Terragrunt管理Okta用户:custom_profile_attributes类型错误求助
问题分析与解决
错误的核心原因是Okta provider的custom_profile_attributes属性要求的是JSON格式的字符串,而非直接传入map类型。你之前的尝试中:
- 直接传map时,Terraform识别为map类型,不符合属性要求的string类型,报错;
- 把变量改为string后,在terragrunt里仍传入map,Terragrunt会将其转为非JSON格式的字符串(比如
map(tenant_id: ssotest)),同样不符合要求。
正确解决方案
1. 修正main.tf,将map转为JSON字符串
在资源定义中使用jsonencode函数,把传入的map变量序列化为符合要求的JSON字符串:
resource "okta_user" "user" { first_name = var.first_name last_name = var.last_name login = var.email email = var.email status = var.status custom_profile_attributes = jsonencode(var.custom_profile_attributes) }
2. 保持vars.tf的map类型定义
不需要修改变量类型,保持原有的map(any)即可,这样可以方便地在terragrunt中传入结构化的map数据:
variable "custom_profile_attributes" { description = "custom profile attributes" type = map(any) default = {} }
3. terragrunt.hcl的inputs保持不变
原来的map写法无需修改,Terragrunt会将这个map传递给Terraform变量,再通过jsonencode转为正确的JSON字符串:
inputs = { first_name = title(local.full_name[0]) last_name = title(local.full_name[1]) email = "${local.full_name[0]}.${local.full_name[1]}@company.com" status = "ACTIVE" groups = [dependency.team.outputs.okta_group_id] admin_roles = ["USER_ADMIN"] lifecycle = { ignore_changes = ["admin_roles"] } custom_profile_attributes = { "tenant_id" : "ssotest", } }
这样修改后,Terraform会自动将custom_profile_attributes的map转为{"tenant_id": "ssotest"}格式的JSON字符串,完全符合Okta provider的属性要求,执行terragrunt apply即可正常运行。
内容的提问来源于stack exchange,提问作者Frendom
相关产品推荐
相关产品推荐

