配置AWS Config ELB自定义SSL安全策略规则Terraform报错排查
问题:AWS Config合规包添加ELB_CUSTOM_SECURITY_POLICY_SSL_CHECK规则时报内部错误
ELB_CUSTOM_SECURITY_POLICY_SSL_CHECK规则说明
Identifier: ELB_CUSTOM_SECURITY_POLICY_SSL_CHECK Resource Types: AWS::ElasticLoadBalancing::LoadBalancer Trigger type: Configuration changes AWS Region: All supported AWS regions except Asia Pacific (Jakarta), Africa (Cape Town), Middle East (UAE), Asia Pacific (Hyderabad), Asia Pacific (Osaka), Asia Pacific (Melbourne), Europe (Milan), AWS GovCloud (US-East), Israel (Tel Aviv), Europe (Spain), Europe (Zurich) Region Parameters: sslProtocolsAndCiphers Type: String Comma separated list of ciphers and protocols.
已定义的Terraform变量
variable "elb_custom_security_policy_ssl_check" { type = string default = "AES128-SHA256,TLSv1.3" }
当前合规包Terraform配置
resource "aws_config_conformance_pack" "conformancepack" { name = "conformancepact" template_body = <<EOT Resources: ElbCustomSecurityPolicySslCheck: properties: ConifigRuleName: elb-custom-security-policy-ssl-check InputParameters: sslProtocolsAndCiphers: ${var.elb_custom_security_policy_ssl_check} Scope: ComplianceResourceTypes: - AWS::ElasticLoadBalancing::LoadBalancer Source: Owner: AWS SourceIdentifier: ELB_CUSTOM_SECURITY_POLICY_SSL_CHECK Type: AWS::Config::ConfigRule EOT }
问题原因与修正方案
触发内部错误的核心问题有两个:
- 字段拼写错误:
ConifigRuleName应为ConfigRuleName(缺失字母g),错误的字段名会导致AWS无法识别规则配置项。 - 参数格式错误:在YAML模板中,
InputParameters的字符串值必须用双引号包裹,否则Terraform插值后的内容会被YAML解析器误判,引发格式异常。
修正后的合规包配置:
resource "aws_config_conformance_pack" "conformancepack" { name = "conformancepact" template_body = <<EOT Resources: ElbCustomSecurityPolicySslCheck: properties: ConfigRuleName: elb-custom-security-policy-ssl-check InputParameters: sslProtocolsAndCiphers: "${var.elb_custom_security_policy_ssl_check}" Scope: ComplianceResourceTypes: - AWS::ElasticLoadBalancing::LoadBalancer Source: Owner: AWS SourceIdentifier: ELB_CUSTOM_SECURITY_POLICY_SSL_CHECK Type: AWS::Config::ConfigRule EOT }
内容的提问来源于stack exchange,提问作者George Udosen
相关产品推荐
相关产品推荐

