-
Notifications
You must be signed in to change notification settings - Fork 35
/
multi-region-multi-area-network-interworking.yml
641 lines (631 loc) · 20.3 KB
/
multi-region-multi-area-network-interworking.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
ROSTemplateFormatVersion: '2015-09-01'
Description:
zh-cn: 构建多地域多可用区混合云,通过物理专线连接IDC与VPC,自动部署VPC、ECS、SLB及CEN,实现高稳定性的业务架构。
en: Build a multi-region and multi-availability zone hybrid cloud, connect IDC and VPC through physical dedicated lines, and automatically deploy VPC, ECS, SLB and CEN to achieve a highly stable business architecture.
Conditions:
BindVBR:
Fn::Not:
Fn::Equals:
- default
- Ref: OtherVBRId
Parameters:
OtherVBRRegion:
Type: String
Label:
en: VBR Region
zh-cn: VBR的地域
Description:
en: Provide sritgoing VBR region name that requires networking.
zh-cn: 提供需要组建网络的VBR地域名称。
Default: cn-hangzhou
AllowedValues:
- cn-shenzhen
- cn-beijing
- ap-south-1
- eu-west-1
- ap-northeast-1
- me-east-1
- cn-chengdu
- cn-qingdao
- cn-shanghai
- cn-hongkong
- ap-southeast-1
- ap-southeast-2
- ap-southeast-3
- eu-central-1
- cn-huhehaote
- ap-southeast-5
- us-east-1
- cn-zhangjiakou
- us-west-1
- cn-hangzhou
OtherVBRId:
Type: String
Label:
en: VBR ID
zh-cn: 高速通道路由VBR ID
Description:
en: High speed channel routing ID
zh-cn: 高速通道路由ID。
Default: default
OtherVPCRegion:
Type: String
Label:
en: Existing VPC Regions
zh-cn: 已存在的VPC地域
Description:
en: Provide the name of another region where the network needs to be formed.
zh-cn: 提供需要组建网络的另一地域名称。
AllowedValues:
- cn-shenzhen
- cn-beijing
- ap-south-1
- eu-west-1
- ap-northeast-1
- me-east-1
- cn-chengdu
- cn-qingdao
- cn-shanghai
- cn-hongkong
- ap-southeast-1
- ap-southeast-2
- ap-southeast-3
- eu-central-1
- cn-huhehaote
- ap-southeast-5
- us-east-1
- cn-zhangjiakou
- us-west-1
- cn-hangzhou
OtherVpcId:
Type: String
Label:
en: VPC ID
zh-cn: 虚拟专有网实例ID
Description:
en: Virtual proprietary network instance ID
zh-cn: ' 虚拟专有网实例ID。'
VpcCidrBlock:
Type: String
Label:
en: VPC CIDR Block
zh-cn: 专有网络网段
Description:
en: 'The IP address range of the VPC in the CIDR Block form; <br>you can use
the following IP address ranges: <br><font color=''green''>[10.0.0.0/8]</font><br><font
color=''green''>[172.16.0.0/12]</font><br><font color=''green''>[192.168.0.0/16]</font>'
zh-cn: 专有网络IP地址段范围,<br>您可以使用以下的IP地址段:<br><font color='green'>[10.0.0.0/8]</font><br><font
color='green'>[172.16.0.0/12]</font><br><font color='green'>[192.168.0.0/16]</font>
Default: 172.16.0.0/12
AllowedValues:
- 192.168.0.0/16
- 172.16.0.0/12
- 10.0.0.0/8
Azone1:
Type: String
Label:
en: Availability Zone 1
zh-cn: 可用区1
Description:
en: Availability Zone ID.<br><b>note:<font color='blue'>before selecting, please
confirm that the Availability Zone supports the specification of creating
ECS resources</font></b>
zh-cn: 可用区ID。<br><b>注: <font color='blue'>选择前请确认该可用区是否支持创建ECS资源的规格</font></b>
AssociationProperty: ALIYUN::ECS::Instance:ZoneId
VSwitch1CidrBlock:
Type: String
Label:
en: VSwitch 1 CIDR Block
zh-cn: 交换机1网段
Description:
en: Must be a sub-network segment of the proprietary network and is not occupied
by other VSwitches.
