You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置ElastiCache全局复制组加密报错求助

解决ElastiCache全局复制组加密配置问题

问题背景

需要部署带有全局复制组的Amazon ElastiCache Redis集群,启用静态加密(at-rest encryption)和传输中加密(in-transit encryption),但在Terraform配置中直接在aws_elasticache_global_replication_group资源里设置加密属性时出现错误。

原配置片段

resource "aws_elasticache_cluster" "redis_cluster" {
  cluster_id               = var.redis_cluster_name
  engine                   = "redis"
  engine_version           = "6.2"
  node_type                = "cache.t2.small"
  num_cache_nodes          = 1
  parameter_group_name     = "default.redis6.x"
  subnet_group_name        = var.subnet_group_name
  security_group_ids       = [var.security_group_id]
  port                     = 6379

  log_delivery_configuration {
    destination      = aws_cloudwatch_log_group.redis_cluster_logs.name
    destination_type = "cloudwatch-logs"
    log_format       = "text"
    log_type         = "slow-log"
  }

  maintenance_window       = "sun:05:00-sun:06:00"
  snapshot_window          = "01:00-02:00"
  snapshot_retention_limit = 30
}

resource "aws_elasticache_global_replication_group" "{replication_group_identifier}" {
  global_replication_group_id_suffix  = "{unique_suffix}"
  automatic_failover_enabled          = true
  primary_replication_group_id        = aws_elasticache_cluster.{cluster_identifier}.id
  at_rest_encryption_enabled = true
  transit_encryption_enabled = true
}

错误信息

Can't configure a value for "at_rest_encryption_enabled": its value will be decided automatically based on the result of applying this configuration. Value for unconfigurable attribute with aws_elasticache_global_replication_group.{replication_group_identifier}, on infra.tf line 537, in resource "aws_elasticache_global_replication_group" "{replication_group_identifier}": transit_encryption_enabled = true

Can't configure a value for "transit_encryption_enabled": its value will be decided automatically based on the result of applying this configuration. in this script

解决方案

核心原理

AWS ElastiCache全局复制组的加密配置完全继承自主复制组,Terraform的aws_elasticache_global_replication_group资源中,at_rest_encryption_enabled和transit_encryption_enabled是只读属性,无法手动设置。因此必须在**主复制组(aws_elasticache_replication_group)**中配置加密属性,全局组会自动同步这些设置。

修正后的配置

  1. 将原单个集群资源替换为复制组资源,在其中配置加密参数
  2. 全局复制组引用该复制组作为主组,无需再设置加密属性
# 创建主复制组,配置静态和传输加密
resource "aws_elasticache_replication_group" "redis_primary_rg" {
  replication_group_id          = var.redis_cluster_name
  engine                        = "redis"
  engine_version                = "6.2"
  node_type                     = "cache.t2.small"
  number_cache_clusters         = 1
  parameter_group_name          = "default.redis6.x"
  subnet_group_name             = var.subnet_group_name
  security_group_ids            = [var.security_group_id]
  port                          = 6379

  # 启用静态加密
  at_rest_encryption_enabled    = true
  # 启用传输中加密
  transit_encryption_enabled    = true
  # 可选:强制所有连接使用加密,避免未加密连接
  transit_encryption_mode       = "required"

  log_delivery_configuration {
    destination      = aws_cloudwatch_log_group.redis_cluster_logs.name
    destination_type = "cloudwatch-logs"
    log_format       = "text"
    log_type         = "slow-log"
  }

  maintenance_window       = "sun:05:00-sun:06:00"
  snapshot_window          = "01:00-02:00"
  snapshot_retention_limit = 30
  automatic_failover_enabled = true
}

# 创建全局复制组,自动继承主复制组的加密配置
resource "aws_elasticache_global_replication_group" "redis_global_rg" {
  global_replication_group_id_suffix  = "your-unique-suffix"
  primary_replication_group_id        = aws_elasticache_replication_group.redis_primary_rg.id
}

关键说明

  • 全局复制组依赖的是aws_elasticache_replication_group资源,而非aws_elasticache_cluster,即使是单节点集群也需要用复制组资源定义
  • 加密属性必须在主复制组中配置,全局组会自动继承,无需重复设置
  • transit_encryption_mode设为required可强制客户端使用加密连接,提升安全性

内容的提问来源于stack exchange,提问作者Albert sahu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 19:07:12