You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于Terraform跨AWS账号通过数据资源获取AWS MSK相关资源的可行性咨询

Can Terraform fetch cross-account AWS MSK resources using data sources?

Absolutely, Terraform does support retrieving cross-account AWS MSK (Managed Streaming for Kafka) resources like cluster ARNs and topic ARNs via data sources. The key is configuring a dedicated AWS provider for the target account and ensuring proper IAM permissions are in place. Let me break this down step by step:

1. Configure a cross-account AWS Provider

You'll need to set up an additional AWS provider that authenticates to the target account, using an alias to distinguish it from your default provider. The most secure method is to use IAM role assumption (instead of hardcoding credentials):

# Default provider for your current/source AWS account
provider "aws" {
  region = "us-east-1" # Update to your region
}

# Provider for the target AWS account (where the MSK resources live)
provider "aws" {
  alias  = "target_msk_account"
  region = "us-east-1" # Match the target cluster's region

  assume_role {
    role_arn = "arn:aws:iam::TARGET_ACCOUNT_ID:role/TerraformCrossAccountAccessRole"
    # Optional: Add an external ID for extra security if required by the target role
    # external_id = "your-security-external-id"
  }
}

2. Use data sources with the cross-account provider

Specify the provider argument in your MSK data sources to point to the target account's provider. Here are examples for both MSK clusters and topics:

Fetch MSK Cluster ARN

data "aws_msk_cluster" "target_kafka_cluster" {
  provider     = aws.target_msk_account
  cluster_name = "your-target-msk-cluster-name"
}

# Access the cluster ARN with: data.aws_msk_cluster.target_kafka_cluster.arn

Fetch MSK Topic ARN

data "aws_msk_topic" "target_kafka_topic" {
  provider     = aws.target_msk_account
  cluster_arn  = data.aws_msk_cluster.target_kafka_cluster.arn
  name         = "your-target-kafka-topic-name"
}

# Access the topic ARN with: data.aws_msk_topic.target_kafka_topic.arn

3. Set up IAM permissions in the target account

For this to work, the target account needs an IAM role that:

  • Allows your source account's identity (user/role) to assume it
  • Grants permissions to describe MSK clusters and topics

Trust Policy for the Target Role

This policy lets your source account's identity assume the role:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::SOURCE_ACCOUNT_ID:user/YourTerraformUser" # Or role ARN
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

Permissions Policy for the Target Role

This policy grants the necessary access to MSK resources:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "kafka:DescribeCluster",
        "kafka:DescribeTopic"
      ],
      "Resource": [
        "arn:aws:kafka:REGION:TARGET_ACCOUNT_ID:cluster/your-target-msk-cluster-name/*",
        "arn:aws:kafka:REGION:TARGET_ACCOUNT_ID:topic/your-target-msk-cluster-name/*/your-target-kafka-topic-name"
      ]
    }
  ]
}

4. Key Notes

  • Ensure your source account's identity has the sts:AssumeRole permission for the target role
  • Double-check resource names, ARNs, and regions—typos here are a common pitfall
  • MSK's aws_msk_cluster and aws_msk_topic data sources do support cross-account access when permissions are correctly configured
  • Test with terraform plan first to confirm Terraform can retrieve the cross-account resources without errors

内容的提问来源于stack exchange,提问作者David Faizulaev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 12:22:29