zh-cn: 必须是所属专有网络的子网段,并且没有被其他交换机占用。
Default: 172.16.100.0/25
Azone2:
Type: String
Label:
en: Availability Zone 2
zh-cn: 可用区2
Description:
en: Availability Zone ID, <font color='red'><b>please select a different Availability
Zone than Availability Zone 1</font></b><br><b>note:<font color='blue'>before
selecting, please confirm that the Availability Zone supports the specification
of creating SLB、CEN and ECS resources</font></b>
zh-cn: 可用区ID,<font color='red'><b>请选择与可用区1不同的可用区</font></b><br><b>注: <font color='blue'>选择前请确认该可用区是否支持创建SLB、CEN及ECS资源的规格</font></b>
AssociationProperty: ALIYUN::ECS::Instance:ZoneId
VSwitch2CidrBlock:
Type: String
Label:
en: VSwitch 2 CIDR Block
zh-cn: 交换机2网段
Description:
en: Must be a sub-network segment of the proprietary network and is not occupied
by other VSwitches.
zh-cn: 必须是所属专有网络的子网段,并且没有被其他交换机占用。
Default: 172.16.80.0/25
ImageId:
Type: String
Label:
en: Image
zh-cn: 镜像
Description:
en: Image ID,see detail:<b><a href='https://www.alibabacloud.com/help/en/doc-detail/112977.html'
target='_blank'><font color='blue'>Find the mirror</font></a></b>
zh-cn: 镜像ID, 详见:<b><a href='https://help.aliyun.com/document_detail/112977.html'
target='_blank'><font color='blue'>查找镜像</font></a></b>
Default: centos_7
VSwitch1InstanceType:
Type: String
Label:
en: Availability Zone 1 Instance Type
zh-cn: 可用区1实例规格
Description:
en: 'Fill in the specifications that can be used under the VSwitch 1 availability
zone;</b></font><br>general specifications:<font color=''red''><b>ecs.c5.large</b></font><br>note:
a few zones do not support general specifications<br>see detail: <a href=''https://www.alibabacloud.com/help/en/doc-detail/25378.html''
target=''_blank''><b><font color=''blue''>Instance Specification Family</font></a></b>'
zh-cn: 填写VSwitch1可用区下可使用的规格;<br>通用规格:<font color='red'><b>ecs.c5.large</b></font><br>注:可用区可能不支持通用规格<br>规格详见:<a
href='https://help.aliyun.com/document_detail/25378.html' target='_blank'><b><font
color='blue'>实例规格族</font></a></b>
AssociationProperty: ALIYUN::ECS::Instance::InstanceType
AssociationPropertyMetadata:
ZoneId: Azone1
VSwitch2InstanceType:
Type: String
Label:
en: Availability Zone 2 Instance Type
zh-cn: 可用区2实例规格
Description:
en: 'Fill in the specifications that can be used under the VSwitch 2 availability
zone;</b></font><br>general specifications:<font color=''red''><b>ecs.c5.large</b></font><br>note:
a few zones do not support general specifications<br>see detail: <a href=''https://www.alibabacloud.com/help/en/doc-detail/25378.html''
target=''_blank''><b><font color=''blue''>Instance Specification Family</font></a></b>'
zh-cn: 填写VSwitch2可用区下可使用的规格;<br>通用规格:<font color='red'><b>ecs.c5.large</b></font><br>注:可用区可能不支持通用规格<br>规格详见:<a
href='https://help.aliyun.com/document_detail/25378.html' target='_blank'><b><font
color='blue'>实例规格族</font></a></b>
AssociationProperty: ALIYUN::ECS::Instance::InstanceType
AssociationPropertyMetadata:
ZoneId: Azone2
SystemDiskCategory:
Type: String
Label:
en: System Disk Type
zh-cn: 系统盘类型
Description:
en: '<font color=''blue''><b>Optional values:</b></font><br>[cloud_efficiency:
<font color=''green''>Efficient Cloud Disk</font>]<br>[cloud_ssd: <font color=''green''>SSD
Cloud Disk</font>]<br>[cloud_essd: <font color=''green''>ESSD Cloud Disk</font>]<br>[cloud:
<font color=''green''>Cloud Disk</font>]<br>[ephemeral_ssd: <font color=''green''>Local
SSD Cloud Disk</font>]'
zh-cn: '<font color=''blue''><b>可选值:</b></font><br>[cloud_efficiency: <font
color=''green''>高效云盘</font>]<br>[cloud_ssd: <font color=''green''>SSD云盘</font>]<br>[cloud_essd:
<font color=''green''>ESSD云盘</font>]<br>[cloud: <font color=''green''>普通云盘</font>]<br>[ephemeral_ssd:
<font color=''green''>本地SSD盘</font>]'
Default: cloud_ssd
AllowedValues:
- cloud_auto
- cloud_efficiency
- cloud_ssd
- cloud
- cloud_essd
- ephemeral_ssd
Password:
Type: String
Label:
en: Instance Password
zh-cn: 实例密码
Description:
en: Server login password, Length 8-30, must contain three(Capital letters,
lowercase letters, numbers, ()`~!@#$%^&*_-+=|{}[]:;'<>,.?/ Special symbol
in).
