View a markdown version of this page

Parti di un CloudFormation modello per AWS 2 PEZZI - AWS PEZZI

Le traduzioni sono generate tramite traduzione automatica. In caso di conflitto tra il contenuto di una traduzione e la versione originale in Inglese, quest'ultima prevarrà.

Parti di un CloudFormation modello per AWS 2 PEZZI

Un CloudFormation modello è composto da una o più sezioni, ognuna delle quali ha uno scopo specifico. CloudFormation definisce il formato, la sintassi e il linguaggio standard in un modello. Per ulteriori informazioni, vedere Utilizzo dei CloudFormation modelli nella Guida per l'AWS CloudFormation utente.

CloudFormation i modelli sono altamente personalizzabili e pertanto i loro formati possono variare. Per comprendere le parti necessarie di un CloudFormation modello per creare un cluster AWS PCS, ti consigliamo di esaminare il modello di esempio fornito per creare un cluster di esempio. Questo argomento spiega brevemente le sezioni di quel modello di esempio.

Importante

Gli esempi di codice in questo argomento non sono completi. La presenza dei puntini di sospensione ([...]) indica che è presente un codice aggiuntivo che non viene visualizzato. Per scaricare il YAML-formatted CloudFormation modello completo, consulta. CloudFormation modelli per creare un campione AWS cluster PCS

Header

AWSTemplateFormatVersion: '2010-09-09' Transform: AWS::Serverless-2016-10-31 Description: AWS Parallel Computing Service "getting started" cluster

AWSTemplateFormatVersionidentifica la versione del formato del modello a cui il modello è conforme. Per ulteriori informazioni, vedere la sintassi della versione CloudFormation del formato del modello nella Guida per l'AWS CloudFormation utente.

Transformspecifica una macro CloudFormation utilizzata per elaborare il modello. Per ulteriori informazioni, vedere la sezione Trasformazione del CloudFormation modello nella Guida per l'AWS CloudFormation utente. La AWS::Serverless-2016-10-31 trasformazione consente CloudFormation di elaborare un modello scritto nella sintassi AWS Serverless Application Model (AWS SAM). Per ulteriori informazioni, vedere AWS::Serverless transform nella Guida per l'AWS CloudFormation utente.

Metadati

### Stack metadata Metadata: AWS::CloudFormation::Interface: ParameterGroups: - Label: default: PCS Cluster configuration Parameters: - SlurmVersion - ManagedAccounting - AccountingPolicyEnforcement - Label: default: PCS ComputeNodeGroups configuration Parameters: - NodeArchitecture - KeyName - ClientIpCidr - Label: default: HPC Recipes configuration Parameters: - HpcRecipesS3Bucket - HpcRecipesBranch

La metadata sezione di un CloudFormation modello fornisce informazioni sul modello stesso. Il modello di esempio crea un cluster HPC (High Performance Computing) completo che utilizza AWS PCS. La sezione dei metadati del modello di esempio dichiara i parametri che controllano il modo in cui CloudFormation avvia (fornisce) lo stack corrispondente. Esistono parametri che controllano la scelta dell'architettura (NodeArchitecture), la versione di Slurm () e i controlli di SlurmVersion accesso (e). KeyName ClientIpCidr

Parameters

La Parameters sezione definisce i parametri personalizzati per il modello. CloudFormation utilizza queste definizioni di parametri per costruire e convalidare il modulo con cui interagisci quando avvii uno stack da questo modello.

Parameters: NodeArchitecture: Type: String Default: x86 AllowedValues: - x86 - Graviton Description: Processor architecture for the login and compute node instances SlurmVersion: Type: String Default: 25.11 Description: Version of Slurm to use AllowedValues: - 25.05 - 25.11 ManagedAccounting: Type: String Default: 'disabled' AllowedValues: - 'enabled' - 'disabled' Description: Monitor cluster usage, manage access control, and enforce resource limits with Slurm accounting. AccountingPolicyEnforcement: Description: Specify which Slurm accounting policies to enforce Type: String Default: none AllowedValues: - none - 'associations,limits,safe' KeyName: Description: SSH keypair to log in to the head node Type: AWS::EC2::KeyPair::KeyName AllowedPattern: ".+" # Required ClientIpCidr: Description: IP(s) allowed to access the login node over SSH. We recommend that you restrict it with your own IP/subnet (x.x.x.x/32 for your own ip or x.x.x.x/24 for range. Replace x.x.x.x with your own PUBLIC IP. You can get your public IP using tools such as https://ifconfig.co/) Default: 127.0.0.1/32 Type: String AllowedPattern: (\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})/(\d{1,2}) ConstraintDescription: Value must be a valid IP or network range of the form x.x.x.x/x. HpcRecipesS3Bucket: Type: String Default: aws-hpc-recipes Description: HPC Recipes for AWS S3 bucket AllowedValues: - aws-hpc-recipes - aws-hpc-recipes-dev HpcRecipesBranch: Type: String Default: main Description: HPC Recipes for AWS release branch AllowedPattern: '^(?!.*/\.git$)(?!.*/\.)(?!.*\\.\.)[a-zA-Z0-9-_\.]+$'

