You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Terraform在变量为null时跳过virtual_network_subnet_id?

Terraform空值索引报错解决

问题场景

需求是:当传入subnet变量时,从azurerm_subnet数据块中获取对应ID赋值给virtual_network_subnet_id;当subnet变量为null时,给该参数传递null值。但实际运行时,subnet变量为null时,Terraform仍尝试执行索引操作,触发报错。

原配置代码

resource "azurerm_windows_web_app" "web-app" {
  for_each                  = var.web_app
  name                      = each.key
  resource_group_name       = data.azurerm_resource_group.rg2.name
  location                  = data.azurerm_resource_group.rg2.location
  tags                      = merge(local.base_tags, { Component = each.value.component_tag })
  service_plan_id           = azurerm_service_plan.asp[each.value.asp].id
  virtual_network_subnet_id = each.value.subnet != "" ? data.azurerm_subnet.vnet-subnets[each.value.subnet].id : null


  site_config {
    ftps_state             = "FtpsOnly"
    minimum_tls_version    = 1.2
    vnet_route_all_enabled = each.value.subnet != "" ? true : false
    worker_count           = each.value.worker_count
    always_on              = each.value.always_on
    use_32_bit_worker      = each.value.use_32_bit_worker

    application_stack {
      dotnet_version = each.value.dotnet_version
    }

    ip_restriction_default_action = "Deny"

    dynamic "ip_restriction" {
      for_each = local.vpn
      content {
        ip_address = ip_restriction.value["ip_address"]
        action     = "Allow"
        priority   = ip_restriction.value["priority"]
        name       = ip_restriction.value["name"]
      }
    }
    dynamic "ip_restriction" {
      for_each = local.azure_service_tag
      content {
        name        = ip_restriction.value["name"]
        service_tag = ip_restriction.value["service_tag"]
        priority    = ip_restriction.value["priority"]
      }
    }
    #Subnets
    dynamic "ip_restriction" {
        for_each = local.subnets
        content {
          name = ip_restriction.value["subnet_name"]
          virtual_network_subnet_id = data.azurerm_virtual_network.vnet.id
          priority = ip_restriction.value["priority"]
        }
      
    }
  }

  identity {
    type = "SystemAssigned"
  }

  lifecycle {
    ignore_changes = [
      identity,
      app_settings,
      connection_string,
      https_only,
      site_config
    ]
  }

}

错误信息

│ Error: Invalid index
│
│   on web_app.tf line 12, in resource "azurerm_windows_web_app" "web-app":
│   12:   virtual_network_subnet_id = each.value.subnet != "" ? data.azurerm_subnet.vnet-subnets[each.value.subnet].id : null
│     ├────────────────
│     │ data.azurerm_subnet.vnet-subnets is object with 9 attributes
│     │ each.value.subnet is null
│
│ Can't use a null value as an indexing key.

问题原因

原条件判断each.value.subnet != ""只处理了空字符串的情况,但当each.value.subnet为null时,null != ""的结果是true,Terraform会执行冒号左侧的索引操作,而null不能作为索引键,因此触发报错。

解决方案

修改条件判断,同时覆盖null和空字符串的情况,确保只有当subnet变量不为null且不为空字符串时,才执行索引操作:

修改后的关键代码行

virtual_network_subnet_id = each.value.subnet != null && each.value.subnet != "" ? data.azurerm_subnet.vnet-subnets[each.value.subnet].id : null
vnet_route_all_enabled    = each.value.subnet != null && each.value.subnet != "" ? true : false

更简洁的写法(利用Terraform真值特性)

在Terraform中,null、空字符串、false都会被视为假值,因此可以直接用each.value.subnet作为判断条件:

virtual_network_subnet_id = each.value.subnet ? data.azurerm_subnet.vnet-subnets[each.value.subnet].id : null
vnet_route_all_enabled    = each.value.subnet ? true : false

这样修改后,当subnet变量为null或空字符串时,都会返回null给virtual_network_subnet_id,同时vnet_route_all_enabled设为false,符合需求。

内容的提问来源于stack exchange,提问作者NickP

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 04:18:23