zh-cn: 服务器登录密码,长度8-30,必须包含三项(大写字母、小写字母、数字、 ()`~!@#$%^&*_-+=|{}[]:;'<>,.?/ 中的特殊符号)。
ConstraintDescription:
en: Length 8-30, must contain three(Capital letters, lowercase letters, numbers,
()`~!@#$%^&*_-+=|{}[]:;'<>,.?/ Special symbol in).
zh-cn: 长度8-30,必须包含三项(大写字母、小写字母、数字、 ()`~!@#$%^&*_-+=|{}[]:;'<>,.?/ 中的特殊符号)。
AllowedPattern: '[0-9A-Za-z\_\-\&:;''<>,=%`~!@#\(\)\$\^\*\+\|\{\}\[\]\.\?\/]+$'
MinLength: 8
MaxLength: 30
NoEcho: true
LoadBalancerSpec:
Type: String
Label:
en: Specifications
zh-cn: 规格
Description:
en: Instance specifications,</br>see detail:</b><a href='https://www.alibabacloud.com/help/doc-detail/85939.html'
target='_blank'><b><font color='blue'>Performance support type</b></font></a>
zh-cn: 实例规格,</br>详见:</b><a href='https://help.aliyun.com/document_detail/85939.html'
target='_blank'><b><font color='blue'>性能保障型</b></font></a>
Default: slb.s1.small
Bandwidth:
Type: Number
Label:
en: Bandwidth
zh-cn: 带宽包带宽峰值
Description:
en: The units are Mbps, ranging from 2 to 10000
zh-cn: 单位为Mbps,范围2-10000。
Default: 2
MinValue: 2
MaxValue: 10000
GeographicRegionAId:
Type: String
Label:
en: Geographic A Region ID
zh-cn: 网络实例A所属大区
Description:
en: '<font color=''blue''><b>The region to which the network instance belongs,
Purchasing a cross-border bandwidth pack requires that the current account
be enterprise certified; optional values:</b></font><br>[China: <font color=''green''>Chinese
Mainland</font>]<br>[North-America: <font color=''green''>North America</font>]<br>[Asia-Pacific:
<font color=''green''>Asia-Pacific</font>]<br>[Europe: <font color=''green''>Europe</font>]<br>[Australia:
<font color=''green''>Australia</font>]<br><font color=''blue''></a>'
zh-cn: '<font color=''blue''><b>网络实例所属的大区,购买跨境带宽包需要保证当前帐号已取得企业认证;可选值: </b></font><br>[China:
<font color=''green''>中国大陆</font>]<br>[North-America: <font color=''green''>北美</font>]<br>[Asia-Pacific:
<font color=''green''>亚太</font>]<br>[Europe: <font color=''green''>欧洲</font>]<br>[Australia:
<font color=''green''>澳洲</font>]<br><font color=''blue''></a>'
Default: China
AllowedValues:
- China
- North-America
- Asia-Pacific
- Europe
- Australia
GeographicRegionBId:
Type: String
Label:
en: Geographic B Region ID
zh-cn: 网络实例B所属的大区
Description:
en: '<font color=''blue''><b>The region to which the network instance belongs,
Purchasing a cross-border bandwidth pack requires that the current account
be enterprise certified; optional values:</b></font><br>[China: <font color=''green''>Chinese
Mainland</font>]<br>[North-America: <font color=''green''>North America</font>]<br>[Asia-Pacific:
<font color=''green''>Asia-Pacific</font>]<br>[Europe: <font color=''green''>Europe</font>]<br>[Australia:
<font color=''green''>Australia</font>]<br><font color=''blue''></a>'
zh-cn: '<font color=''blue''><b>网络实例所属的大区,购买跨境带宽包需要保证当前帐号已取得企业认证;可选值: </b></font><br>[China:
<font color=''green''>中国大陆</font>]<br>[North-America: <font color=''green''>北美</font>]<br>[Asia-Pacific:
<font color=''green''>亚太</font>]<br>[Europe: <font color=''green''>欧洲</font>]<br>[Australia:
<font color=''green''>澳洲</font>]<br><font color=''blue''></a>'
Default: China
AllowedValues:
- China
- North-America
- Asia-Pacific
- Europe
- Australia
SecurityGroupName:
Type: String
Label:
en: Security Group Name
zh-cn: 安全组名称
Description:
en: 2 to 128 English or Chinese characters in length.Must start with size letters
or Chinese, not http:// and https://, can contain Numbers, dots (.), underscores
(_) and hyphens (-).