Mappature

La Mappings sezione definisce coppie chiave-valore che specificano valori in base a determinate condizioni o dipendenze.

Mappings: Architecture: AmiArchParameter: Graviton: arm64 x86: x86_64 LoginNodeInstances: Graviton: c7g.xlarge x86: c6i.xlarge ComputeNodeInstances: Graviton: c7g.xlarge x86: c6i.xlarge

Resources

La Resources sezione dichiara le AWS risorse da fornire e configurare come parte dello stack.

Resources: [...]

Il modello fornisce l'infrastruttura del cluster di esempio a livelli. Inizia con Networking la configurazione del VPC. L'archiviazione è fornita da due sistemi: EfsStorage per l'archiviazione condivisa e FSxLStorage per l'archiviazione ad alte prestazioni. Il cluster principale viene stabilito tramitePCSCluster.

Networking: Type: AWS::CloudFormation::Stack Properties: Parameters: ProvisionSubnetsC: "False" TemplateURL: !Sub 'https://${HpcRecipesS3Bucket}.s3.amazonaws.com/${HpcRecipesBranch}/recipes/net/hpc_large_scale/assets/main.yaml' EfsStorage: Type: AWS::CloudFormation::Stack Properties: Parameters: SubnetIds: !GetAtt [ Networking, Outputs.DefaultPrivateSubnet ] SubnetCount: 1 VpcId: !GetAtt [ Networking, Outputs.VPC ] TemplateURL: !Sub 'https://${HpcRecipesS3Bucket}.s3.amazonaws.com/${HpcRecipesBranch}/recipes/storage/efs_simple/assets/main.yaml' FSxLStorage: Type: AWS::CloudFormation::Stack Properties: Parameters: PerUnitStorageThroughput: 125 SubnetId: !GetAtt [ Networking, Outputs.DefaultPrivateSubnet ] VpcId: !GetAtt [ Networking, Outputs.VPC ] TemplateURL: !Sub 'https://${HpcRecipesS3Bucket}.s3.amazonaws.com/${HpcRecipesBranch}/recipes/storage/fsx_lustre/assets/persistent.yaml' [...] # Cluster PCSCluster: Type: AWS::PCS::Cluster Properties: Name: !Sub '${AWS::StackName}' Size: SMALL Scheduler: Type: SLURM Version: !Ref SlurmVersion Networking: SubnetIds: - !GetAtt [ Networking, Outputs.DefaultPrivateSubnet ] SecurityGroupIds: - !GetAtt [ PCSSecurityGroup, Outputs.ClusterSecurityGroupId ]

Per le risorse di calcolo, il modello crea due gruppi di nodi: PCSNodeGroupLogin per un singolo nodo di accesso e PCSNodeGroupCompute per un massimo di quattro nodi di calcolo. Questi gruppi di nodi sono supportati da PCSInstanceProfile per le autorizzazioni e per le configurazioni di PCSLaunchTemplate esempio.

