:
- SecurityGroup
- SecurityGroupId
ImageId:
Ref: ImageId
IoOptimized: optimized
Password:
Ref: InstancePassword
AllocatePublicIP: 'false'
SystemDiskCategory:
Ref: SystemDiskCategory
InstanceType:
Ref: InstanceType
Eip:
Type: ALIYUN::VPC::EIP
Properties:
InternetChargeType: PayByTraffic
Bandwidth: 5
EIpAssociation:
Type: ALIYUN::VPC::EIPAssociation
Properties:
InstanceId:
Ref: NatGateway
AllocationId:
Ref: Eip
DependsOn: NatGateway
ForwardTableEntry:
Type: ALIYUN::ECS::ForwardEntry
Properties:
IpProtocol: TCP
ExternalIp:
Fn::GetAtt:
- Eip
- EipAddress
ForwardTableId:
Fn::GetAtt:
- NatGateway
- ForwardTableId
ExternalPort: '22'
InternalPort: '22'
InternalIp:
Fn::GetAtt:
- Ecs
- PrivateIp
DependsOn: EIpAssociation
Outputs:
ForwardEntryId:
Description: The id of created forward entry.
Value:
Fn::GetAtt:
- ForwardTableEntry
- ForwardEntryId