You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置GCP Cloud Armor策略报错:enforce_on_key_configs参数不被识别

解决Terraform Cloud Armor策略中enforce_on_key_configs参数报错问题

问题核心原因

你遇到的错误源于两个关键问题:

  1. 参数名称错误:Terraform Google Provider中对应的正确参数名是enforce_on_key_config(单数形式),而非你使用的enforce_on_key_configs(复数)
  2. 结构类型错误:该参数是嵌套块,不是键值对参数,不能用=赋值,必须以块的形式定义

修正后的Terraform代码片段

将你代码中rate_limit_options部分的错误代码替换为以下内容:

rate_limit_options {
    conform_action   = "allow"
    # 使用正确的嵌套块形式定义强制密钥配置
    enforce_on_key_config {
        enforce_on_key_type = "IP"
    }
    exceed_action    = "deny(479)"
    rate_limit_threshold {
        count        = 80
        interval_sec = 60
    }
    ban_duration_sec = 60
}

额外注意事项

  • Provider版本检查:确保你的Terraform Google Provider版本足够新(建议>=4.0.0),旧版本可能不支持enforce_on_key_config字段。可在versions.tf中指定版本:
    terraform {
      required_providers {
        google = {
          source  = "hashicorp/google"
          version = ">= 4.0.0"
        }
      }
    }
    
  • 状态同步:若升级Provider后资源状态仍未包含该字段,执行terraform refresh同步最新的GCP资源状态,再重新运行terraform plan

内容的提问来源于stack exchange,提问作者sainadh vennapusa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 09:27:07