Terraform部署Azure堡垒机模块报错:子网ID格式无效
问题背景
正在基于Terraform构建Azure Landing Zone,已实现Resource_Groups、Storage_Accounts、Virtual_Networks三个模块。新增Bastion_Host模块后执行terraform plan,触发以下错误:
Planning failed. Terraform encountered an error while generating this plan.
╷
│ Error: parsing "AzureBastionSubnet": parsing Azure ID: parse "AzureBastionSubnet": invalid URI for request
│
│ with module.Azure_Module_BH.azurerm_bastion_host.bastion,
│ on modules\Bastion_Host\main.tf line 19, in resource "azurerm_bastion_host" "bastion":
│ 19: subnet_id = var.subnet_id
经排查,错误源于Bastion_Host模块的subnet_id变量默认值设为子网名称AzureBastionSubnet,而非Azure要求的完整子网资源ID。
故障原因
- 参数类型不匹配:
azurerm_bastion_host资源的subnet_id参数必须接收完整的Azure子网资源ID(格式类似/subscriptions/{subscription-id}/resourceGroups/{rg-name}/providers/Microsoft.Network/virtualNetworks/{vnet-name}/subnets/{subnet-name}),但当前传入的是子网名称,不符合URI格式要求。 - 变量定义错误:
subnet_id变量的描述字段错误标注为"the name of the vnet",容易造成混淆。 - 模块间依赖传递缺失:根模块未从Virtual_Networks模块获取正确的子网ID,而是使用了模块内的错误默认值。
解决方案
1. 修正Bastion_Host模块的变量定义
更新variables.tf,修正描述并移除错误的默认值:
variable "resourcegroup_name" { type = string description = "The name of the resource group" default = "Networking-CC-RG" } variable "location" { type = string description = "The region for the deployment" default = "canadacentral" } variable "tags" { type = map(string) description = "Tags used for the deployment" default = { "Environment" = "Development" "Owner" = "OwnerEmail" "CreatedBy" = "JNuaman@outlook.com" } } variable "vnet_name" { type = string description = "The name of the virtual network" default = "VNET-Hub-CC-Prod-01" } variable "subnet_id" { type = string description = "The full resource ID of the AzureBastionSubnet" # 移除错误的默认值,强制从根模块传入正确ID } variable "bastionhost_name" { type = string description = "The name of the bastion host" default = "VNET-Hub-CC-Prod-01-BH-01" }
2. 在Virtual_Networks模块中输出子网ID
在Virtual_Networks模块的outputs.tf中添加AzureBastionSubnet的资源ID输出(假设子网在该模块中定义为azurerm_subnet.bastion):
output "bastion_subnet_id" { type = string description = "Resource ID of the AzureBastionSubnet" value = azurerm_subnet.bastion.id }
3. 根模块传递正确的子网ID到Bastion_Host模块
修改根模块代码,将Virtual_Networks模块输出的子网ID传递给Bastion_Host模块:
module "Azure_Module_RG" { source = "./Modules/Resource_Groups" } module "Azure_Module_SA" { source = "./Modules/Storage_Accounts" depends_on = [ module.Azure_Module_RG ] } module "Azure_Module_VNET" { source = "./Modules/Virtual_Networks" } module "Azure_Module_BH" { source = "./modules/Bastion_Host" subnet_id = module.Azure_Module_VNET.bastion_subnet_id # 若需要覆盖其他默认变量,也可在此传递,比如resourcegroup_name等 depends_on = [ module.Azure_Module_VNET ] }
验证执行
完成上述修改后,重新执行:
terraform init terraform plan
此时subnet_id将传入正确的子网资源ID,错误即可解决。
内容的提问来源于stack exchange,提问作者P for Tech