# Compute Node groups PCSInstanceProfile: Type: AWS::CloudFormation::Stack Properties: Parameters: # We have to regionalize this in case CX use the template in more than one region. Otherwise, # the create action will fail since instance-role-${AWS::StackName} already exists! RoleName: !Sub '${AWS::StackName}-${AWS::Region}' TemplateURL: !Sub 'https://${HpcRecipesS3Bucket}.s3.amazonaws.com/${HpcRecipesBranch}/recipes/pcs/getting_started/assets/pcs-iip-minimal.yaml' PCSLaunchTemplate: Type: AWS::CloudFormation::Stack Properties: Parameters: VpcDefaultSecurityGroupId: !GetAtt [ Networking, Outputs.SecurityGroup ] ClusterSecurityGroupId: !GetAtt [ PCSSecurityGroup, Outputs.ClusterSecurityGroupId ] SshSecurityGroupId: !GetAtt [ PCSSecurityGroup, Outputs.InboundSshSecurityGroupId ] EfsFilesystemSecurityGroupId: !GetAtt [ EfsStorage, Outputs.SecurityGroupId ] FSxLustreFilesystemSecurityGroupId: !GetAtt [ FSxLStorage, Outputs.FSxLustreSecurityGroupId ] SshKeyName: !Ref KeyName TemplateURL: !Sub 'https://${HpcRecipesS3Bucket}.s3.amazonaws.com/${HpcRecipesBranch}/recipes/pcs/getting_started/assets/cfn-pcs-lt-efs-fsxl.yaml' # Compute Node groups - Login Nodes PCSNodeGroupLogin: Type: AWS::PCS::ComputeNodeGroup Properties: ClusterId: !GetAtt [PCSCluster, Id] Name: login ScalingConfiguration: MinInstanceCount: 1 MaxInstanceCount: 1 IamInstanceProfileArn: !GetAtt [ PCSInstanceProfile, Outputs.InstanceProfileArn ] CustomLaunchTemplate: TemplateId: !GetAtt [ PCSLaunchTemplate, Outputs.LoginLaunchTemplateId ] Version: 1 SubnetIds: - !GetAtt [ Networking, Outputs.DefaultPublicSubnet ] AmiId: !GetAtt [PcsSampleAmi, AmiId] InstanceConfigs: - InstanceType: !FindInMap [ Architecture, LoginNodeInstances, !Ref NodeArchitecture ] # Compute Node groups - Compute Nodes PCSNodeGroupCompute: Type: AWS::PCS::ComputeNodeGroup Properties: ClusterId: !GetAtt [PCSCluster, Id] Name: compute-1 ScalingConfiguration: MinInstanceCount: 0 MaxInstanceCount: 4 IamInstanceProfileArn: !GetAtt [ PCSInstanceProfile, Outputs.InstanceProfileArn ] CustomLaunchTemplate: TemplateId: !GetAtt [ PCSLaunchTemplate, Outputs.ComputeLaunchTemplateId ] Version: 1 SubnetIds: - !GetAtt [ Networking, Outputs.DefaultPrivateSubnet ] AmiId: !GetAtt [PcsSampleAmi, AmiId] InstanceConfigs: - InstanceType: !FindInMap [ Architecture, ComputeNodeInstances, !Ref NodeArchitecture ]

Entrambi i gruppi di nodi includono un NodeLifecycleActions blocco che monta lo storage condiviso e inoltra i log dei nodi ad Amazon CloudWatch Logs in fase iniziale. nodeBootstrapped Questo sostituisce il vecchio approccio di montaggio dei file system tramite i dati utente del modello di avvio. Amazon EFS è montato /home per le home directory degli utenti e FSx for Lustre è montato su per lo storage scratch ad alte prestazioni. /shared Una quarta azione inoltra i log delle azioni del ciclo di vita dei nodi ad Amazon Logs. CloudWatch Le azioni di mount e directory vengono eseguite ad ogni riavvio e mantengono lo storage disponibile, mentre vengono configure-cloudwatch-logs utilizzate FIRST_BOOT_ONLY perché la configurazione CloudWatch dell'agente persiste anche dopo i riavvii e non deve essere riapplicata. EVERY_BOOT Per ulteriori informazioni sulle azioni del ciclo di vita dei nodi, vedere. Azioni relative al ciclo di vita dei nodi Per dettagli sugli script che AWS gestisce, consulta. AWS-script mantenuti

