无法遍历terraform.tfvars中变量,创建AWS安全组入站规则报错
解决Terraform安全组入站规则配置错误问题
问题背景
在terraform.tfvars中声明的变量如下:
sg_rules = { nlb_rules = { "ir_web_subnet" = { "cidr_ipv4" :"170.20.5.0/24", "from_port" = "9003", "ip_protocol" = "tcp", "to_port" = "9003", "description" = "Web Subnet AU-SY" } "ir_app_subnet" = { "cidr_ipv4" :"170.20.10.0/24", "from_port" = "9004", "ip_protocol" = "tcp", "to_port" = "9003", "description" = "App Subnet AU-SY" } } alb_rules = { "ir_http" = { "cidr_ipv4" :"0.0.0.0/0", "from_port" = "80", "ip_protocol" = "tcp", "to_port" = "80", "description" = "HTTP Traffic" } "ir_https" = { "cidr_ipv4" :"0.0.0.0/0", "from_port" = "443", "ip_protocol" = "tcp", "to_port" = "443", "description" = "HTTPS Traffic" } } }
尝试创建安全组入站规则的Terraform配置如下:
resource "aws_security_group" "nlb" { name = "allow-access-to-nlb" description = "Security group for network load balancer" vpc_id = var.vpc_id tags = { Name = "allow-access-to-nlb" } } resource "aws_security_group" "alb" { name = "allow-access-to-nlb" description = "Security group for application load balancer" vpc_id = var.vpc_id tags = { Name = "allow-access-to-alb" } } resource "aws_vpc_security_group_ingress_rule" "nlb-rules" { for_each = var.sg_rules security_group_id = aws_security_group.nlb.id cidr_ipv4 = each.value.nlb_rules["cidr_ipv4"] from_port = each.value.nlb_rules["from_port"] ip_protocol = each.value.nlb_rules["ip_protocol"] to_port = each.value.nlb_rules["to_port"] description = each.value.nlb_rules["description"] } resource "aws_vpc_security_group_ingress_rule" "alb-rules" { for_each = var.sg_rules security_group_id = aws_security_group.alb.id cidr_ipv4 = each.value.alb_rules["cidr_ipv4"] from_port = each.value.alb_rules["from_port"] ip_protocol = each.value.alb_rules["ip_protocol"] to_port = each.value.alb_rules["to_port"] description = each.value.alb_rules["description"] }
执行时出现错误:
each.value is object with 28 attributes. This object does not have an attribute named "alb_rules".
错误原因
错误出在for_each的取值逻辑上:
var.sg_rules是包含nlb_rules和alb_rules两个顶级键的对象,当用for_each = var.sg_rules遍历时,each.value对应的是nlb_rules或alb_rules各自的规则集合(比如第一个迭代的each.value是ir_web_subnet和ir_app_subnet组成的对象),而非包含nlb_rules/alb_rules的父对象。因此在迭代中访问each.value.nlb_rules或each.value.alb_rules时,Terraform会提示找不到对应属性。
修正后的配置
需要针对每个规则集合单独遍历,同时修正ALB安全组名称的笔误(原配置中ALB安全组name与NLB重复):
resource "aws_security_group" "nlb" { name = "allow-access-to-nlb" description = "Security group for network load balancer" vpc_id = var.vpc_id tags = { Name = "allow-access-to-nlb" } } resource "aws_security_group" "alb" { name = "allow-access-to-alb" # 修正名称笔误 description = "Security group for application load balancer" vpc_id = var.vpc_id tags = { Name = "allow-access-to-alb" } } resource "aws_vpc_security_group_ingress_rule" "nlb-rules" { for_each = var.sg_rules.nlb_rules # 直接遍历NLB规则集合 security_group_id = aws_security_group.nlb.id cidr_ipv4 = each.value.cidr_ipv4 from_port = each.value.from_port ip_protocol = each.value.ip_protocol to_port = each.value.to_port description = each.value.description } resource "aws_vpc_security_group_ingress_rule" "alb-rules" { for_each = var.sg_rules.alb_rules # 直接遍历ALB规则集合 security_group_id = aws_security_group.alb.id cidr_ipv4 = each.value.cidr_ipv4 from_port = each.value.from_port ip_protocol = each.value.ip_protocol to_port = each.value.to_port description = each.value.description }
说明
修正后:
aws_vpc_security_group_ingress_rule.nlb-rules会遍历var.sg_rules.nlb_rules下的每一条规则,生成对应的入站规则aws_vpc_security_group_ingress_rule.alb-rules会遍历var.sg_rules.alb_rules下的每一条规则,生成对应的入站规则- 每个
each.value直接对应单条规则的对象,可以直接访问其中的属性
内容的提问来源于stack exchange,提问作者Prashast
相关产品推荐
相关产品推荐

