如何通过Terraform实现FSx Lustre SCRATCH2与S3的DRA关联?
解决方案:Terraform 实现 FSx Lustre SCRATCH_2 关联 S3 DRA
你遇到的问题核心是:Terraform AWS Provider 的 aws_fsx_data_repository_association 资源目前(截至 5.26.0 版本)仅支持 PERSISTENT_2 类型的 FSx Lustre 文件系统,但 AWS 控制台通过直接调用「创建 FSx 时关联数据仓库」的 API 路径,支持为 SCRATCH_2 类型配置 S3 DRA。以下是两种可行的实现方式:
方式一:创建 FSx 时直接关联 S3 DRA(推荐)
这种方式和控制台「一次性创建带 DRA 的文件系统」逻辑完全一致,通过 aws_fsx_lustre_file_system 资源自带的 data_repository_configuration 块实现,绕过单独 DRA 资源的类型限制。
完整代码示例
# 1. 创建 FSx 访问 S3 所需的 IAM 角色 resource "aws_iam_role" "fsx_lustre_dra_role" { name = "fsx-lustre-scratch2-dra-role" assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Action = "sts:AssumeRole" Effect = "Allow" Principal = { Service = "fsx.amazonaws.com" } } ] }) } # 2. 为角色附加 FSx 全访问权限(可自定义更严格的权限政策) resource "aws_iam_role_policy_attachment" "fsx_lustre_dra_policy" { role = aws_iam_role.fsx_lustre_dra_role.name policy_arn = "arn:aws:iam::aws:policy/AmazonFSxLustreFullAccess" } # 3. 创建 S3 桶(注意桶名必须全局唯一) resource "aws_s3_bucket" "a_buck" { bucket = "my-unique-scratch2-dra-bucket" } # 4. 创建带 S3 DRA 关联的 SCRATCH_2 文件系统 resource "aws_fsx_lustre_file_system" "smpl_lstr_scr2" { deployment_type = "SCRATCH_2" storage_capacity = 1200 data_compression_type = null subnet_ids = [var.mysubnet] data_repository_configuration { data_repository_path = "s3://${aws_s3_bucket.a_buck.bucket}" file_system_path = "/" iam_role_arn = aws_iam_role.fsx_lustre_dra_role.arn auto_import_policy { events = ["NEW", "CHANGED", "DELETED"] } auto_export_policy { events = ["NEW", "CHANGED", "DELETED"] } } }
方式二:事后为已创建的 SCRATCH_2 文件系统添加 DRA
如果需要先创建 FSx 再关联 DRA,可以通过 local-exec 调用 AWS CLI 命令实现(因为 AWS API 本身支持该操作,仅 Terraform Provider 资源未适配 SCRATCH_2 类型)。
代码示例
# 1. 基础资源:IAM 角色、S3 桶、SCRATCH_2 文件系统 resource "aws_iam_role" "fsx_lustre_dra_role" { name = "fsx-lustre-scratch2-dra-role" assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Action = "sts:AssumeRole" Effect = "Allow" Principal = { Service = "fsx.amazonaws.com" } } ] }) } resource "aws_iam_role_policy_attachment" "fsx_lustre_dra_policy" { role = aws_iam_role.fsx_lustre_dra_role.name policy_arn = "arn:aws:iam::aws:policy/AmazonFSxLustreFullAccess" } resource "aws_s3_bucket" "a_buck" { bucket = "my-unique-scratch2-dra-bucket" } resource "aws_fsx_lustre_file_system" "smpl_lstr_scr2" { deployment_type = "SCRATCH_2" storage_capacity = 1200 data_compression_type = null subnet_ids = [var.mysubnet] } # 2. 通过 CLI 事后创建 DRA resource "null_resource" "create_scratch2_dra" { depends_on = [aws_fsx_lustre_file_system.smpl_lstr_scr2, aws_s3_bucket.a_buck, aws_iam_role_policy_attachment.fsx_lustre_dra_policy] # 创建 DRA provisioner "local-exec" { command = <<EOT aws fsx create-data-repository-association \ --file-system-id ${aws_fsx_lustre_file_system.smpl_lstr_scr2.id} \ --data-repository-path s3://${aws_s3_bucket.a_buck.bucket} \ --file-system-path "/" \ --s3 '{"AutoExportPolicy": {"Events": ["NEW", "CHANGED", "DELETED"]}, "AutoImportPolicy": {"Events": ["NEW", "CHANGED", "DELETED"]}}' \ --iam-role-arn ${aws_iam_role.fsx_lustre_dra_role.arn} EOT } # 销毁时清理 DRA provisioner "local-exec" { when = destroy command = <<EOT ASSOC_ID=$(aws fsx describe-data-repository-associations --file-system-id ${aws_fsx_lustre_file_system.smpl_lstr_scr2.id} --query 'Associations[0].AssociationId' --output text) if [ -n "$ASSOC_ID" ]; then aws fsx delete-data-repository-association --association-id $ASSOC_ID fi EOT } }
内容的提问来源于stack exchange,提问作者Alexander Ites
相关产品推荐
相关产品推荐

