如何在Terraform中将Aurora生成的密钥名称传入Lambda环境变量
解决Terraform Aurora模块Secret传入Lambda环境变量的类型错误问题
当你用terraform-aws-modules/rds-aurora/aws模块开启manage_master_user_password=true后,cluster_master_user_secret返回的是一个列表对象(而非单个字符串),每个列表元素包含secret_name、secret_arn等属性,直接传入Lambda环境变量会因为类型不匹配报错。
解决步骤
直接提取列表中第一个元素的secret_name字段即可,单Aurora集群场景下这个列表只会有一个元素:
resource "aws_lambda_function" "your_lambda" { # 省略其他必填配置(如filename、role、runtime等) environment { variables = { DB_CREDENTIALS_SECRET_NAME = module.rds.cluster_master_user_secret[0].secret_name } } }
额外说明
- 如果需要兼容多集群场景(少见),可以用
element函数安全获取第一个元素:DB_CREDENTIALS_SECRET_NAME = element(module.rds.cluster_master_user_secret, 0).secret_name - 你可以通过
terraform console命令验证结构:执行后输入module.rds.cluster_master_user_secret,就能看到完整的对象结构,确认secret_name字段存在。
内容的提问来源于stack exchange,提问作者Kashiiif3
相关产品推荐
相关产品推荐

