Terraform跨AWS账号模块调用报错:子模块无法访问父级network模块输出
解决Terraform跨模块引用VPC ID的报错问题
报错no module call named network is declared in module.sandbox的核心原因是Terraform模块的作用域是隔离的:子模块(sandbox)无法直接访问父模块(根目录)中声明的其他子模块(network),必须通过输入变量的方式传递所需值。
步骤1:为sandbox模块定义输入变量
在sandbox/variables.tf中添加变量声明,用来接收父模块传递的VPC ID:
variable "vpc_id" { type = string description = "VPC ID from network account" }
如果需要传递子网、安全组等其他资源ID,可同步添加对应变量,比如:
variable "private_subnet_ids" { type = list(string) description = "Private subnet IDs from network account" } variable "allow_rds_sg_id" { type = string description = "Security group ID for RDS access from network account" }
步骤2:根目录传递资源ID给sandbox模块
在根目录的main.tf里,调用sandbox模块时,将network模块输出的资源ID作为参数传入:
module "network" { source = "./network" # 配置network模块的provider、参数等 } module "sandbox" { source = "./sandbox" # 传递VPC ID到sandbox模块 vpc_id = module.network.nw_stack_vpc_id private_subnet_ids = module.network.private_subnet_ids allow_rds_sg_id = module.network.allow_rds_sg_id # 其他sandbox模块的配置 }
步骤3:在sandbox模块内部使用变量
修改sandbox/main.tf,用var.xxx替代原来的module.network.xxx引用,比如配置EC2或RDS时:
resource "aws_rds_cluster" "sandbox_db" { cluster_identifier = "sandbox-db-cluster" engine = "aurora-postgresql" master_username = "admin" master_password = var.db_password vpc_security_group_ids = [var.allow_rds_sg_id] # 其他配置 } resource "aws_rds_cluster_instance" "sandbox_db_node" { cluster_identifier = aws_rds_cluster.sandbox_db.id instance_class = "db.t3.small" db_subnet_group_name = aws_db_subnet_group.sandbox_db_subnet.name # 其他配置 } resource "aws_db_subnet_group" "sandbox_db_subnet" { name = "sandbox-db-subnet-group" subnet_ids = var.private_subnet_ids }
额外验证:确保network模块已输出对应值
检查network模块的outputs.tf,确认已声明需要传递的资源输出,比如:
output "nw_stack_vpc_id" { type = string value = aws_vpc.nw_stack.id description = "VPC ID of the network stack" } output "private_subnet_ids" { type = list(string) value = aws_subnet.private.*.id description = "IDs of private subnets in network account" }
内容的提问来源于stack exchange,提问作者Dean Christian Armada
相关产品推荐
相关产品推荐

