1+ Metadata :
2+ License : Apache-2.0
3+ AWSTemplateFormatVersion : ' 2010-09-09'
4+ Description : ' AWS CloudFormation Template to create an EC2 instance
5+ **WARNING** This template creates an Amazon EC2 instance and an Elastic IP Address.
6+ You will be billed for the AWS resources used if you create a stack from this template.'
7+
8+ Parameters :
9+ Namespace :
10+ Type : String
11+ Description : An environment name that will be prefixed to resource names
12+ S3Mounts :
13+ Type : String
14+ Description : A JSON array of objects with name, bucket, and prefix properties used to mount data
15+ IamPolicyDocument :
16+ Type : String
17+ Description : The IAM policy to be associated with the launched workstation
18+ EnvironmentInstanceFiles :
19+ Type : String
20+ Description : >-
21+ An S3 URI (starting with "s3://") that specifies the location of files to be copied to
22+ the environment instance, including any bootstrap scripts
23+ InstanceType :
24+ Description : Choose the instance type for this instance. e.g. t2.small
25+ Type : String
26+ Default : t2.small
27+ AllowedValues : [t2.nano, t2.micro, t2.small, t2.medium]
28+ ConstraintDescription : must be a valid EC2 instance type.
29+ KeyPair :
30+ Description : Name of an existing EC2 KeyPair to enable SSH access to the instance. If no key pairs exist, please create one from the button next to the dropdown. Please contact your Administrator if you are unable to create one.
31+ Type : AWS::EC2::KeyPair::KeyName
32+ ConstraintDescription : must be the name of an existing EC2 KeyPair.
33+ AllowedSSHLocation :
34+ Description : The IP address range that can be used to SSH to the EC2 instances
35+ Type : String
36+ MinLength : ' 9'
37+ MaxLength : ' 18'
38+ Default : 0.0.0.0/0
39+ AllowedPattern : (\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})/(\d{1,2})
40+ ConstraintDescription : must be a valid IP CIDR range of the form x.x.x.x/x.
41+ LatestAmiId :
42+ Type : ' AWS::SSM::Parameter::Value<AWS::EC2::Image::Id>'
43+ Default : ' /aws/service/ecs/optimized-ami/amazon-linux-2/recommended/image_id'
44+ MasterPassword :
45+ NoEcho : " true"
46+ Description : " The database master password"
47+ Type : " String"
48+ MinLength : " 8"
49+ MaxLength : " 100"
50+ AllowedPattern : " [a-zA-Z0-9]{8,100}"
51+ ConstraintDescription : " must contain only alphanumeric characters."
52+ ConnectFromPort :
53+ Type : Number
54+ Description : Required Port mappings
55+ ConnectToPort :
56+ Type : Number
57+ Description : Required Port mappings
58+
59+ Conditions :
60+ IamPolicyEmpty : !Equals [!Ref IamPolicyDocument, '{}']
61+
62+ Resources :
63+ IAMRole :
64+ Type : ' AWS::IAM::Role'
65+ Properties :
66+ RoleName : !Join ['-', [Ref: Namespace, 'ec2-role']]
67+ Path : ' /'
68+ AssumeRolePolicyDocument :
69+ Version : ' 2012-10-17'
70+ Statement :
71+ - Effect : ' Allow'
72+ Principal :
73+ Service :
74+ - ' ec2.amazonaws.com'
75+ Action :
76+ - ' sts:AssumeRole'
77+ Policies :
78+ - !If
79+ - IamPolicyEmpty
80+ - !Ref ' AWS::NoValue'
81+ - PolicyName : !Join ['-', [Ref: Namespace, 's3-studydata-policy']]
82+ PolicyDocument : !Ref IamPolicyDocument