NodeLifecycleActions: ScriptCachingPolicy: CACHE_ONCE Stages: NodeBootstrapped: # Forward node lifecycle action logs to CloudWatch Logs. Runs first so the # actions that follow have their output captured from the node's first boot. - Name: configure-cloudwatch-logs ScriptSource: ScriptLocation: !Sub 's3://aws-pcs-repo-${AWS::Region}/aws-pcs-node-lifecycle-scripts/configure-cloudwatch-logs-v1-latest.sh' OnError: CONTINUE ExecutionPolicy: FIRST_BOOT_ONLY # Mount EFS as the home-directory base at /home and create home dirs on first login. - Name: configure-efs-homes ScriptSource: ScriptLocation: !Sub 's3://aws-pcs-repo-${AWS::Region}/aws-pcs-node-lifecycle-scripts/configure-efs-homes-v1-latest.sh' Arguments: - '--efs-id' - !GetAtt [ EfsStorage, Outputs.EFSFilesystemId ] - '--home-base' - '/home' - '--options' - 'tls' OnError: CONTINUE ExecutionPolicy: EVERY_BOOT # Mount FSx for Lustre at /shared for high-performance shared scratch storage. - Name: mount-fsx-lustre ScriptSource: ScriptLocation: !Sub 's3://aws-pcs-repo-${AWS::Region}/aws-pcs-node-lifecycle-scripts/mount-fsx-lustre-v1-latest.sh' Arguments: - '--fsx-dns-name' - !GetAtt FSxLustreLookup.DNSName - '--mount-name' - !GetAtt FSxLustreLookup.MountName - '--mount-point' - '/shared' OnError: CONTINUE ExecutionPolicy: EVERY_BOOT # Set /shared to world-writable sticky mode (1777). Runs after mount-fsx-lustre # so it applies to the mounted file system, not an empty directory. - Name: set-shared-dir-mode ScriptSource: ScriptLocation: !Sub 'https://${HpcRecipesS3Bucket}.s3.us-east-1.amazonaws.com/${HpcRecipesBranch}/recipes/pcs-scripts/open_shared_dir/assets/set-shared-dir-mode-v1.0.0.sh' Arguments: - '--path' - '/shared' - '--mode' - '1777' OnError: CONTINUE ExecutionPolicy: EVERY_BOOT

La pianificazione dei lavori viene gestita tramite. PCSQueueCompute

PCSQueueCompute: Type: AWS::PCS::Queue Properties: ClusterId: !GetAtt [PCSCluster, Id] Name: demo ComputeNodeGroupConfigurations: - ComputeNodeGroupId: !GetAtt [PCSNodeGroupCompute, Id]

La selezione dell'AMI avviene automaticamente tramite la funzione PcsAMILookupFn Lambda e le risorse correlate.

PcsAMILookupRole: Type: AWS::IAM::Role [...] PcsAMILookupFn: Type: AWS::Lambda::Function Properties: Runtime: python3.12 Handler: index.handler Role: !GetAtt PcsAMILookupRole.Arn Code: [...] Timeout: 30 MemorySize: 128 # Example of using the custom resource to look up an AMI PcsSampleAmi: Type: Custom::AMILookup Properties: ServiceToken: !GetAtt PcsAMILookupFn.Arn OperatingSystem: 'amzn2' Architecture: !FindInMap [ Architecture, AmiArchParameter, !Ref NodeArchitecture ] SlurmVersion: !Ref SlurmVersion

Output

Il modello genera gli URL di identificazione e gestione del cluster tramiteClusterId,, PcsConsoleUrl e. Ec2ConsoleUrl

Outputs: ClusterId: Description: The Id of the PCS cluster Value: !GetAtt [ PCSCluster, Id ] PcsConsoleUrl: Description: URL to access the cluster in the PCS console Value: !Sub - https://${ConsoleDomain}/pcs/home?region=${AWS::Region}#/clusters/${ClusterId} - { ConsoleDomain: !If [ GovCloud, 'console.amazonaws-us-gov.com', !If [ China, 'console.amazonaws.cn', !Sub '${AWS::Region}.console.aws.amazon.com']], ClusterId: !GetAtt [ PCSCluster, Id ] } Export: Name: !Sub ${AWS::StackName}-PcsConsoleUrl Ec2ConsoleUrl: Description: URL to access instance(s) in the login node group via Session Manager Value: !Sub - https://${ConsoleDomain}/ec2/home?region=${AWS::Region}#Instances:instanceState=running;tag:aws:pcs:compute-node-group-id=${NodeGroupLoginId} - { ConsoleDomain: !If [ GovCloud, 'console.amazonaws-us-gov.com', !If [ China, 'console.amazonaws.cn', !Sub '${AWS::Region}.console.aws.amazon.com']], NodeGroupLoginId: !GetAtt [ PCSNodeGroupLogin, Id ] } Export: Name: !Sub ${AWS::StackName}-Ec2ConsoleUrl