全部產品
Search
文件中心

Resource Orchestration Service:ALIYUN::CS::ClusterAddons

更新時間:Jul 16, 2026

ALIYUN::CS::ClusterAddons類型用於指定叢集安裝組件。

文法

{
  "Type": "ALIYUN::CS::ClusterAddons",
  "Properties": {
    "ClusterId": String,
    "Addons": List,
    "InstalledIgnore": Boolean,
    "WaitUntil": List,
    "OverrideExisting": Boolean,
    "RolePolicy": String,
    "ValidationMode": String
  }
}

屬性

屬性名稱

類型

必須

允許更新

描述

約束

Addons

List

是

是

組件配置資訊列表。

更多資訊,請參見Addons屬性。

ClusterId

String

是

否

叢集ID。

無

InstalledIgnore

Boolean

否

否

建立叢集時是否忽略已安裝的組件。

取值:

  • true:忽略已安裝的組件。

    當建立叢集時,只安裝尚未安裝的組件。當刪除叢集時,只卸載在建立階段安裝的組件。

  • false(預設值):不忽略已安裝的組件。

OverrideExisting

Boolean

否

否

建立時是否覆蓋已安裝外掛程式(addon)的配置。

如果為 true,建立時,已存在的外掛程式將覆蓋其配置,不存在的外掛程式將被安裝;刪除時,僅卸載在建立階段安裝的外掛程式。 不能與 InstalledIgnore 同時使用。 預設值為 false。

RolePolicy

String

否

是

在部署應用程式之前,請檢查與目前使用者的角色關聯的策略。 

取值:

  • EnsureAdminRoleAndBinding(預設值):自動建立一個名為ros:application-admin:${user-id}\的角色,具有管理員權限,並將其綁定到目前使用者。 

  • None:不執行任何操作。 

ValidationMode

String

否

否

驗證模式。

取值:

  • Basic:基本驗證,例如驗證叢集是否存在。

  • Strict:除了基本驗證外,還驗證WaitUntil的合法性。 

WaitUntil

List

否

是

開始建立或更新後,等待直到滿足所有條件。 

更多資訊,請參見WaitUntil屬性。

Addons文法

"Addons": [
  {
    "Version": String,
    "Config": String,
    "Name": String
  }
]

Addons屬性

屬性名稱

類型

必須

允許更新

描述

約束

Name

String

是

否

組件名稱。

無

Config

String

否

是

組件配置資訊。

無

Version

String

否

否

組件版本。

無

WaitUntil文法

"WaitUntil": [
  {
   "ApiVersion": String,
   "FirstMatch": Boolean,
   "Timeout": Integer,
   "JsonPath": String,
   "Namespace": String,
   "Stage": String,
   "Name": String,
   "ValueType": String,
   "Kind": String,
   "Value": String,
   "Operator": String
  }
]

WaitUntil屬性

屬性名稱

類型

必須

允許更新

描述

約束

Kind

String

是

是

要查詢的kubernetes資源類型。

無

Name

String

是

是

要查詢的kubernetes資源名稱。

無

Operator

String

是

是

將值與JsonPath運算式的結果進行比較的操作符。 

無

ApiVersion

String

否

是

API版本。

無

FirstMatch

Boolean

否

是

只返回 JsonPath過濾結果中的第一個匹配結果。 

取值:

  • true

  • false(預設值)

JsonPath

String

否

是

Json路徑運算式用於過濾輸出。

無

Namespace

String

否

是

資源所在的kubernetes的命名空間。

預設值為DefaultNamespace。 

Stage

String

否

否

在什麼階段等待。  

取值:

