You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

导入aws_iam_role_policy报错:无法找到对应远程对象求助

问题:Terragrunt导入IAM角色内联策略失败,提示找不到远程对象

使用Terragrunt管理基础设施,执行以下导入命令时持续报错:

terragrunt import aws_iam_role_policy.aws_load_balancer_controller cp-sw-ore-nonprod-aws-load-balancer-controller:cp-sw-ore-nonprod-alb-management

当前环境:Terraform 0.14.5、AWS Provider 4.29(需保留版本)

报错详情

WARN[0039] No double-slash (//) found in source URL /koralkloud/tg-module-eks.git. Relative paths in downloaded Terraform code may not work. 
aws_iam_role_policy.aws_load_balancer_controller: Importing from ID "cp-sw-ore-nonprod-aws-load-balancer-controller:cp-sw-ore-nonprod-alb-management"...
aws_iam_role_policy.aws_load_balancer_controller: Import prepared!
  Prepared aws_iam_role_policy for import
aws_iam_role_policy.aws_load_balancer_controller: Refreshing state... [id=cp-sw-ore-nonprod-aws-load-balancer-controller:cp-sw-ore-nonprod-alb-management]

Error: Cannot import non-existent remote object

While attempting to import an existing object to
aws_iam_role_policy.aws_load_balancer_controller, the provider detected that
no object exists with the given id. Only pre-existing objects can be imported;
check that the id is correct and that it is associated with the provider's
configured region or endpoint, or use "terraform apply" to create a new remote
object for this resource.

Releasing state lock. This may take a few moments...
ERRO[0047] 1 error occurred:
    * exit status 1

解决方案

  • 验证导入ID的正确性
    aws_iam_role_policy的导入ID格式为角色名:内联策略名,需严格匹配:

    1. 用AWS CLI确认角色存在:
      aws iam get-role --role-name cp-sw-ore-nonprod-aws-load-balancer-controller
      
    2. 列出角色下的所有内联策略,确认目标策略名在列表中(注意大小写敏感):
      aws iam list-role-policies --role-name cp-sw-ore-nonprod-aws-load-balancer-controller
      
  • 检查AWS区域配置
    确保Terragrunt使用的AWS区域与IAM角色/策略所在区域一致:

    • 查看terragrunt.hcl中的provider区域配置
    • 或通过环境变量指定区域后重试:
      export AWS_DEFAULT_REGION=us-west-2 # 替换为实际区域
      terragrunt import aws_iam_role_policy.aws_load_balancer_controller cp-sw-ore-nonprod-aws-load-balancer-controller:cp-sw-ore-nonprod-alb-management
      
  • 修复模块源URL警告
    虽然警告不直接导致导入失败,但可能影响模块加载。将模块源修改为带协议头和双斜杠的格式,例如:

    source = "git::https://koralkloud/tg-module-eks.git//path/to/submodule" # 补充//和子模块路径(如果有)
    
  • 确认Terraform资源定义匹配
    检查代码中aws_iam_role_policy的参数是否与实际资源一致:

    resource "aws_iam_role_policy" "aws_load_balancer_controller" {
      role   = "cp-sw-ore-nonprod-aws-load-balancer-controller" # 或关联对应的aws_iam_role资源的name属性
      name   = "cp-sw-ore-nonprod-alb-management"
      policy = jsonencode(...)
    }
    
  • 刷新状态后重试
    执行状态刷新清除缓存,再重新导入:

    terragrunt refresh
    terragrunt import aws_iam_role_policy.aws_load_balancer_controller cp-sw-ore-nonprod-aws-load-balancer-controller:cp-sw-ore-nonprod-alb-management
    

内容的提问来源于stack exchange,提问作者Muneeshpandi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 20:17:33