Terraform部署GCP HTTPS静态站点:URL Map创建失败排查
问题:GCP Terraform搭建HTTPS静态站点时URL Map创建失败
问题背景
通过Terraform在GCP上搭建关联存储桶的HTTPS负载均衡以提供静态站点服务,Terraform计划执行正常,但创建URL Map环节失败。
错误信息
TF Cloud返回错误:
Error: Error creating UrlMap: googleapi: Error 400: Invalid value for field 'resource.pathMatchers[0].pathRules[0].service': 'https://www.googleapis.com/storage/v1/b/eef9da33ed80dd35-static-website-bucket'. The URL is malformed., invalid with google_compute_url_map.my-https-network on main.tf line 81, in resource "google_compute_url_map" "my-https-network"
CURL测试结果
curl错误信息中引用的存储桶URL,返回200状态码:
curl -I https://www.googleapis.com/storage/v1/b/eef9da33ed80dd35-static-website-bucket
响应内容:
HTTP/2 200 x-guploader-uploadid: ADPycdslp8INsL__5hlmPHtkK8HUr4j1YOBpnnrpkGFqNfMmFKD82O3M4RciiHRrgqXh__wCccgJfjcR2WeQGlPM2mQ_pMMYGV2_ etag: CAI= content-type: application/json; charset=UTF-8 date: Fri, 04 Aug 2023 17:41:13 GMT vary: Origin vary: X-Origin cache-control: private, max-age=0, must-revalidate, no-transform expires: Fri, 04 Aug 2023 17:41:13 GMT server: UploadServer alt-svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
相关Terraform配置
版本与提供者声明
required_version = ">= 1.1.2" required_providers { google = { source = "hashicorp/google" version = ">= 3.53, < 5.0" } google-beta = { source = "hashicorp/google-beta" version = ">= 4.40, < 5.0" } random = { source = "hashicorp/random" } tls = { source = "hashicorp/tls" } }
负载均衡器与核心资源配置
使用GoogleCloudPlatform/lb-http/google模块搭建HTTPS负载均衡,核心配置如下:
resource "google_storage_bucket" "static_website" { name = "${random_id.bucket_prefix.hex}-static-website-bucket" location = "US" storage_class = "STANDARD" website { main_page_suffix = "index.html" not_found_page = "404.html" } } module "gce-lb-https" { source = "GoogleCloudPlatform/lb-http/google" name = var.network_name project = var.project_id target_tags = [] firewall_networks = [google_compute_network.default.self_link] url_map = google_compute_url_map.my-network.self_link create_url_map = false ssl = true private_key = tls_private_key.my-app.private_key_pem certificate = tls_self_signed_cert.my-app.cert_pem backends = { default = { protocol = "HTTP" port = 80 port_name = "http" timeout_sec = 10 enable_cdn = false groups = [] health_check = local.health_check log_config = { enable = true sample_rate = 1.0 } iap_config = { enable = false } } } } resource "google_compute_url_map" "my-https-network" { // note that this is the name of the load balancer name = var.network_name default_service = module.gce-lb-https.backend_services["default"].self_link host_rule { hosts = ["*"] path_matcher = "allpaths" } path_matcher { name = "allpaths" default_service = module.gce-lb-https.backend_services["default"].self_link path_rule { paths = [ "/", "/*" ] service = google_storage_bucket.static_website.self_link } } }
解决方案
错误核心原因:GCP的URL Map规则中,service字段不能直接使用存储桶的REST API链接,必须使用Cloud Storage后端服务的自链接。
修复步骤
- 创建
google_compute_backend_bucket资源,将存储桶关联为负载均衡的后端存储桶:
resource "google_compute_backend_bucket" "static_site_bucket" { name = "${random_id.bucket_prefix.hex}-static-site-backend-bucket" bucket_name = google_storage_bucket.static_website.name enable_cdn = false // 根据业务需求决定是否开启CDN }
- 修改
google_compute_url_map中的path_rule,将service替换为后端存储桶的自链接:
path_rule { paths = [ "/", "/*" ] service = google_compute_backend_bucket.static_site_bucket.self_link }
关键说明
google_compute_backend_bucket是GCP专门用于将Cloud Storage桶作为负载均衡后端的资源,它会生成符合URL Map要求的服务链接格式(格式示例:https://www.googleapis.com/compute/v1/projects/[PROJECT_ID]/global/backendBuckets/[NAME])。- 原配置中直接使用存储桶的
self_link是REST API地址,不符合URL Map对后端服务链接的格式要求,因此触发400错误。
内容的提问来源于stack exchange,提问作者K Pekosh
相关产品推荐
相关产品推荐