  • Create/Update(預設值):建立和更新階段。

  • Delete:刪除階段。 

Timeout

Integer

否

是

等待滿足條件的逾時時間。

單位為秒。

Value

String

否

是

要與JsonPath運算式的結果進行比較的值。 

無

ValueType

String

否

是

值的類型。

預設值為String。

傳回值

Fn::GetAtt

  • ClusterId:叢集ID。

  • WaitUntilData:WaitUntil中每個JsonPath的值列表。 

樣本

情境 1 :為ACK叢集安裝基礎網路和日誌組件。

ROSTemplateFormatVersion: '2015-09-01'
Description:
  zh-cn: 為ACK叢集安裝基礎網路和日誌組件。
  en: Install basic network and logging addons for an ACK cluster.
Parameters:
  ClusterId:
    Type: String
    Label:
      zh-cn: 叢集ID
      en: Cluster ID
    Description:
      zh-cn: ACK叢集的唯一標識,可在Container Service控制台擷取。
      en: The unique identifier of the ACK cluster, available in the Container Service console.
    AssociationProperty: ALIYUN::CS::Cluster::ClusterId
Resources:
  ClusterAddons:
    Type: ALIYUN::CS::ClusterAddons
    Properties:
      ClusterId:
        Ref: ClusterId
      Addons:
        - Name: flannel
        - Name: logtail-ds
      InstalledIgnore: true
Outputs:
  ClusterId:
    Label:
      zh-cn: 叢集ID
      en: Cluster ID
    Description:
      zh-cn: 已安裝組件的ACK叢集ID。
      en: The ACK cluster ID with addons installed.
    Value:
      Fn::GetAtt:
        - ClusterAddons
        - ClusterId
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Description": {
    "zh-cn": "為ACK叢集安裝基礎網路和日誌組件。",
    "en": "Install basic network and logging addons for an ACK cluster."
  },
  "Parameters": {
    "ClusterId": {
      "Type": "String",
      "Label": {
        "zh-cn": "叢集ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "ACK叢集的唯一標識,可在Container Service控制台擷取。",
        "en": "The unique identifier of the ACK cluster, available in the Container Service console."
      },
      "AssociationProperty": "ALIYUN::CS::Cluster::ClusterId"
    }
  },
  "Resources": {
    "ClusterAddons": {
      "Type": "ALIYUN::CS::ClusterAddons",
      "Properties": {
        "ClusterId": {
          "Ref": "ClusterId"
        },
        "Addons": [
          {
            "Name": "flannel"
          },
          {
            "Name": "logtail-ds"
          }
        ],
        "InstalledIgnore": true
      }
    }
  },
  "Outputs": {
    "ClusterId": {
      "Label": {
        "zh-cn": "叢集ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "已安裝組件的ACK叢集ID。",
        "en": "The ACK cluster ID with addons installed."
      },
      "Value": {
        "Fn::GetAtt": [
          "ClusterAddons",
          "ClusterId"
        ]
      }
    }
  }
}

