You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法遍历terraform.tfvars中变量,创建AWS安全组入站规则报错

解决Terraform安全组入站规则配置错误问题

问题背景

在terraform.tfvars中声明的变量如下:

sg_rules = {
  nlb_rules = {
    "ir_web_subnet" = { "cidr_ipv4" :"170.20.5.0/24", "from_port" = "9003", "ip_protocol" = "tcp", "to_port" = "9003", "description" = "Web Subnet AU-SY" }
    "ir_app_subnet" = { "cidr_ipv4" :"170.20.10.0/24", "from_port" = "9004", "ip_protocol" = "tcp", "to_port" = "9003", "description" = "App Subnet AU-SY" }
  }
  alb_rules = {
    "ir_http" = { "cidr_ipv4" :"0.0.0.0/0", "from_port" = "80", "ip_protocol" = "tcp", "to_port" = "80", "description" = "HTTP Traffic" }
    "ir_https" = { "cidr_ipv4" :"0.0.0.0/0", "from_port" = "443", "ip_protocol" = "tcp", "to_port" = "443", "description" = "HTTPS Traffic" }
  }
}

尝试创建安全组入站规则的Terraform配置如下:

resource "aws_security_group" "nlb" {
  name        = "allow-access-to-nlb"
  description = "Security group for network load balancer"
  vpc_id      = var.vpc_id
  tags = {
    Name = "allow-access-to-nlb"
  }
}

resource "aws_security_group" "alb" {
  name        = "allow-access-to-nlb"
  description = "Security group for application load balancer"
  vpc_id      = var.vpc_id
  tags = {
    Name = "allow-access-to-alb"
  }
}
    
resource "aws_vpc_security_group_ingress_rule" "nlb-rules" {
  for_each          = var.sg_rules
  security_group_id = aws_security_group.nlb.id
  cidr_ipv4         = each.value.nlb_rules["cidr_ipv4"]
  from_port         = each.value.nlb_rules["from_port"]
  ip_protocol       = each.value.nlb_rules["ip_protocol"]
  to_port           = each.value.nlb_rules["to_port"]
  description       = each.value.nlb_rules["description"]
}
    
resource "aws_vpc_security_group_ingress_rule" "alb-rules" {
  for_each          = var.sg_rules
  security_group_id = aws_security_group.alb.id
  cidr_ipv4         = each.value.alb_rules["cidr_ipv4"]
  from_port         = each.value.alb_rules["from_port"]
  ip_protocol       = each.value.alb_rules["ip_protocol"]
  to_port           = each.value.alb_rules["to_port"]
  description       = each.value.alb_rules["description"]
}

执行时出现错误:

each.value is object with 28 attributes. This object does not have an attribute named "alb_rules".

错误原因

错误出在for_each的取值逻辑上:

  • var.sg_rules是包含nlb_rules和alb_rules两个顶级键的对象,当用for_each = var.sg_rules遍历时,each.value对应的是nlb_rules或alb_rules各自的规则集合(比如第一个迭代的each.value是ir_web_subnet和ir_app_subnet组成的对象),而非包含nlb_rules/alb_rules的父对象。因此在迭代中访问each.value.nlb_rules或each.value.alb_rules时,Terraform会提示找不到对应属性。

修正后的配置

需要针对每个规则集合单独遍历,同时修正ALB安全组名称的笔误(原配置中ALB安全组name与NLB重复):

resource "aws_security_group" "nlb" {
  name        = "allow-access-to-nlb"
  description = "Security group for network load balancer"
  vpc_id      = var.vpc_id
  tags = {
    Name = "allow-access-to-nlb"
  }
}

resource "aws_security_group" "alb" {
  name        = "allow-access-to-alb"  # 修正名称笔误
  description = "Security group for application load balancer"
  vpc_id      = var.vpc_id
  tags = {
    Name = "allow-access-to-alb"
  }
}
    
resource "aws_vpc_security_group_ingress_rule" "nlb-rules" {
  for_each          = var.sg_rules.nlb_rules  # 直接遍历NLB规则集合
  security_group_id = aws_security_group.nlb.id
  cidr_ipv4         = each.value.cidr_ipv4
  from_port         = each.value.from_port
  ip_protocol       = each.value.ip_protocol
  to_port           = each.value.to_port
  description       = each.value.description
}
    
resource "aws_vpc_security_group_ingress_rule" "alb-rules" {
  for_each          = var.sg_rules.alb_rules  # 直接遍历ALB规则集合
  security_group_id = aws_security_group.alb.id
  cidr_ipv4         = each.value.cidr_ipv4
  from_port         = each.value.from_port
  ip_protocol       = each.value.ip_protocol
  to_port           = each.value.to_port
  description       = each.value.description
}

说明

修正后:

  • aws_vpc_security_group_ingress_rule.nlb-rules会遍历var.sg_rules.nlb_rules下的每一条规则,生成对应的入站规则
  • aws_vpc_security_group_ingress_rule.alb-rules会遍历var.sg_rules.alb_rules下的每一条规则,生成对应的入站规则
  • 每个each.value直接对应单条规则的对象,可以直接访问其中的属性

内容的提问来源于stack exchange,提问作者Prashast

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 04:19:51