Terraform配置AWS WAFv2规则报错:缺失键值分隔符
Terraform WAFv2规则「Missing key/value separator」错误排查提示
针对第14行的核心排查点
- 先查键值对分隔符:这个错误本质是Terraform没找到
=区分属性名和值,直接看第14行:- 是不是漏写了
=?比如把type = "HEADER"写成type "HEADER" - 字符串引号有没有配对?比如只开了单引号没闭合,导致Terraform认错结构
- 是不是漏写了
- 别直接照搬控制台JSON:AWS控制台导出的JSON和Terraform语法逻辑完全不同,不能直接复制粘贴。比如JSON里的
"FieldToMatch": {"Type": "HEADER", "Data": "Content-Type"},转成Terraform得写成:
尤其注意别把JSON的冒号field_to_match { type = "HEADER" data = "Content-Type" }:当成Terraform的等号=用,这是高频踩坑点 - 检查嵌套块格式:如果第14行在
statement或condition这类嵌套块里,得确认:- 大括号
{}有没有配对,别漏了结尾的} - 缩进要统一,别混合空格和制表符,Terraform对格式敏感度很高
- 大括号
- 核对规则逻辑写法:要拦截未携带
Content-Type: application/json的POST请求,逻辑得拆成两步:先匹配POST方法,再匹配不符合Content-Type要求的请求,参考示例片段:statement { and_statement { statements { byte_match_statement { field_to_match { type = "METHOD" } positional_constraint = "EXACTLY" search_string = "POST" text_transformation { priority = 0 type = "NONE" } } } statements { not_statement { statement { byte_match_statement { field_to_match { type = "HEADER" data = "Content-Type" } positional_constraint = "CONTAINS" search_string = "application/json" text_transformation { priority = 0 type = "NONE" } } } } } } } - 利用VS Code提示:把鼠标悬停在第14行的红色波浪线上,插件会给出具体错误原因,比如“missing = after attribute name”,直接跟着提示修改即可
内容的提问来源于stack exchange,提问作者Satish Lokhande
相关产品推荐
相关产品推荐