情境 2 :為ACK叢集安裝Ingress和監控組件,並指定版本和自訂配置。

ROSTemplateFormatVersion: '2015-09-01'
Description:
  zh-cn: 為ACK叢集安裝Ingress和監控組件,指定版本和自訂配置。
  en: Install Ingress and monitoring addons with version pinning and custom config.
Parameters:
  ClusterId:
    Type: String
    Label:
      zh-cn: 叢集ID
      en: Cluster ID
    Description:
      zh-cn: 目標ACK叢集的唯一標識。
      en: The unique identifier of the target ACK cluster.
    AssociationProperty: ALIYUN::CS::Cluster::ClusterId
  IngressVersion:
    Type: String
    Label:
      zh-cn: Ingress組件版本
      en: Ingress Addon Version
    Description:
      zh-cn: >-
        Nginx Ingress Controller的版本號碼。
        留空則安裝最新版本。
      en: >-
        Version of Nginx Ingress Controller.
        Leave empty to install the latest version.
    Default: ''
  IngressReplicas:
    Type: Number
    Label:
      zh-cn: Ingress副本數
      en: Ingress Replicas
    Description:
      zh-cn: Nginx Ingress Controller的副本數量,生產環境建議至少2個副本。
      en: Number of Nginx Ingress Controller replicas. At least 2 replicas recommended for production.
    Default: 2
    MinValue: 1
    MaxValue: 10
  RolePolicy:
    Type: String
    Label:
      zh-cn: 角色策略
      en: Role Policy
    Description:
      zh-cn: >-
        部署組件前的角色檢查策略。
        EnsureAdminRoleAndBinding:自動建立管理員角色並綁定。
        None:不執行角色操作。
      en: >-
        Role check policy before deploying addons.
        EnsureAdminRoleAndBinding: auto-create admin role and bindingit.
        None: skip role operations.
    Default: EnsureAdminRoleAndBinding
    AllowedValues:
      - EnsureAdminRoleAndBinding
      - None
Resources:
  ClusterAddons:
    Type: ALIYUN::CS::ClusterAddons
    Properties:
      ClusterId:
        Ref: ClusterId
      InstalledIgnore: true
      RolePolicy:
        Ref: RolePolicy
      Addons:
        - Name: nginx-ingress-controller
          Version:
            Ref: IngressVersion
          Config:
            Fn::Sub:
              - '{"IngressSlbNetworkType":"internet","IngressSlbSpec":"slb.s2.small","IngressReplicaCount":${Replicas}}'
              - Replicas:
                  Ref: IngressReplicas
        - Name: arms-prometheus
Outputs:
  ClusterId:
    Label:
      zh-cn: 叢集ID
      en: Cluster ID
    Value:
      Fn::GetAtt:
        - ClusterAddons
        - ClusterId
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Description": {
    "zh-cn": "為ACK叢集安裝Ingress和監控組件,指定版本和自訂配置。",
    "en": "Install Ingress and monitoring addons with version pinning and custom config."
  },
  "Parameters": {
    "ClusterId": {
      "Type": "String",
      "Label": {
        "zh-cn": "叢集ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "目標ACK叢集的唯一標識。",
        "en": "The unique identifier of the target ACK cluster."
      },
      "AssociationProperty": "ALIYUN::CS::Cluster::ClusterId"
    },
    "IngressVersion": {
      "Type": "String",
      "Label": {
        "zh-cn": "Ingress組件版本",
        "en": "Ingress Addon Version"
      },
      "Description": {
        "zh-cn": "Nginx Ingress Controller的版本號碼。留空則安裝最新版本。",
        "en": "Version of Nginx Ingress Controller. Leave empty to install the latest version."
      },
      "Default": ""
    },
    "IngressReplicas": {
      "Type": "Number",
      "Label": {
        "zh-cn": "Ingress副本數",
        "en": "Ingress Replicas"
      },
      "Description": {
        "zh-cn": "Nginx Ingress Controller的副本數量,生產環境建議至少2個副本。",
        "en": "Number of Nginx Ingress Controller replicas. At least 2 replicas recommended for production."
      },
      "Default": 2,
      "MinValue": 1,
      "MaxValue": 10
    },
    "RolePolicy": {
      "Type": "String",
      "Label": {
        "zh-cn": "角色策略",
        "en": "Role Policy"
      },
      "Description": {
        "zh-cn": "部署組件前的角色檢查策略。EnsureAdminRoleAndBinding:自動建立管理員角色並綁定。None:不執行角色操作。",
        "en": "Role check policy before deploying addons. EnsureAdminRoleAndBinding: auto-create admin role and bind it. None: skip role operations."
      },
      "Default": "EnsureAdminRoleAndBinding",
      "AllowedValues": [
        "EnsureAdminRoleAndBinding",
        "None"
      ]
    }
  },
  "Resources": {
    "ClusterAddons": {
      "Type": "ALIYUN::CS::ClusterAddons",
      "Properties": {
        "ClusterId": {
          "Ref": "ClusterId"
        },
        "InstalledIgnore": true,
        "RolePolicy": {
          "Ref": "RolePolicy"
        },
        "Addons": [
          {
            "Name": "nginx-ingress-controller",
            "Version": {
              "Ref": "IngressVersion"
            },
            "Config": {
              "Fn::Sub": [
                "{\"IngressSlbNetworkType\":\"internet\",\"IngressSlbSpec\":\"slb.s2.small\",\"IngressReplicaCount\":${Replicas}}",
                {
                  "Replicas": {
                    "Ref": "IngressReplicas"
                  }
                }
              ]
            }
          },
          {
            "Name": "arms-prometheus"
          }
        ]
      }
    }
  },
  "Outputs": {
    "ClusterId": {
      "Label": {
        "zh-cn": "叢集ID",
        "en": "Cluster ID"
      },
      "Value": {
        "Fn::GetAtt": [
          "ClusterAddons",
          "ClusterId"
        ]
      }
    }
  }
}

