Terraform循环生成Glue数据库与表IAM权限策略报错求助
Solution to Generate Glue Database and Table ARNs in IAM Policy
To create a flat list of Glue database and table ARNs for your IAM policy, use Terraform's flatten function to combine per-database ARN pairs into a single list. This resolves the nested list error from your first attempt and simplifies logic compared to your second approach.
Correct Terraform Code
variable "glue_database" { type = list(string) default = ["databaseone", "databasetwo", "databasethree"] } variable "region" { type = string default = "us-east-1" } variable "account" { type = string default = "12345678" } data "aws_iam_policy_document" "policy_glue" { statement { actions = [ "glue:Get*", "glue:Create*", "glue:Update*" ] effect = "Allow" resources = flatten([ for db in var.glue_database : [ format("arn:aws:glue:%s:%s:database/%s", var.region, var.account, db), format("arn:aws:glue:%s:%s:table/%s/*", var.region, var.account, db) ] ]) } }
Key Fixes Explained
- Flat List with
flatten: Converts the nested list (each database produces two ARNs) into a single flat list of strings, matching the expected type for theresourcesattribute. - Variable Consistency: Fixed the typo (
var.glue_databases→var.glue_database) to align with your variable name. - Simplified ARN Generation: Used
formatinstead offormatlistsince we generate individual strings per database, not transform an entire list at once.
Generated Policy Output
This code produces exactly the resources list you requested:
[ "arn:aws:glue:us-east-1:12345678:database/databaseone", "arn:aws:glue:us-east-1:12345678:table/databaseone/*", "arn:aws:glue:us-east-1:12345678:database/databasetwo", "arn:aws:glue:us-east-1:12345678:table/databasetwo/*", "arn:aws:glue:us-east-1:12345678:database/databasethree", "arn:aws:glue:us-east-1:12345678:table/databasethree/*" ]
内容的提问来源于stack exchange,提问作者Carlos
相关产品推荐
相关产品推荐

