Terraform中google_compute_firewall模块无法识别project参数问题
问题原因与解决办法
你遇到的错误是因为子模块没有声明project这个输入变量,Terraform模块的参数传递是严格的:父模块给子模块传参数时,子模块必须提前在variables.tf文件里定义对应的变量,否则Terraform会认为这个参数是不被允许的。
具体修复步骤:
- 在你的子模块(
../../modules/networking/firewall)目录下创建或修改variables.tf文件,把所有子模块用到的变量都声明出来,包括project:
variable "project" { type = string description = "GCP项目ID,防火墙规则将创建在此项目中" } variable "name" { type = string description = "防火墙规则名称" } variable "network" { type = string description = "防火墙规则所属的VPC网络(名称或自链接)" } variable "disabled" { type = bool description = "是否禁用此防火墙规则" default = false # 给个默认值,父模块不用强制传递 } variable "protocol" { type = string description = "防火墙允许的协议" } variable "ports" { type = list(number) description = "防火墙允许的端口列表" } variable "target_tags" { type = list(string) description = "规则适用的目标实例标签" default = [] } variable "source_ranges" { type = list(string) description = "允许访问的源IP范围" } variable "source_tags" { type = list(string) description = "允许访问的源实例标签" default = [] }
- 确认父模块的参数传递和子模块变量匹配:
你父模块里传递的project、network、name等参数,现在子模块都有对应的变量声明了,Terraform就能正确识别这些参数。
另外注意:子模块代码里用到了var.disabled,但你父模块没传这个参数,所以给disabled变量加了默认值false,避免后续出现“变量未设置”的错误。
内容的提问来源于stack exchange,提问作者Rahul
相关产品推荐
相关产品推荐