情境 3 :為ACK叢集安裝完整的生產級組件套件,使用WaitUntil等待組件就緒後再繼續部署。

ROSTemplateFormatVersion: '2015-09-01'
Description:
  zh-cn: 為ACK叢集安裝完整的生產級組件套件,使用WaitUntil等待組件就緒。
  en: Install a full production addon suite for ACK with WaitUntil readiness checks.
Parameters:
  ClusterId:
    Type: String
    Label:
      zh-cn: 叢集ID
      en: Cluster ID
    Description:
      zh-cn: 目標ACK叢集的唯一標識。
      en: The unique identifier of the target ACK cluster.
    AssociationProperty: ALIYUN::CS::Cluster::ClusterId
  IngressReplicas:
    Type: Number
    Label:
      zh-cn: Ingress副本數
      en: Ingress Replicas
    Description:
      zh-cn: Nginx Ingress Controller的副本數量。
      en: Number of Nginx Ingress Controller replicas.
    Default: 2
    MinValue: 1
    MaxValue: 10
  WaitTimeout:
    Type: Number
    Label:
      zh-cn: 組件就緒逾時時間(秒)
      en: Addon Readiness Timeout (seconds)
    Description:
      zh-cn: >-
        等待組件就緒的逾時時間,單位為秒。
        逾時後資源棧將復原。建議根據叢集規模適當調大。
      en: >-
        Timeout for waiting addon readiness, in seconds.
        Stack will roll back on timeout. Increase for larger clusters.
    Default: 300
    MinValue: 60
    MaxValue: 1800
Resources:
  ClusterAddons:
    Type: ALIYUN::CS::ClusterAddons
    Properties:
      ClusterId:
        Ref: ClusterId
      InstalledIgnore: true
      RolePolicy: EnsureAdminRoleAndBinding
      ValidationMode: Strict
      Addons:
        - Name: terway-eniip
        - Name: coredns
        - Name: nginx-ingress-controller
          Config:
            Fn::Sub:
              - '{"IngressSlbNetworkType":"internet","IngressSlbSpec":"slb.s2.small","IngressReplicaCount":${Replicas}}'
              - Replicas:
                  Ref: IngressReplicas
        - Name: arms-prometheus
      WaitUntil:
        - Kind: Deployment
          Name: coredns
          Namespace: kube-system
          JsonPath: $.status.readyReplicas
          Value: '1'
          Operator: NotEmpty
          Timeout:
            Ref: WaitTimeout
          Stage: Create/Update
          ApiVersion: apps/v1
          FirstMatch: true
        - Kind: DaemonSet
          Name: terway-eniip
          Namespace: kube-system
          JsonPath: $.status.numberReady
          Value: '1'
          Operator: NotEmpty
          Timeout:
            Ref: WaitTimeout
          Stage: Create/Update
          ApiVersion: apps/v1
          FirstMatch: true
Outputs:
  ClusterId:
    Label:
      zh-cn: 叢集ID
      en: Cluster ID
    Description:
      zh-cn: 已完成生產級組件部署的ACK叢集ID。
      en: The ACK cluster ID with production addons deployed.
    Value:
      Fn::GetAtt:
        - ClusterAddons
        - ClusterId
  WaitUntilData:
    Label:
      zh-cn: 組件就緒檢查結果
      en: Addon Readiness Check Results
    Description:
      zh-cn: WaitUntil中每個JsonPath的值列表,用於驗證組件是否已就緒。
      en: The value list for each JsonPath in WaitUntil, for verifying addon readiness.
    Value:
      Fn::GetAtt:
        - ClusterAddons
        - WaitUntilData
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Description": {
    "zh-cn": "為ACK叢集安裝完整的生產級組件套件,使用WaitUntil等待組件就緒。",
    "en": "Install a full production addon suite for ACK with WaitUntil readiness checks."
  },
  "Parameters": {
    "ClusterId": {
      "Type": "String",
      "Label": {
        "zh-cn": "叢集ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "目標ACK叢集的唯一標識。",
        "en": "The unique identifier of the target ACK cluster."
      },
