Terraform Okta Provider:如何根据应用类型设置redirect_uris为可空?
Okta OAuth应用
redirect_uris条件必填配置问题 我正在使用Okta Provider实现app_oauth资源,其中redirect_uris属性仅对service类型应用非必填,其他类型应用均要求必填。
我尝试在vars.tf中做如下配置:
variable "type" { description = "应用类型" type = string nullable = false } variable "redirect_uris" { description = "应用重定向URI列表" type = list(string) nullable = var.type == "service" ? true : false }
执行terragrunt plan时触发以下错误:
Error: Variables not allowed │ │ on vars.tf line 23, in variable "redirect_uris": │ 23: nullable = var.type == "service" ? true : false │ │ Variables may not be used here. ╵ ╷ │ Error: Unsuitable value type │ │ on vars.tf line 23, in variable "redirect_uris": │ 23: nullable = var.type == "service" ? true : false │ │ Unsuitable value: value must be known
可行解决方案
将条件判断逻辑移到okta_app_oauth资源的属性赋值中,而非变量定义阶段:
resource "okta_app_oauth" "app" { label = var.label type = var.type grant_types = var.grant_types redirect_uris = var.type != "service" ? var.redirect_uris : null response_types = var.response_types }
Terraform不允许在变量的nullable参数中引用其他变量,因为变量定义的元参数必须在解析阶段确定,不能依赖运行时的变量值。通过在资源属性中使用三元表达式,当应用类型为service时传递null,既满足Okta Provider的非必填要求,其他类型则强制传入redirect_uris变量,符合必填约束。
内容的提问来源于stack exchange,提问作者Frendom
相关产品推荐
相关产品推荐

