You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

执行Terraform Apply后无修改仍需Update的原因排查

问题:Terraform apply后未修改配置,执行plan却提示aws_route资源原地更新

配置代码

resource "aws_route_table" "rt_for_private_subnet" {
  vpc_id = aws_vpc.my_vpc.id

  tags = {
    Name = "rt_for_private_subnet"
  }
}

resource "aws_route_table_association" "private" {
  subnet_id      = aws_subnet.private_subnet.id
  route_table_id = aws_route_table.rt_for_private_subnet.id
}

resource "aws_route" "private_route-1" {
  route_table_id         = aws_route_table.rt_for_private_subnet.id
  destination_cidr_block = "0.0.0.0/0"
  gateway_id             = aws_nat_gateway.my_nat_gw.id
}

执行plan结果

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  ~ update in-place

Terraform will perform the following actions:

  # aws_route.private_route-1 will be updated in-place
  ~ resource "aws_route" "private_route-1" {
      + gateway_id             = "nat-098147d3e6b748323"
        id                     = "r-rtb-06e149dbb8685ec071080289494"
      - nat_gateway_id         = "nat-098147d3e6b748323" -> null
        # (4 unchanged attributes hidden)
    }

Plan: 0 to add, 1 to change, 0 to destroy.

问题原因

这是因为你混淆了AWS路由资源中不同目标类型对应的配置字段:

  • gateway_id字段专门用于关联Internet Gateway(IGW)
  • nat_gateway_id字段才是关联NAT Gateway的正确字段

虽然AWS API在你传入gateway_id为NAT网关ID时会做兼容处理,实际将路由关联到NAT网关,但Terraform读取远程资源状态时,会发现远程资源的nat_gateway_id字段有值,而本地配置里写的是gateway_id,两者字段不匹配,因此生成了这个看似矛盾的更新计划。

本质是配置字段使用错误,若按此计划执行,会导致路由失效——gateway_id无法正确关联NAT网关。

内容的提问来源于stack exchange,提问作者Red Hat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 07:07:19