基于顶层CIDR动态拆分netmask_length至Terraform IPAM模块
基于顶层CIDR动态设置IPAM池子网掩码长度的解决方案
已知顶层CIDR为10.0.0.0/8,需根据IP池层级关系,为各级pool及sub_pool分配对应的netmask_length,替代配置中的占位符?,具体逻辑及完整配置如下:
层级掩码分配逻辑
- 二级IP池(如
corporate-us-west-2、us-east-1):从顶层/8的CIDR分配/16的块,对应netmask_length = 16 - 三级IP池(如
sandbox、prod、us-east-1下的team_a/team_b):从二级/16的CIDR分配/20的块,对应netmask_length = 20 - 四级IP池(如
prod下的team_a/team_b):从三级/20的CIDR分配/24的块,对应netmask_length = 24
完整配置代码
module "basic" { source = "aws-ia/ipam/aws" top_cidr = ["10.0.0.0/8"] top_name = "basic ipam" pool_configurations = { corporate-us-west-2 = { description = "2nd level, locale us-west-2 pool" netmask_length = 16 sub_pools = { sandbox = { name = "mysandbox" netmask_length = 20 ram_share_principals = var.sandbox_ou_arn allocation_resource_tags = { env = "sandbox" } } dev = { netmask_length = 20 sub_pools = { team_a = { netmask_length = 24 locale = "us-west-2" } team_b = { netmask_length = 26 } } } prod = { netmask_length = 20 locale = "us-west-2" sub_pools = { team_a = { netmask_length = 24 ram_share_principals = var.prod_account # prod account } team_b = { netmask_length = 24 ram_share_principals = var.prod_account # prod account } } } } } us-east-1 = { netmask_length = 16 locale = "us-east-1" sub_pools = { team_a = { netmask_length = 20 } team_b = { netmask_length = 20 } } } } }
说明
- 配置严格遵循CIDR层级划分逻辑,从顶层/8依次向下划分子网掩码长度,确保IP地址空间的合理分配
- 已有的明确值(如
dev下team_b的26)保持不变,仅替换占位符
内容的提问来源于stack exchange,提问作者doctore
相关产品推荐
相关产品推荐

