关于Terraform跨AWS账号通过数据资源获取AWS MSK相关资源的可行性咨询
Absolutely, Terraform does support retrieving cross-account AWS MSK (Managed Streaming for Kafka) resources like cluster ARNs and topic ARNs via data sources. The key is configuring a dedicated AWS provider for the target account and ensuring proper IAM permissions are in place. Let me break this down step by step:
1. Configure a cross-account AWS Provider
You'll need to set up an additional AWS provider that authenticates to the target account, using an alias to distinguish it from your default provider. The most secure method is to use IAM role assumption (instead of hardcoding credentials):
# Default provider for your current/source AWS account provider "aws" { region = "us-east-1" # Update to your region } # Provider for the target AWS account (where the MSK resources live) provider "aws" { alias = "target_msk_account" region = "us-east-1" # Match the target cluster's region assume_role { role_arn = "arn:aws:iam::TARGET_ACCOUNT_ID:role/TerraformCrossAccountAccessRole" # Optional: Add an external ID for extra security if required by the target role # external_id = "your-security-external-id" } }
2. Use data sources with the cross-account provider
Specify the provider argument in your MSK data sources to point to the target account's provider. Here are examples for both MSK clusters and topics:
Fetch MSK Cluster ARN
data "aws_msk_cluster" "target_kafka_cluster" { provider = aws.target_msk_account cluster_name = "your-target-msk-cluster-name" } # Access the cluster ARN with: data.aws_msk_cluster.target_kafka_cluster.arn
Fetch MSK Topic ARN
data "aws_msk_topic" "target_kafka_topic" { provider = aws.target_msk_account cluster_arn = data.aws_msk_cluster.target_kafka_cluster.arn name = "your-target-kafka-topic-name" } # Access the topic ARN with: data.aws_msk_topic.target_kafka_topic.arn
3. Set up IAM permissions in the target account
For this to work, the target account needs an IAM role that:
- Allows your source account's identity (user/role) to assume it
- Grants permissions to describe MSK clusters and topics
Trust Policy for the Target Role
This policy lets your source account's identity assume the role:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::SOURCE_ACCOUNT_ID:user/YourTerraformUser" # Or role ARN }, "Action": "sts:AssumeRole" } ] }
Permissions Policy for the Target Role
This policy grants the necessary access to MSK resources:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "kafka:DescribeCluster", "kafka:DescribeTopic" ], "Resource": [ "arn:aws:kafka:REGION:TARGET_ACCOUNT_ID:cluster/your-target-msk-cluster-name/*", "arn:aws:kafka:REGION:TARGET_ACCOUNT_ID:topic/your-target-msk-cluster-name/*/your-target-kafka-topic-name" ] } ] }
4. Key Notes
- Ensure your source account's identity has the
sts:AssumeRolepermission for the target role - Double-check resource names, ARNs, and regions—typos here are a common pitfall
- MSK's
aws_msk_clusterandaws_msk_topicdata sources do support cross-account access when permissions are correctly configured - Test with
terraform planfirst to confirm Terraform can retrieve the cross-account resources without errors
内容的提问来源于stack exchange,提问作者David Faizulaev

