You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置AWS Cognito User Pool时password_policy参数报错求助

解决Terraform配置AWS Cognito User Pool时的password_policy错误

我用Terraform配置AWS Cognito用户池的代码如下:

provider "aws" {
  region = "us-east-1" # 指定你需要的区域
}

resource "aws_cognito_user_pool" "main_user_pool" {
  name = "main_user_pool"

  account_recovery_setting {
    recovery_mechanism {
      name     = "verified_email"
      priority = 1
    }

    recovery_mechanism {
      name     = "verified_phone_number"
      priority = 2
    }
  }

  # 定义用户池属性
  schema {
    name                = "email"
    attribute_data_type = "String"
    mutable             = true
    required            = true
  }

  password_policy = {
    minimum_length    = 6
    require_lowercase = true
    require_numbers   = true
    require_symbols   = true
    require_uppercase = true
  }

  email_configuration {
    email_sending_account = "COGNITO_DEFAULT"
  }

  auto_verified_attributes = ["email"]

  username_attributes = ["email"]
  username_configuration {
    case_sensitive = true
  }

  schema {
    name                = "password"
    attribute_data_type = "String"
    mutable             = true
    required            = true
  }
}

运行terraform plan时出现错误:

Error: Unsupported argument
│ 
│   on cognitoPool.tf line 29, in resource "aws_cognito_user_pool" "main_user_pool":
│   29:   password_policy = {
│ 
│ An argument named "password_policy" is not expected here. Did you mean to define a block of type "password_policy"?

问题原因

你用了参数赋值的写法(password_policy = { ... }),但在Terraform AWS Provider v5.x版本中,password_policy是嵌套块,不是顶层属性参数,不能用=赋值。

另外还有两个小问题:

  • Cognito的密码是系统内置字段,不需要手动在schema块中定义,这个多余的配置可以删掉
  • 你查看的文档逻辑是对的,但要注意v5.x版本的password_policy采用块语法,而非属性语法

修正后的代码

provider "aws" {
  region = "us-east-1" # 指定你需要的区域
}

resource "aws_cognito_user_pool" "main_user_pool" {
  name = "main_user_pool"

  account_recovery_setting {
    recovery_mechanism {
      name     = "verified_email"
      priority = 1
    }

    recovery_mechanism {
      name     = "verified_phone_number"
      priority = 2
    }
  }

  # 定义用户池属性
  schema {
    name                = "email"
    attribute_data_type = "String"
    mutable             = true
    required            = true
  }

  # 修正为嵌套块写法,去掉=号
  password_policy {
    minimum_length    = 6
    require_lowercase = true
    require_numbers   = true
    require_symbols   = true
    require_uppercase = true
  }

  email_configuration {
    email_sending_account = "COGNITO_DEFAULT"
  }

  auto_verified_attributes = ["email"]

  username_attributes = ["email"]
  username_configuration {
    case_sensitive = true
  }
}

验证

重新运行terraform plan,错误即可消除。

内容的提问来源于stack exchange,提问作者Runeaway3

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 02:30:38