zh-cn: 长度为2~128个英文或中文字符。必须以大小字母或中文开头,不能以http://和https://开头,可包含数字、点(.)、下划线(_)和连字符(-)。
Default: mysecuritygroup
Resources:
Vpc:
Type: ALIYUN::ECS::VPC
Properties:
CidrBlock:
Ref: VpcCidrBlock
VpcName:
Fn::Join:
- '-'
- - StackId
- Ref: ALIYUN::StackId
SecurityGroup:
Type: ALIYUN::ECS::SecurityGroup
Properties:
VpcId:
Ref: Vpc
SecurityGroupEgress:
- DestCidrIp: 0.0.0.0/0
IpProtocol: all
NicType: internet
PortRange: -1/-1
Priority: 1
- DestCidrIp: 0.0.0.0/0
IpProtocol: all
NicType: intranet
PortRange: -1/-1
Priority: 1
SecurityGroupIngress:
- IpProtocol: all
NicType: internet
PortRange: -1/-1
Priority: 1
SourceCidrIp: 0.0.0.0/0
- IpProtocol: all
NicType: intranet
PortRange: -1/-1
Priority: 1
SourceCidrIp: 0.0.0.0/0
SecurityGroupName:
Fn::Join:
- '-'
- - StackId
- Ref: ALIYUN::StackId
Tags:
- Key: best_practice
Value: '020'
VSwitch1:
Type: ALIYUN::ECS::VSwitch
Properties:
ZoneId:
Ref: Azone1
VpcId:
Ref: Vpc
CidrBlock:
Ref: VSwitch1CidrBlock
VSwitchName:
Fn::Join:
- '-'
- - VSwitch1
- StackId
- Ref: ALIYUN::StackId
BackendServer1:
Type: ALIYUN::ECS::Instance
Properties:
VpcId:
Ref: Vpc
VSwitchId:
Ref: VSwitch1
SecurityGroupId:
Ref: SecurityGroup
ImageId:
Ref: ImageId
InstanceChargeType: PostPaid
InstanceType:
Ref: VSwitch1InstanceType
IoOptimized: optimized
SystemDiskCategory:
Ref: SystemDiskCategory
Tags:
- Key: best_practice
Value: '020'
UserData:
Fn::Join:
- ''
- - '#!/bin/sh
'
- 'sudo yum check-update
'
- "sudo yum -y install httpd php \n"
- 'cd /var/www/html
'
- 'echo "hello world,This is shanghaiECS1." >index.html
'
- 'service httpd start
'
- systemctl enable httpd.service
DependsOn:
- VSwitch1
- Vpc
VSwitch2:
Type: ALIYUN::ECS::VSwitch
Properties:
ZoneId:
Ref: Azone2
VpcId:
Ref: Vpc
CidrBlock:
Ref: VSwitch2CidrBlock
VSwitchName:
Fn::Join:
- '-'
- - VSwitch2
- StackId
- Ref: ALIYUN::StackId
BackendServer2:
Type: ALIYUN::ECS::Instance
Properties:
VpcId:
Ref: Vpc
VSwitchId:
Ref: VSwitch2
SecurityGroupId:
Ref: SecurityGroup
ImageId:
Ref: ImageId
InstanceChargeType: PostPaid
InstanceType:
Ref: VSwitch2InstanceType
IoOptimized: optimized
SystemDiskCategory:
Ref: SystemDiskCategory
Tags:
- Key: best_practice
Value: '020'
UserData:
Fn::Join:
- ''
- - '#!/bin/sh
'
- 'sudo yum check-update
'
- "sudo yum -y install httpd php \n"
- 'cd /var/www/html
'
- 'echo "hello world,This is shanghaiECS2." >index.html
'
- 'service httpd start
'
- systemctl enable httpd.service
DependsOn:
- VSwitch2
- Vpc
LoadBalancer:
Type: ALIYUN::SLB::LoadBalancer
Properties:
AddressType: internet
Bandwidth: 1
InternetChargeType: paybytraffic
LoadBalancerSpec:
Ref: LoadBalancerSpec
MasterZoneId:
Ref: Azone2
Tags:
- Key: best_practice
Value: '020'
Attachment:
