省略对象键导致Terraform后续执行计划始终返回变更求助
Terraform FusionAuth应用每次apply都试图清空自动生成的id_token_key_id
问题重现
Terraform配置如下:
resource "fusionauth_application" "test" { tenant_id = fusionauth_tenant.test_frontend.id application_id = var.fusionauth_test_application_id name = var.fusionauth_test_application_name jwt_configuration { enabled = true access_token_id = fusionauth_key.test-rsa-access-token.key_id } }
首次执行terraform apply时资源创建正常,但由于未指定ID Token密钥,FusionAuth系统自动为JWT配置生成了新的ID密钥。后续每次执行terraform apply,执行计划都会试图将jwt_configuration.id_token_key_id设为null:
Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols: ~ update in-place Terraform will perform the following actions: # fusionauth_application.formedia will be updated in-place ~ resource "fusionauth_application" "test" { id = <some-id> name = "Test" # (16 unchanged attributes hidden) ~ jwt_configuration { - id_token_key_id = <some-key> -> null # always shows up # (4 unchanged attributes hidden) } # (4 unchanged blocks hidden) }
问题原因
这是FusionAuth Terraform Provider的已知问题:当配置中未显式设置id_token_key_id时,Provider在读取资源状态时,无法正确识别系统自动生成的密钥ID,反而会将该字段视为需要被重置为null。
解决方案
方案1:显式指定ID Token密钥
创建专门的ID Token密钥资源,并在应用配置中显式引用它:
resource "fusionauth_key" "test-rsa-id-token" { algorithm = "RS256" name = "Test ID Token RSA Key" } resource "fusionauth_application" "test" { tenant_id = fusionauth_tenant.test_frontend.id application_id = var.fusionauth_test_application_id name = var.fusionauth_test_application_name jwt_configuration { enabled = true access_token_id = fusionauth_key.test-rsa-access-token.key_id id_token_key_id = fusionauth_key.test-rsa-id-token.key_id } }
这种方式能让Terraform完全管理密钥生命周期,避免状态不一致。
方案2:忽略该字段的变更
如果不想显式指定密钥,可通过lifecycle块的ignore_changes参数让Terraform忽略id_token_key_id的状态差异:
resource "fusionauth_application" "test" { tenant_id = fusionauth_tenant.test_frontend.id application_id = var.fusionauth_test_application_id name = var.fusionauth_test_application_name jwt_configuration { enabled = true access_token_id = fusionauth_key.test-rsa-access-token.key_id } lifecycle { ignore_changes = [ jwt_configuration[0].id_token_key_id ] } }
该配置会告诉Terraform不要将自动生成的id_token_key_id纳入变更检测,从而消除每次apply的无效更新计划。
内容的提问来源于stack exchange,提问作者Maksym
相关产品推荐
相关产品推荐

