You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform创建Cisco DNA Center IP子池报错排查求助

Cisco DNA Center Terraform创建IP子池报错排查

场景与代码结构

我正在编写Terraform脚本,用于在Cisco DNA/Catalyst Center中创建站点层级的IP子池,目录结构如下:

├── main.tf
├── variables.tf
├── modules 
│ └── site_settings 
│   └── ip-pools.tf 
│   └── variables.tf
├── Site-1
│ └── site-1.tfvars

各文件代码如下:

./main.tf

provider "dnacenter" {
    base_url = var.dnac_url
    debug = "true"
    ssl_verify = "false"
}

module "site_settings" {
  source = "../modules/site_settings"
  ip_pools = var.ip_pools
}

./modules/site_settings/ip-pools.tf

resource "dnacenter_reserve_ip_subpool" "pool" {
  for_each = { for pool in var.ip_pools : pool.name => pool }
  provider = dnacenter
  parameters {
    ipv4_dhcp_servers  = "${each.value.dhcp_server_ips}"
    ipv4_dns_servers   = "${each.value.dns_server_ips}"
    ipv4_gate_way      = "${each.value.ipv4_gate_way}"
    ipv4_global_pool   = "${each.value.ipv4_global_pool}"
    ipv4_prefix        = "true"
    ipv4_prefix_length = "${each.value.ipv4_prefix_length}"
    ipv4_subnet        = "${each.value.subnet_id}"
    ipv6_address_space = "false"
    name               = "${each.value.name}"
    site_id            = dnacenter_area.site.item.0.id
    type               = each.value.type
  }
}

./Site-1/site-1.tfvars

ip_pools = [{
subnet_id = "10.0.4.0"
ipv4_prefix_length = "24"
name = "Site-1-USER"
reso_code = "Site-1"
ipv4_gate_way = "10.0.4.1"
type = "General"
dns_server_ips = ["10.10.1.30" , "10.10.1.31"]
dhcp_server_ips = ["10.10.10.112" , "10.10.10.116" , "10.10.11.112" , "10.10.11.116"]
ipv4_global_pool = "10.0.0.0/16" 
}]

./variables.tf

variable "dnac_username" {
    sensitive = true
}
variable "dnac_password" {
    sensitive = true
}
variable "dnac_url" {
  type = string
}
variable "ip_pools" {
  type = list(object({
    name = string
    subnet_id = string
    type = string
    dhcp_server_ips = list(string)
    dns_server_ips = list(string)
    ipv4_gate_way = string
    ipv4_global_pool = string
    ipv4_prefix_length = string
    }))
}

./modules/site_settings/variables.tf

variable "ip_pools" {}

报错情况

执行terraform plan时结果正常,显示将创建对应的IP子池资源,但执行terraform apply时出现模糊报错:

Error: Failure when executing ReserveIPSubpool
│ 
│   with module.site_settings.dnacenter_reserve_ip_subpool.pool["Site-1-USER"],
│   on modules/site_settings/ip-pools.tf line 16, in resource "dnacenter_reserve_ip_subpool" "pool":
│   16: resource "dnacenter_reserve_ip_subpool" "pool" {
│ 

可能的问题

  • Site ID 未正确关联:代码中引用的dnacenter_area.site.item.0.id对应的dnacenter_area资源未定义,导致站点ID为空,DNA Center API拒绝创建子池(子池必须绑定已存在的站点)。
  • 参数格式错误:ipv4_dhcp_servers和ipv4_dns_servers被转成了字符串(通过"${each.value.dhcp_server_ips}"),但API实际需要数组格式,格式不匹配导致调用失败。
  • 全局IP池不存在:ipv4_global_pool指定的10.0.0.0/16未在DNA Center中预先创建,无法关联子池。
  • 变量类型不匹配:模块内的ip_pools变量未定义类型,可能导致参数传递时类型异常(比如ipv4_prefix_length是字符串,但API要求整数)。
  • 版本或权限问题:dnacenter provider版本与DNA Center API版本不兼容,或者操作账号没有创建IP子池的权限。

调试与解决方法

  1. 开启详细日志:设置环境变量TF_LOG=DEBUG后执行terraform apply,可以获取包含API请求/响应的完整日志,从DNA Center的返回信息中定位具体错误。
  2. 验证Site ID有效性:先确认dnacenter_area资源是否已正确创建,或者手动在DNA Center控制台获取目标站点ID,硬编码到site_id字段测试是否能成功创建。
  3. 修正参数格式:去掉列表参数的字符串插值,直接传递列表变量:
    ipv4_dhcp_servers = each.value.dhcp_server_ips
    ipv4_dns_servers = each.value.dns_server_ips
    
  4. 完善模块变量定义:给模块内的ip_pools变量添加与根模块一致的类型约束,避免类型不匹配:
    variable "ip_pools" {
      type = list(object({
        name = string
        subnet_id = string
        type = string
        dhcp_server_ips = list(string)
        dns_server_ips = list(string)
        ipv4_gate_way = string
        ipv4_global_pool = string
        ipv4_prefix_length = string
      }))
    }
    
  5. 验证全局池状态:登录DNA Center控制台,确认10.0.0.0/16全局IP池已创建且状态正常。
  6. 直接测试API:用Postman或curl直接调用DNA Center的ReserveIPSubpool API,传入相同参数,查看返回的具体错误信息,快速定位问题。

内容的提问来源于stack exchange,提问作者MupEHcEH

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 00:12:22