You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terragrunt跨模块传递敏感输出为敏感变量失败问题咨询

问题解答

核心疑问:依赖变量的来源

Terragrunt的dependency模块依赖项,是从依赖模块的Terraform状态文件中读取输出值,而非从terraform output命令生成的输出文件或控制台可见的输出内容。

报错原因

虽然你在database模块将password输出标记为sensitive = true,但该值依然会被Terraform写入状态文件中。报错的真实原因是:Terragrunt默认会自动过滤掉依赖模块的敏感输出,禁止直接通过dependency.database.outputs.password访问,因此才会提示该属性不存在。

解决方法

要允许Terragrunt访问依赖模块的敏感输出,只需在dependency配置块中添加skip_outputs_filter = true:

# terragrunt/_env/app.hcl
dependency "database" {
  config_path = find_in_parent_folders("database")
  skip_outputs_filter = true # 添加这一行
}

inputs = {
  db_password = dependency.database.outputs.password
}

同时确保你的app模块变量db_password已正确设置sensitive = true(你当前的配置已经符合要求)。

内容的提问来源于stack exchange,提问作者tailaiw

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 10:47:40