You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨账号TGW路由传播至本地VPC:Terraform配置报错排查

问题描述

我有多个工作负载账号,新增工作负载时通过Terraform执行以下操作:将工作负载连接至TGW、接受TGW连接请求、修改路由表(添加工作负载指向检测VPC的默认静态路由)、关联tgw-attach到路由表。但在尝试将路由传播至检测VPC时触发InvalidTransitGatewayAttachmentID.Malformed错误。当前TGW检测路由表已完成入口和出口VPC的路由传播,现需新增工作负载环境至检测VPC传播表,使用Terraform v1.8.0执行时出错,相关信息如下:

Terraform版本信息

terraform --version
Terraform v1.8.0
on darwin_amd64

本地配置文件

locals {
  pending_acceptance_requests = {
    "tgw-attach-0xxxxxxxxxxxxxxx" = "dev-test"
    # Add more pending acceptance requests as needed
  }
}

路由传播代码

resource "aws_ec2_transit_gateway_route_table_propagation" "propagate_routes" {
  for_each = local.pending_acceptance_requests

  transit_gateway_route_table_id = aws_ec2_transit_gateway_route_table.workload_route_table[each.key].id
  transit_gateway_attachment_id = aws_ec2_transit_gateway_route_table.tg_inspection_route_table.id
}

Terraform执行计划

Terraform will perform the following actions:

  # aws_ec2_transit_gateway_route_table_propagation.propagate_routes["tgw-attach-0xxxxxxxxxxxxx6"] will be created
  + resource "aws_ec2_transit_gateway_route_table_propagation" "propagate_routes" {
      + id                             = (known after apply)
      + resource_id                    = (known after apply)
      + resource_type                  = (known after apply)
      + transit_gateway_attachment_id  = "tgw-rtb-0xxxxxxxxxxxxa9"
      + transit_gateway_route_table_id = "tgw-rtb-0xxxxxxxxxxxxbe55"
    }

报错信息

│ Error: creating EC2 Transit Gateway Route Table Propagation (tgw-rtb-0daxxxxxxxxxxxxxx55_tgw-rtb-06b9xxxxxxxxxxxxa9): InvalidTransitGatewayAttachmentID.Malformed: Invalid Transit Gateway Attachment id tgw-rtb-0******a9.
│   status code: 400, request id: 6526181d-f7c8-4fb2-804e-9888888888
│
│   with aws_ec2_transit_gateway_route_table_propagation.propagate_routes["tgw-attach-0******96"],
│   on workload-tg.tf line 43, in resource "aws_ec2_transit_gateway_route_table_propagation" "propagate_routes":
│   43: resource "aws_ec2_transit_gateway_route_table_propagation" "propagate_routes" {
│

问题原因及修复方案

  • 错误原因:aws_ec2_transit_gateway_route_table_propagation资源中,transit_gateway_attachment_id参数被错误赋值为路由表ID(格式tgw-rtb-xxxx),但该参数要求传入的是TGW附件ID(格式tgw-attach-xxxx)。
  • 修复代码:调整参数对应关系,让transit_gateway_route_table_id指向检测VPC的路由表,transit_gateway_attachment_id使用本地变量中的工作负载TGW附件ID:
resource "aws_ec2_transit_gateway_route_table_propagation" "propagate_routes" {
  for_each = local.pending_acceptance_requests

  # 目标路由表:检测VPC的TGW路由表
  transit_gateway_route_table_id = aws_ec2_transit_gateway_route_table.tg_inspection_route_table.id
  # 路由来源:当前工作负载的TGW附件ID
  transit_gateway_attachment_id = each.key
}
  • 逻辑说明:路由传播的核心是让指定的TGW附件(工作负载VPC与TGW的连接)将自身路由条目传播到目标路由表(检测VPC的TGW路由表),因此必须正确匹配两个参数的含义。

内容的提问来源于stack exchange,提问作者Jaimin Patel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 09:34:59