83+
84+ InstanceProfile :
85+ Type : ' AWS::IAM::InstanceProfile'
86+ Properties :
87+ InstanceProfileName : !Join ['-', [Ref: Namespace, 'ec2-profile']]
88+ Path : ' /'
89+ Roles :
90+ - Ref : IAMRole
91+
92+ EC2Instance :
93+ Type : AWS::EC2::Instance
94+ CreationPolicy :
95+ ResourceSignal :
96+ Timeout : PT5M
97+ Properties :
98+ UserData :
99+ Fn::Base64 : !Sub |
100+ # !/usr/bin/env bash
101+ # pull mysql version 8
102+ sudo yum install zip -y
103+ sudo yum install unzip -y
104+ # Install AWS CLI version2
105+ curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
106+ unzip awscliv2.zip
107+ sudo ./aws/install
108+ # Install Mysql Shell
109+ sudo yum install mysql -y
110+ # Pull Mysql Image
111+ docker pull mysql:8
112+ mkdir docker
113+ mkdir docker/mysql
114+ mkdir docker/mysql/conf
115+ mkdir docker/mysql/data
116+ docker run -d -p 3306:3306 \
117+ -v /home/ec2-user/docker/mysql/conf/:/etc/mysql/conf.d \
118+ -v /home/ec2-user/docker/mysql/data/:/var/lib/mysql \
119+ -e MYSQL_ROOT_PASSWORD=${MasterPassword} \
120+ --restart always \
121+ --name docker_mysql mysql:8 \
122+ # Download and execute shell script
123+ cd /home/ec2-user
124+ aws s3 cp "${EnvironmentInstanceFiles}/alter_rootpassword.sh" "alter_rootpassword.sh"
125+ chmod +x alter_rootpassword.sh
126+ ./alter_rootpassword.sh ${MasterPassword}
127+ # Install cfn
128+ yum install -y aws-cfn-bootstrap
129+ # Download and execute shell script
130+ aws s3 cp "${EnvironmentInstanceFiles}/get_bootstrap_mysql.sh" "/tmp"
131+ chmod 500 "/tmp/get_bootstrap_mysql.sh"
132+ /tmp/get_bootstrap_mysql.sh "${EnvironmentInstanceFiles}" '${S3Mounts}'
133+ # Signal result to CloudFormation
134+ /opt/aws/bin/cfn-signal --exit-code 0 --resource EC2Instance --region ${AWS::Region} --stack ${AWS::StackName}
135+ InstanceType : !Ref 'InstanceType'
136+ SecurityGroups : [!Ref 'InstanceSecurityGroup']
137+ KeyName : !Ref 'KeyPair'
138+ ImageId : !Ref 'LatestAmiId'
139+ IamInstanceProfile : !Ref InstanceProfile
140+ Tags :
141+ - Key : Name
142+ Value : !Join ['-', [Ref: Namespace, 'ec2-linux']]
143+ - Key : Description
144+ Value : EC2 workspace instance
145+
146+ InstanceSecurityGroup :
147+ Type : AWS::EC2::SecurityGroup
148+ Properties :
149+ GroupDescription : Enable SSH access
150+ SecurityGroupIngress :
151+ - IpProtocol : tcp
152+ FromPort : ' 22'
153+ ToPort : ' 22'
154+ CidrIp : !Ref 'AllowedSSHLocation'
155+ - IpProtocol : tcp
156+ FromPort : !Ref 'ConnectFromPort'
157+ ToPort : !Ref 'ConnectToPort'
158+ CidrIp : !Ref 'AllowedSSHLocation'
159+ Outputs :
160+ InstanceId :
161+ Description : InstanceId of the newly created EC2 instance
162+ Value : !Ref 'EC2Instance'
163+ InstanceIPAddress :
164+ Description : IP address of the newly created EC2 instance
165+ Value : !GetAtt [EC2Instance, PublicIp]
166+ InstanceDNSName :
167+ Description : DNS name of the newly created EC2 instance
168+ Value : !GetAtt [EC2Instance, PublicDnsName]
169+ InstancePrivateIPAddress :
170+ Description : Private IP address of the newly created EC2 instance
171+ Value : !GetAtt [EC2Instance, PrivateIp]
0 commit comments