GCP:在指定子网中创建私有PostgreSQL实例
解决方案
要将私有PostgreSQL实例部署到VPC的指定子网,需要调整Terraform配置中的几个关键参数,以下是具体修正步骤:
1. 修正IP配置参数
你的ip_configuration存在三个核心问题:
- 错误使用
ipv4_enabled控制公网IP(该参数用于启用/禁用IPv4,而非开关公网IP) - 错误将
private_network指向子网ID(该字段应指定VPC ID) allocated_ip_range误用了VPC CIDR(应指定之前创建的预留 peering IP范围)
修正后的ip_configuration配置如下:
ip_configuration = { public_ip_enabled = false # 禁用公网IP,仅使用私有IP private_network = module.vpc.vpc.id # 保持指向VPC ID subnet = module.vpc.subnet-a.id # 新增:指定目标子网的ID allocated_ip_range = google_compute_global_address.private_ip_address_some_name.name # 使用预留的peering IP范围名称 require_ssl = true authorized_networks = [ { name = "vpc-subnet-a" value = "10.2.1.0/24" } ] }
2. 确保依赖关系正确
由于PostgreSQL实例需要依赖VPC peering连接完成创建,需在PostgreSQL模块资源中添加依赖声明,避免资源创建顺序错误:
module "postgresql" { # 其他模块参数... depends_on = [google_service_networking_connection.some_other_name] }
3. 验证子网输出的正确性
确认VPC模块中subnet-a的输出指向正确的子网资源:
output "subnet-a" { value = google_compute_subnetwork.db_a # 确保db_a是subnet-a对应的资源 }
引用时module.vpc.subnet-a.id的写法是正确的,只要输出的子网资源存在且配置无误即可。
内容的提问来源于stack exchange,提问作者kvelev
相关产品推荐
相关产品推荐

