You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OCI中Terraform模块创建监控告警遇404权限/资源不存在问题求助

OCI Terraform告警配置:ONS主题访问权限问题排查思路

问题场景

使用Terraform模块配置OCI文件系统告警时,计划检查通过,但执行apply时出现404权限/资源找不到错误,指向指定的ONS主题。相关代码如下:

module "Module_FS_Critical_env_oci_all_instance" {
  source                = "../Common/Module/FileSystem"
  compartment_id        = oci_identity_compartment.project.id
  destination           = [data.oci_ons_notification_topics.get_project_Critical_topic.notification_topics[0].topic_id]
  display_name          = "tf_Module_Critical_FS_Alarm_${each.key}"
  metric_compartment_id = oci_identity_compartment.cic_prod.id
  for_each = toset([
    oci_core_instance.env_oci_instance_01.display_name,
    oci_core_instance.env_oci_instance_02.display_name,
    oci_core_instance.env_oci_instance_03.display_name,
    oci_core_instance.env_oci_instance_04.display_name
  ])
  query = "FilesystemUtilization[5m]{resourceName = \"${each.key}\"}.mean() > 85"
}

执行报错信息:

Error: 404-NotAuthorizedOrNotFound, Resource ocid1.onstopic.oc1.me-jeddah-1.aaaaaaaafdm2dzvukduuall5dd<truncated> could not be found or you are not authorized to access it.
│ Suggestion: Either the resource has been deleted or service Monitoring Alarm need policy to access this resource.
│ Provider version: 4.120.0, released on 2023-05-11.
│ Service: Monitoring Alarm
│ Operation Name: CreateAlarm
│ OPC request ID: c1f38e322c48c04acaab36db1baca20b/72E14735786558F3B/29692EC46A11C9C7A38BCF3CAC8ACC24
│
│
│   with module.Module_FS_Critical_env_oci_all_instance["instance_01"].oci_monitoring_alarm.tf_FS_Critical_FileSystem_alarm,
│   on ../Common/Module/FileSystem/fs.critical.tf line 18, in resource "oci_monitoring_alarm" "tf_FS_Critical_FileSystem_alarm":
│   18: resource "oci_monitoring_alarm" "tf_FS_Critical_FileSystem_alarm" {

已确认data块能正常获取主题ID,改用resource块仍报错,推测模块无法访问该主题,以下是排查解决思路:

  • 配置监控服务的IAM权限策略
    确保监控服务(Monitoring)拥有访问ONS主题的权限,需在OCI IAM中添加策略:

    Allow service monitoring to use ons-topics in compartment <目标 compartment 名称>
    

    注意策略的compartment要与ONS主题所在的compartment一致,若跨compartment配置,需确保策略覆盖对应范围。

  • 核对compartment一致性
    检查告警资源的compartment_id与ONS主题所在的compartment是否匹配。若告警和ONS主题不在同一compartment,除了上述监控服务的策略,还需确保执行Terraform的主体拥有跨compartment访问ONS主题的权限。

  • 验证Terraform身份凭证的权限
    使用执行Terraform的同一凭证,通过OCI CLI测试访问ONS主题:

    oci ons topic get --topic-id <你的ONS主题OCID>
    

    若返回权限错误,需给该凭证添加ONS_TOPIC_READ和ONS_TOPIC_USE权限;若能正常返回,再确认凭证是否拥有创建监控告警的权限。

  • 检查ONS主题状态
    登录OCI控制台,进入通知服务(Notifications),确认目标ONS主题状态为Active,未被删除或禁用。

  • 确认OCID完全匹配
    手动对比控制台中ONS主题的完整OCID与Terraform输出的OCID,避免因字符截断、复制错误导致资源不匹配。

内容的提问来源于stack exchange,提问作者doubando

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 15:55:05