You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform Okta Provider:如何根据应用类型设置redirect_uris为可空?

Okta OAuth应用redirect_uris条件必填配置问题

我正在使用Okta Provider实现app_oauth资源,其中redirect_uris属性仅对service类型应用非必填,其他类型应用均要求必填。

我尝试在vars.tf中做如下配置:

variable "type" {
  description = "应用类型"
  type        = string
  nullable    = false
}

variable "redirect_uris" {
  description = "应用重定向URI列表"
  type        = list(string)
  nullable    = var.type == "service" ? true : false
}

执行terragrunt plan时触发以下错误:

Error: Variables not allowed
│ 
│   on vars.tf line 23, in variable "redirect_uris":
│   23:   nullable    = var.type == "service" ? true : false
│ 
│ Variables may not be used here.
╵

╷
│ Error: Unsuitable value type
│ 
│   on vars.tf line 23, in variable "redirect_uris":
│   23:   nullable    = var.type == "service" ? true : false
│ 
│ Unsuitable value: value must be known

可行解决方案

将条件判断逻辑移到okta_app_oauth资源的属性赋值中,而非变量定义阶段:

resource "okta_app_oauth" "app" {
  label          = var.label
  type           = var.type
  grant_types    = var.grant_types
  redirect_uris  = var.type != "service" ? var.redirect_uris : null
  response_types = var.response_types
}

Terraform不允许在变量的nullable参数中引用其他变量,因为变量定义的元参数必须在解析阶段确定,不能依赖运行时的变量值。通过在资源属性中使用三元表达式,当应用类型为service时传递null,既满足Okta Provider的非必填要求,其他类型则强制传入redirect_uris变量,符合必填约束。

内容的提问来源于stack exchange,提问作者Frendom

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 05:05:18