Type: ALIYUN::SLB::BackendServerAttachment
Properties:
BackendServerList:
- Ref: BackendServer1
- Ref: BackendServer2
BackendServerWeightList:
- 100
LoadBalancerId:
Ref: LoadBalancer
DependsOn:
- BackendServer1
- BackendServer2
CenBandwidthPackage:
Type: ALIYUN::CEN::CenBandwidthPackage
Properties:
Bandwidth:
Ref: Bandwidth
BandwidthPackageChargeType: POSTPAY
GeographicRegionAId:
Ref: GeographicRegionAId
GeographicRegionBId:
Ref: GeographicRegionBId
CenInstance:
Type: ALIYUN::CEN::CenInstance
Properties: {}
CenBandwidthPackageAssociation:
Type: ALIYUN::CEN::CenBandwidthPackageAssociation
Properties:
CenBandwidthPackageId:
Ref: CenBandwidthPackage
CenId:
Ref: CenInstance
DependsOn:
- CenBandwidthPackage
- CenInstance
CenVBRAttachment:
Type: ALIYUN::CEN::CenInstanceAttachment
Condition: BindVBR
Properties:
CenId:
Fn::GetAtt:
- CenInstance
- CenId
ChildInstanceId:
Ref: OtherVBRId
ChildInstanceRegionId:
Ref: OtherVBRRegion
ChildInstanceType: VBR
DependsOn:
- CenBandwidthPackageAssociation
CenVpcAttachment:
Type: ALIYUN::CEN::CenInstanceAttachment
Properties:
CenId:
Ref: CenInstance
ChildInstanceId:
Ref: OtherVpcId
ChildInstanceRegionId:
Ref: OtherVPCRegion
ChildInstanceType: VPC
DependsOn:
- CenBandwidthPackageAssociation
- CenInstance
- CenVBRAttachment
SlbListener:
Type: ALIYUN::SLB::Listener
Properties:
BackendServerPort: 80
Bandwidth: -1
HealthCheck:
HealthyThreshold: 3
HttpCode: http_2xx,http_3xx,http_4xx,http_5xx
Interval: 2
Timeout: 5
UnhealthyThreshold: 3
ListenerPort: '80'
LoadBalancerId:
Ref: LoadBalancer
Protocol: http
TheCenVpcAttachment:
Type: ALIYUN::CEN::CenInstanceAttachment
Properties:
CenId:
Ref: CenInstance
ChildInstanceId:
Ref: Vpc
ChildInstanceRegionId:
Ref: ALIYUN::Region
ChildInstanceType: VPC
DependsOn:
- CenVpcAttachment
Outputs:
LoadBalancerId:
Description:
en: SLB ID
zh-cn: 负载均衡实力ID
Value:
Fn::GetAtt:
- LoadBalancer
- LoadBalancerId
SlbIpAddress:
Description:
en: SLB IP
zh-cn: 负载均衡IP地址。
Value:
Fn::GetAtt:
- LoadBalancer
- IpAddress
VpcId:
Description:
en: VPC Id
zh-cn: 虚拟专有网络Id
Value:
Fn::GetAtt:
- Vpc
- VpcId
Metadata:
ALIYUN::ROS::Interface:
ParameterGroups:
- Parameters:
- OtherVBRRegion
- OtherVBRId
- OtherVPCRegion
- OtherVpcId
Label:
default:
en: Information Required
zh-cn: 需组建网络的地域信息
- Parameters:
- VpcCidrBlock
- Azone1
- VSwitch1CidrBlock
- Azone2
- VSwitch2CidrBlock
Label:
default: VPC
- Parameters:
- ImageId
- VSwitch1InstanceType
- VSwitch2InstanceType
- SystemDiskCategory
- Password
Label:
default: ECS
- Parameters:
- LoadBalancerSpec
Label:
default: SLB
- Parameters:
- Bandwidth
- GeographicRegionAId
- GeographicRegionBId
Label:
default: CEN
TemplateTags:
- acs:solution:网络组网:组建多可用区多地域的混合云-多可用区多地域混合云搭建服务