Terraform:在嵌套映射列表中为每个监听规则添加条件映射
解决Terraform监听规则添加HTTP Header条件的问题
问题核心
你当前的问题是修改https_listener_rules嵌套映射列表时,仅返回了conditions子列表,未保留完整的监听规则结构,同时存在类型不匹配错误。本质是没有正确遍历并重构整个规则对象,仅单独处理了conditions字段。
解决方案
1. 原始变量示例
假设你的初始变量定义如下:
variable "https_listener_rules" { type = list(object({ priority = number actions = list(object({ type = string target_group_arn = string })) conditions = list(object({ host_header = optional(list(string)) path_pattern = optional(list(string)) })) })) default = [ { priority = 10 actions = [ { type = "forward" target_group_arn = "arn:aws:elasticloadbalancing:us-east-1:123456789012:targetgroup/test1/abc123" } ] conditions = [ { host_header = ["example.com"] } ] }, { priority = 20 actions = [ { type = "forward" target_group_arn = "arn:aws:elasticloadbalancing:us-east-1:123456789012:targetgroup/test2/def456" } ] conditions = [ { path_pattern = ["/api/*"] } ] } ] }
2. 重构规则列表(添加HTTP Header条件)
通过for表达式遍历每个规则,保留所有原有字段,仅扩展conditions列表:
locals { updated_https_listener_rules = [ for rule in var.https_listener_rules : { # 保留原规则的全部字段 priority = rule.priority actions = rule.actions # 合并原有条件与新增的http_headers条件 conditions = concat( rule.conditions, [ { http_headers = [ { http_header_name = "X-Forwarded-For" values = ["192.168.0.0/16"] } ] } ] ) } ] }
3. 修正类型匹配问题
如果变量类型定义未包含http_headers,需要先更新类型约束:
variable "https_listener_rules" { type = list(object({ priority = number actions = list(object({ type = string target_group_arn = string })) conditions = list(object({ host_header = optional(list(string)) path_pattern = optional(list(string)) http_headers = optional(list(object({ http_header_name = string values = list(string) }))) })) })) # default值保持不变 }
4. 在资源中使用更新后的规则
通过for_each和dynamic块实现灵活配置:
resource "aws_lb_listener_rule" "example" { for_each = { for idx, rule in local.updated_https_listener_rules : idx => rule } listener_arn = aws_lb_listener.example.arn priority = each.value.priority action { type = each.value.actions[0].type target_group_arn = each.value.actions[0].target_group_arn } dynamic "condition" { for_each = each.value.conditions content { dynamic "host_header" { for_each = condition.value.host_header != null ? [condition.value.host_header] : [] content { values = host_header.value } } dynamic "path_pattern" { for_each = condition.value.path_pattern != null ? [condition.value.path_pattern] : [] content { values = path_pattern.value } } dynamic "http_header" { for_each = condition.value.http_headers != null ? condition.value.http_headers : [] content { http_header_name = http_header.value.http_header_name values = http_header.value.values } } } } }
关键注意事项
- 必须完整重构每个规则对象,不能仅返回
conditions字段 - 使用
concat函数合并条件列表,保证结构一致性 - 提前更新变量类型约束,避免类型不匹配错误
- 用
dynamic块处理可选条件类型,适配不同规则的条件组合
内容的提问来源于stack exchange,提问作者Nelfo
相关产品推荐
相关产品推荐

