Terraform动态创建AWS EFS访问点参数传递错误,求正确配置
解决Terraform动态创建AWS EFS访问点的配置错误
问题根源
你的access_points变量传递结构完全错误。模块中for_each = { for k, v in var.access_points : k => v if var.create }是遍历每个独立的访问点定义,但你现在把单个访问点的posix_user、root_directory拆成了map的独立键,导致Terraform把每个键值对当成一个独立访问点创建,且每个访问点配置不完整,最终生成仅含默认根路径的空访问点。
修正方案
1. 规范变量类型(可选但推荐)
将variable "access_points"的类型从any改为明确的对象结构,提前规避结构错误:
修改module/variable.tf:
variable "access_points" { description = "A map of access point definitions to create" type = map(object({ posix_user = optional(object({ gid = number uid = number secondary_gids = optional(list(number)) })) root_directory = optional(object({ path = optional(string) creation_info = optional(object({ owner_gid = number owner_uid = number permissions = string })) })) tags = optional(map(string)) })) }
2. 修正根模块参数传递
把access_points调整为每个键对应一个完整访问点配置的结构,先实现单个访问点创建:
修改root main.tf:
module "EFS-ap" { source = "../modules/xxx/xxx/accessPoints" aws_efs_file_system_id = "fs-0bcf0c0xxxx" access_points = { # 键"git_repo_ap"作为访问点的标识名称 git_repo_ap = { posix_user = { gid = 1001 uid = 1001 } root_directory = { path = "/hengg/git" creation_info = { owner_gid = 1001 owner_uid = 1001 permissions = "0775" # 必须用字符串包裹,避免八进制解析错误 } } } } }
3. 扩展多访问点(后续需求)
如果要创建多个访问点,只需在access_points map中添加更多键值对:
access_points = { git_repo_ap = { # 第一个访问点配置 posix_user = { gid = 1001 uid = 1001 } root_directory = { path = "/hengg/git" creation_info = { owner_gid = 1001 owner_uid = 1001 permissions = "0775" } } }, logs_ap = { # 第二个访问点配置 posix_user = { gid = 1002 uid = 1002 } root_directory = { path = "/hengg/logs" creation_info = { owner_gid = 1002 owner_uid = 1002 permissions = "0750" } } } }
额外注意事项
- 权限值必须用字符串包裹(如
"0775"),否则Terraform会把八进制数解析为十进制,导致权限配置错误。 - 若需要标签功能,恢复模块中tags配置并修正变量类型:
在module/variable.tf中修正tags变量:
取消variable "tags" { description = "Base tags for all access points" type = map(string) default = {} }module/main.tf中tags的注释:tags = merge( var.tags, try(each.value.tags, {}), { Name = try(each.value.name, each.key) }, )
内容的提问来源于stack exchange,提问作者striker
相关产品推荐
相关产品推荐

