"Type": "AWS::EC2::SecurityGroupIngress",
"Properties": {
"Description" : "Allow outbound traffic to EKS worker nodes security group across account",
"GroupId": "sg-xxxxxxx", # source security group ID
"IpProtocol": "tcp",
"FromPort": "0",
"ToPort": "65535",
"SourceSecurityGroupId": "sg-yyyyyyy", # destination EKS worker nodes security group ID
"SourceSecurityGroupName": "",
"SourceSecurityGroupOwnerId": "xxxxxxxxxxxx" # destination AWS account ID
}
"Type": "AWS::EC2::SecurityGroupIngress",
"Properties": {
"Description" : "Allow incoming traffic from EKS worker nodes security group across account",
"GroupId": "sg-yyyyyyy", # destination security group ID
"IpProtocol": "tcp",
"FromPort": "0",
"ToPort": "65535",
"SourceSecurityGroupId": "sg-xxxxxxx", # source EKS worker nodes security group ID
"SourceSecurityGroupName": "",
"SourceSecurityGroupOwnerId": "yyyyyyyyyyyy" # source AWS account ID
}
注意:使用跨账户功能需要确保已经通过AWS IAM设置了角色和权限。