You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

省略对象键导致Terraform后续执行计划始终返回变更求助

Terraform FusionAuth应用每次apply都试图清空自动生成的id_token_key_id

问题重现

Terraform配置如下:

resource "fusionauth_application" "test" {
  tenant_id = fusionauth_tenant.test_frontend.id
  application_id = var.fusionauth_test_application_id
  name      = var.fusionauth_test_application_name

  jwt_configuration {
    enabled = true
    access_token_id = fusionauth_key.test-rsa-access-token.key_id
  }
}

首次执行terraform apply时资源创建正常,但由于未指定ID Token密钥,FusionAuth系统自动为JWT配置生成了新的ID密钥。后续每次执行terraform apply,执行计划都会试图将jwt_configuration.id_token_key_id设为null:

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  ~ update in-place

Terraform will perform the following actions:

  # fusionauth_application.formedia will be updated in-place
  ~ resource "fusionauth_application" "test" {
        id                                         = <some-id>
        name                                       = "Test"
        # (16 unchanged attributes hidden)

      ~ jwt_configuration {
          - id_token_key_id           = <some-key> -> null # always shows up
            # (4 unchanged attributes hidden)
        }

        # (4 unchanged blocks hidden)
    }

问题原因

这是FusionAuth Terraform Provider的已知问题:当配置中未显式设置id_token_key_id时,Provider在读取资源状态时,无法正确识别系统自动生成的密钥ID,反而会将该字段视为需要被重置为null。

解决方案

方案1:显式指定ID Token密钥

创建专门的ID Token密钥资源,并在应用配置中显式引用它:

resource "fusionauth_key" "test-rsa-id-token" {
  algorithm = "RS256"
  name      = "Test ID Token RSA Key"
}

resource "fusionauth_application" "test" {
  tenant_id = fusionauth_tenant.test_frontend.id
  application_id = var.fusionauth_test_application_id
  name      = var.fusionauth_test_application_name

  jwt_configuration {
    enabled = true
    access_token_id = fusionauth_key.test-rsa-access-token.key_id
    id_token_key_id = fusionauth_key.test-rsa-id-token.key_id
  }
}

这种方式能让Terraform完全管理密钥生命周期,避免状态不一致。

方案2:忽略该字段的变更

如果不想显式指定密钥,可通过lifecycle块的ignore_changes参数让Terraform忽略id_token_key_id的状态差异:

resource "fusionauth_application" "test" {
  tenant_id = fusionauth_tenant.test_frontend.id
  application_id = var.fusionauth_test_application_id
  name      = var.fusionauth_test_application_name

  jwt_configuration {
    enabled = true
    access_token_id = fusionauth_key.test-rsa-access-token.key_id
  }

  lifecycle {
    ignore_changes = [
      jwt_configuration[0].id_token_key_id
    ]
  }
}

该配置会告诉Terraform不要将自动生成的id_token_key_id纳入变更检测,从而消除每次apply的无效更新计划。

内容的提问来源于stack exchange,提问作者Maksym

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 04:50:09