Terragrunt跨模块传递敏感输出为敏感变量失败问题咨询
问题解答
核心疑问:依赖变量的来源
Terragrunt的dependency模块依赖项,是从依赖模块的Terraform状态文件中读取输出值,而非从terraform output命令生成的输出文件或控制台可见的输出内容。
报错原因
虽然你在database模块将password输出标记为sensitive = true,但该值依然会被Terraform写入状态文件中。报错的真实原因是:Terragrunt默认会自动过滤掉依赖模块的敏感输出,禁止直接通过dependency.database.outputs.password访问,因此才会提示该属性不存在。
解决方法
要允许Terragrunt访问依赖模块的敏感输出,只需在dependency配置块中添加skip_outputs_filter = true:
# terragrunt/_env/app.hcl dependency "database" { config_path = find_in_parent_folders("database") skip_outputs_filter = true # 添加这一行 } inputs = { db_password = dependency.database.outputs.password }
同时确保你的app模块变量db_password已正确设置sensitive = true(你当前的配置已经符合要求)。
内容的提问来源于stack exchange,提问作者tailaiw
相关产品推荐
相关产品推荐

