You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform:在嵌套映射列表中为每个监听规则添加条件映射

解决Terraform监听规则添加HTTP Header条件的问题

问题核心

你当前的问题是修改https_listener_rules嵌套映射列表时,仅返回了conditions子列表,未保留完整的监听规则结构,同时存在类型不匹配错误。本质是没有正确遍历并重构整个规则对象,仅单独处理了conditions字段。

解决方案

1. 原始变量示例

假设你的初始变量定义如下:

variable "https_listener_rules" {
  type = list(object({
    priority                = number
    actions                 = list(object({
      type               = string
      target_group_arn   = string
    }))
    conditions              = list(object({
      host_header        = optional(list(string))
      path_pattern       = optional(list(string))
    }))
  }))
  default = [
    {
      priority = 10
      actions = [
        {
          type             = "forward"
          target_group_arn = "arn:aws:elasticloadbalancing:us-east-1:123456789012:targetgroup/test1/abc123"
        }
      ]
      conditions = [
        {
          host_header = ["example.com"]
        }
      ]
    },
    {
      priority = 20
      actions = [
        {
          type             = "forward"
          target_group_arn = "arn:aws:elasticloadbalancing:us-east-1:123456789012:targetgroup/test2/def456"
        }
      ]
      conditions = [
        {
          path_pattern = ["/api/*"]
        }
      ]
    }
  ]
}

2. 重构规则列表(添加HTTP Header条件)

通过for表达式遍历每个规则,保留所有原有字段,仅扩展conditions列表:

locals {
  updated_https_listener_rules = [
    for rule in var.https_listener_rules : {
      # 保留原规则的全部字段
      priority = rule.priority
      actions  = rule.actions
      # 合并原有条件与新增的http_headers条件
      conditions = concat(
        rule.conditions,
        [
          {
            http_headers = [
              {
                http_header_name = "X-Forwarded-For"
                values           = ["192.168.0.0/16"]
              }
            ]
          }
        ]
      )
    }
  ]
}

3. 修正类型匹配问题

如果变量类型定义未包含http_headers,需要先更新类型约束:

variable "https_listener_rules" {
  type = list(object({
    priority                = number
    actions                 = list(object({
      type               = string
      target_group_arn   = string
    }))
    conditions              = list(object({
      host_header        = optional(list(string))
      path_pattern       = optional(list(string))
      http_headers       = optional(list(object({
        http_header_name = string
        values           = list(string)
      })))
    }))
  }))
  # default值保持不变
}

4. 在资源中使用更新后的规则

通过for_each和dynamic块实现灵活配置:

resource "aws_lb_listener_rule" "example" {
  for_each             = { for idx, rule in local.updated_https_listener_rules : idx => rule }
  listener_arn         = aws_lb_listener.example.arn
  priority             = each.value.priority

  action {
    type               = each.value.actions[0].type
    target_group_arn   = each.value.actions[0].target_group_arn
  }

  dynamic "condition" {
    for_each = each.value.conditions
    content {
      dynamic "host_header" {
        for_each = condition.value.host_header != null ? [condition.value.host_header] : []
        content {
          values = host_header.value
        }
      }

      dynamic "path_pattern" {
        for_each = condition.value.path_pattern != null ? [condition.value.path_pattern] : []
        content {
          values = path_pattern.value
        }
      }

      dynamic "http_header" {
        for_each = condition.value.http_headers != null ? condition.value.http_headers : []
        content {
          http_header_name = http_header.value.http_header_name
          values           = http_header.value.values
        }
      }
    }
  }
}

关键注意事项

  • 必须完整重构每个规则对象,不能仅返回conditions字段
  • 使用concat函数合并条件列表,保证结构一致性
  • 提前更新变量类型约束,避免类型不匹配错误
  • 用dynamic块处理可选条件类型,适配不同规则的条件组合

内容的提问来源于stack exchange,提问作者Nelfo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 13:34:57