You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform+GitLab基于已有VPC创建EKS集群遇子网不存在错误求助

问题:Terraform创建EKS集群提示Subnet ID不存在

执行Terraform创建EKS集群时触发以下错误:

创建EKS Cluster (example): InvalidParameterException: The subnet ID 'subnet-0250558d209750998' does not exist (Service: AmazonEC2; Status Code: 400; Error Code: InvalidSubnetID.NotFound; Request ID: da43167e-7430-4f7a-85e5-3ea185468c0a; Proxy: null)

我的Cluster.tf代码如下:

resource "aws_eks_cluster" "example" {
  name     = "example"
  role_arn = aws_iam_role.example.arn

  vpc_config {
    subnet_ids = ["subnet-0250558d209750998","subnet-0aab7bc16ef569ef1"]
  }

  depends_on = [
    aws_iam_role_policy_attachment.example-AmazonEKSClusterPolicy,
    aws_iam_role_policy_attachment.example-AmazonEKSVPCResourceController,
  ]
}

output "endpoint" {
  value = aws_eks_cluster.example.endpoint
}

output "kubeconfig-certificate-authority-data" {
  value = aws_eks_cluster.example.certificate_authority[0].data
}

data "aws_iam_policy_document" "assume_role" {
  statement {
    effect = "Allow"

    principals {
      type        = "Service"
      identifiers = ["eks.amazonaws.com"]
    }

    actions = ["sts:AssumeRole"]
  }
}

resource "aws_iam_role" "example" {
  name               = "eks-cluster-example"
  assume_role_policy = data.aws_iam_policy_document.assume_role.json
}

resource "aws_iam_role_policy_attachment" "example-AmazonEKSClusterPolicy" {
  policy_arn = "arn:aws:iam::aws:policy/AmazonEKSClusterPolicy"
  role       = aws_iam_role.example.name
}

# Optionally, enable Security Groups for Pods
resource "aws_iam_role_policy_attachment" "example-AmazonEKSVPCResourceController" {
  policy_arn = "arn:aws:iam::aws:policy/AmazonEKSVPCResourceController"
  role       = aws_iam_role.example.name
}


data "aws_eks_clusters" "example" {}


resource "aws_launch_template" "this" {
  name = "this"

  metadata_options {
    http_endpoint               = "enabled"
    http_tokens                 = "required"
    http_put_response_hop_limit = 1
    instance_metadata_tags      = "enabled"
  }
}


resource "aws_eks_node_group" "example" {
  cluster_name    = aws_eks_cluster.example.name
  node_group_name = "example"
  node_role_arn   = aws_iam_role.example2.arn
  ami_type = "AL2_x86_64"
  subnet_ids = ["subnet-0250558d209750998","subnet-0aab7bc16ef569ef1"]

  scaling_config {
    desired_size = 1
    max_size     = 2
    min_size     = 1
  }

  update_config {
    max_unavailable = 1
  }
  
  launch_template {
    version = aws_launch_template.this.latest_version
    id      = aws_launch_template.this.id
  }
  
}

resource "aws_iam_role" "example2" {
  name = "eks-node-group-example"

  assume_role_policy = jsonencode({
    Statement = [{
      Action = "sts:AssumeRole"
      Effect = "Allow"
      Principal = {
        Service = "ec2.amazonaws.com"
      }
    }]
    Version = "2012-10-17"
  })
}

resource "aws_iam_role_policy_attachment" "example-AmazonEKSWorkerNodePolicy" {
  policy_arn = "arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy"
  role       = aws_iam_role.example.name
}

resource "aws_iam_role_policy_attachment" "example-AmazonEKS_CNI_Policy" {
  policy_arn = "arn:aws:iam::aws:policy/AmazonEKS_CNI_Policy"
  role       = aws_iam_role.example.name
}

resource "aws_iam_role_policy_attachment" "example-AmazonEC2ContainerRegistryReadOnly" {
  policy_arn = "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly"
  role       = aws_iam_role.example.name
}

排查与解决方法

1. 验证Subnet ID的正确性

  • 登录AWS控制台进入VPC服务,核对代码中的subnet-0250558d209750998是否存在于目标VPC的子网列表中,注意检查字符输入错误。
  • 若子网不存在,替换为VPC下有效的子网ID;若为输入错误,直接修正ID即可。

2. 确认AWS区域匹配

  • 检查Terraform配置的AWS区域(provider "aws"块或GitLab CI/CD的AWS_REGION环境变量)是否与子网所在区域一致。
  • 子网是区域级资源,跨区域无法访问,必须保证操作区域与子网区域完全匹配。

3. 检查AWS权限与账户

  • 确认Terraform使用的AWS凭证(GitLab配置的IAM角色或Access Key)所属账户,与子网所在账户一致。
  • 确保该凭证拥有ec2:DescribeSubnets权限,保证Terraform能正常读取子网信息。

4. 优化代码:自动获取子网(可选)

避免手动输入出错,可通过Terraform数据源自动获取现有VPC下的子网:

data "aws_subnet_ids" "eks_subnets" {
  vpc_id = "你的现有VPC ID"
}

# 在EKS集群和节点组中使用数据源结果
resource "aws_eks_cluster" "example" {
  # 其他配置保持不变
  vpc_config {
    subnet_ids = data.aws_subnet_ids.eks_subnets.ids
  }
}

resource "aws_eks_node_group" "example" {
  # 其他配置保持不变
  subnet_ids = data.aws_subnet_ids.eks_subnets.ids
}

5. 修正IAM角色绑定错误

代码中节点组的IAM角色(example2)所需的策略,错误绑定到了集群角色(example)上,需修正以下配置:

resource "aws_iam_role_policy_attachment" "example-AmazonEKSWorkerNodePolicy" {
  policy_arn = "arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy"
  role       = aws_iam_role.example2.name # 改为example2
}

resource "aws_iam_role_policy_attachment" "example-AmazonEKS_CNI_Policy" {
  policy_arn = "arn:aws:iam::aws:policy/AmazonEKS_CNI_Policy"
  role       = aws_iam_role.example2.name # 改为example2
}

resource "aws_iam_role_policy_attachment" "example-AmazonEC2ContainerRegistryReadOnly" {
  policy_arn = "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly"
  role       = aws_iam_role.example2.name # 改为example2
}

该错误虽不是当前子网问题的直接原因,但会导致节点组无法正常工作,建议一并修正。


内容的提问来源于stack exchange,提问作者Azmy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 23:47:21