Terraform配置ElastiCache全局复制组加密报错求助
问题背景
需要部署带有全局复制组的Amazon ElastiCache Redis集群,启用静态加密(at-rest encryption)和传输中加密(in-transit encryption),但在Terraform配置中直接在aws_elasticache_global_replication_group资源里设置加密属性时出现错误。
原配置片段
resource "aws_elasticache_cluster" "redis_cluster" { cluster_id = var.redis_cluster_name engine = "redis" engine_version = "6.2" node_type = "cache.t2.small" num_cache_nodes = 1 parameter_group_name = "default.redis6.x" subnet_group_name = var.subnet_group_name security_group_ids = [var.security_group_id] port = 6379 log_delivery_configuration { destination = aws_cloudwatch_log_group.redis_cluster_logs.name destination_type = "cloudwatch-logs" log_format = "text" log_type = "slow-log" } maintenance_window = "sun:05:00-sun:06:00" snapshot_window = "01:00-02:00" snapshot_retention_limit = 30 } resource "aws_elasticache_global_replication_group" "{replication_group_identifier}" { global_replication_group_id_suffix = "{unique_suffix}" automatic_failover_enabled = true primary_replication_group_id = aws_elasticache_cluster.{cluster_identifier}.id at_rest_encryption_enabled = true transit_encryption_enabled = true }
错误信息
Can't configure a value for "at_rest_encryption_enabled": its value will be decided automatically based on the result of applying this configuration. Value for unconfigurable attribute with aws_elasticache_global_replication_group.{replication_group_identifier}, on infra.tf line 537, in resource "aws_elasticache_global_replication_group" "{replication_group_identifier}": transit_encryption_enabled = true
Can't configure a value for "transit_encryption_enabled": its value will be decided automatically based on the result of applying this configuration. in this script
解决方案
核心原理
AWS ElastiCache全局复制组的加密配置完全继承自主复制组,Terraform的aws_elasticache_global_replication_group资源中,at_rest_encryption_enabled和transit_encryption_enabled是只读属性,无法手动设置。因此必须在**主复制组(aws_elasticache_replication_group)**中配置加密属性,全局组会自动同步这些设置。
修正后的配置
- 将原单个集群资源替换为复制组资源,在其中配置加密参数
- 全局复制组引用该复制组作为主组,无需再设置加密属性
# 创建主复制组,配置静态和传输加密 resource "aws_elasticache_replication_group" "redis_primary_rg" { replication_group_id = var.redis_cluster_name engine = "redis" engine_version = "6.2" node_type = "cache.t2.small" number_cache_clusters = 1 parameter_group_name = "default.redis6.x" subnet_group_name = var.subnet_group_name security_group_ids = [var.security_group_id] port = 6379 # 启用静态加密 at_rest_encryption_enabled = true # 启用传输中加密 transit_encryption_enabled = true # 可选:强制所有连接使用加密,避免未加密连接 transit_encryption_mode = "required" log_delivery_configuration { destination = aws_cloudwatch_log_group.redis_cluster_logs.name destination_type = "cloudwatch-logs" log_format = "text" log_type = "slow-log" } maintenance_window = "sun:05:00-sun:06:00" snapshot_window = "01:00-02:00" snapshot_retention_limit = 30 automatic_failover_enabled = true } # 创建全局复制组,自动继承主复制组的加密配置 resource "aws_elasticache_global_replication_group" "redis_global_rg" { global_replication_group_id_suffix = "your-unique-suffix" primary_replication_group_id = aws_elasticache_replication_group.redis_primary_rg.id }
关键说明
- 全局复制组依赖的是
aws_elasticache_replication_group资源,而非aws_elasticache_cluster,即使是单节点集群也需要用复制组资源定义 - 加密属性必须在主复制组中配置,全局组会自动继承,无需重复设置
transit_encryption_mode设为required可强制客户端使用加密连接,提升安全性
内容的提问来源于stack exchange,提问作者Albert sahu

