You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terragrunt管理Okta用户:custom_profile_attributes类型错误求助

问题分析与解决

错误的核心原因是Okta provider的custom_profile_attributes属性要求的是JSON格式的字符串,而非直接传入map类型。你之前的尝试中:

  • 直接传map时,Terraform识别为map类型,不符合属性要求的string类型,报错;
  • 把变量改为string后,在terragrunt里仍传入map,Terragrunt会将其转为非JSON格式的字符串(比如map(tenant_id: ssotest)),同样不符合要求。

正确解决方案

1. 修正main.tf,将map转为JSON字符串

在资源定义中使用jsonencode函数,把传入的map变量序列化为符合要求的JSON字符串:

resource "okta_user" "user" {
  first_name                = var.first_name
  last_name                 = var.last_name
  login                     = var.email
  email                     = var.email
  status                    = var.status
  custom_profile_attributes = jsonencode(var.custom_profile_attributes)
}

2. 保持vars.tf的map类型定义

不需要修改变量类型,保持原有的map(any)即可,这样可以方便地在terragrunt中传入结构化的map数据:

variable "custom_profile_attributes" {
  description = "custom profile attributes"
  type        = map(any)
  default     = {}
}

3. terragrunt.hcl的inputs保持不变

原来的map写法无需修改,Terragrunt会将这个map传递给Terraform变量,再通过jsonencode转为正确的JSON字符串:

inputs = {
  first_name  = title(local.full_name[0])
  last_name   = title(local.full_name[1])
  email       = "${local.full_name[0]}.${local.full_name[1]}@company.com"
  status      = "ACTIVE"
  groups      = [dependency.team.outputs.okta_group_id]
  admin_roles = ["USER_ADMIN"]
  lifecycle = {
    ignore_changes = ["admin_roles"]
  }
  custom_profile_attributes = {
    "tenant_id" : "ssotest",
  }
}

这样修改后,Terraform会自动将custom_profile_attributes的map转为{"tenant_id": "ssotest"}格式的JSON字符串,完全符合Okta provider的属性要求,执行terragrunt apply即可正常运行。

内容的提问来源于stack exchange,提问作者Frendom

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 23:43:28