      "AssociationProperty": "ALIYUN::CS::Cluster::ClusterId"
    },
    "IngressReplicas": {
      "Type": "Number",
      "Label": {
        "zh-cn": "Ingress副本數",
        "en": "Ingress Replicas"
      },
      "Description": {
        "zh-cn": "Nginx Ingress Controller的副本數量。",
        "en": "Number of Nginx Ingress Controller replicas."
      },
      "Default": 2,
      "MinValue": 1,
      "MaxValue": 10
    },
    "WaitTimeout": {
      "Type": "Number",
      "Label": {
        "zh-cn": "組件就緒逾時時間(秒)",
        "en": "Addon Readiness Timeout (seconds)"
      },
      "Description": {
        "zh-cn": "等待組件就緒的逾時時間,單位為秒。逾時後資源棧將復原。建議根據叢集規模適當調大。",
        "en": "Timeout for waiting addon readiness, in seconds. Stack will roll back on timeout. Increase for larger clusters."
      },
      "Default": 300,
      "MinValue": 60,
      "MaxValue": 1800
    }
  },
  "Resources": {
    "ClusterAddons": {
      "Type": "ALIYUN::CS::ClusterAddons",
      "Properties": {
        "ClusterId": {
          "Ref": "ClusterId"
        },
        "InstalledIgnore": true,
        "RolePolicy": "EnsureAdminRoleAndBinding",
        "ValidationMode": "Strict",
        "Addons": [
          {
            "Name": "terway-eniip"
          },
          {
            "Name": "coredns"
          },
          {
            "Name": "nginx-ingress-controller",
            "Config": {
              "Fn::Sub": [
                "{\"IngressSlbNetworkType\":\"internet\",\"IngressSlbSpec\":\"slb.s2.small\",\"IngressReplicaCount\":${Replicas}}",
                {
                  "Replicas": {
                    "Ref": "IngressReplicas"
                  }
                }
              ]
            }
          },
          {
            "Name": "arms-prometheus"
          }
        ],
        "WaitUntil": [
          {
            "Kind": "Deployment",
            "Name": "coredns",
            "Namespace": "kube-system",
            "JsonPath": "$.status.readyReplicas",
            "Value": "1",
            "Operator": "NotEmpty",
            "Timeout": {
              "Ref": "WaitTimeout"
            },
            "Stage": "Create/Update",
            "ApiVersion": "apps/v1",
            "FirstMatch": true
          },
          {
            "Kind": "DaemonSet",
            "Name": "terway-eniip",
            "Namespace": "kube-system",
            "JsonPath": "$.status.numberReady",
            "Value": "1",
            "Operator": "NotEmpty",
            "Timeout": {
              "Ref": "WaitTimeout"
            },
            "Stage": "Create/Update",
            "ApiVersion": "apps/v1",
            "FirstMatch": true
          }
        ]
      }
    }
  },
  "Outputs": {
    "ClusterId": {
      "Label": {
        "zh-cn": "叢集ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "已完成生產級組件部署的ACK叢集ID。",
        "en": "The ACK cluster ID with production addons deployed."
      },
      "Value": {
        "Fn::GetAtt": [
          "ClusterAddons",
          "ClusterId"
        ]
      }
    },
    "WaitUntilData": {
      "Label": {
        "zh-cn": "組件就緒檢查結果",
        "en": "Addon Readiness Check Results"
      },
      "Description": {
        "zh-cn": "WaitUntil中每個JsonPath的值列表,用於驗證組件是否已就緒。",
        "en": "The value list for each JsonPath in WaitUntil, for verifying addon readiness."
      },
      "Value": {
        "Fn::GetAtt": [
          "ClusterAddons",
          "WaitUntilData"
        ]
      }
    }
  }
}