You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform导入AWS Transit Gateway Route失败,提示对象不存在

Transit Gateway Route导入Terraform项目失败求助

问题概述

尝试将现有AWS Transit Gateway Route导入到名为gateway的Terraform模块中,已核对路由表ID、目标CIDR块及AWS区域,但导入操作仍失败。

Gateway模块配置

resource "aws_ec2_transit_gateway" "tgw" {
  description = "gateway for vpn"
  
  tags = {
    "Name" = "openvpn-gateway"
    "managed_by_terraform" = "true"
  }
}

resource "aws_ec2_transit_gateway_vpc_attachment" "tgw-attachments-private-vpc" {
  transit_gateway_id = aws_ec2_transit_gateway.tgw.id
  vpc_id = var.private-vpc-id

  subnet_ids = var.private-vpc-subnets

  tags = {
    "Name" = "private-vpc-gateway-attachment"
    "managed_by_terraform" = "true"
  }
}

resource "aws_ec2_transit_gateway_route_table" "tgw-route-table" {
  transit_gateway_id = aws_ec2_transit_gateway.tgw.id

  tags = {
    "Name" = "openvpn-gateawy-route-table"
    "managed_by_terraform" = "true"
  }
}

resource "aws_ec2_transit_gateway_route" "private-vpc-route" {
  destination_cidr_block = var.private-vpc-cidr
  transit_gateway_attachment_id = aws_ec2_transit_gateway_vpc_attachment.tgw-attachments-private-vpc.id
  transit_gateway_route_table_id = aws_ec2_transit_gateway_route_table.tgw-route-table.id
}

执行的导入命令

terraform import 'module.gateway.aws_ec2_transit_gateway_route.private-vpc-route' 'tgw-rtb-xxx_10.0.0.0/16'

错误提示

Error: Cannot import non-existent remote object

While attempting to import an existing object to "module.gateway.aws_ec2_transit_gateway_route.private-vpc-route", the provider detected that no object exists with the given id. Only pre-existing objects can be imported; check that the id is correct and that it is associated with the provider's configured region or endpoint, or use "terraform apply" to create a new remote object for this resource.

模块调用方式

module "vpc" {
  source      = "../modules/vpc"
  public-subnets-name = var.public-subnets-name
  public-subnets-cidr = var.public-subnets-cidr
  private-cidr = var.private-cidr
  private-subnets-name = var.private-subnets-name
  private-subnets-cidr = var.private-subnets-cidr
  igw-id = module.gateway.igw-id
  private-igw-id = module.gateway.private-igw-id
  tg-id = module.gateway.tgw-id
  pcx-id = var.pcx-id
  nat-id = module.gateway.nat-id
  development-private-vpc-cidr = var.development-private-vpc-cidr
}

module "gateway" {
  source = "../modules/gateway"
  public-vpc-id = module.vpc.public-vpc-id
  public-vpc-cidr = var.public-cidr
  private-vpc-id = module.vpc.private-vpc-id
  private-vpc-cidr = var.private-cidr
  nat-subnet = module.vpc.private-vpcs_public-subnet-id
  nat-allocation = var.nat-allocation
  private-vpc-subnets = module.vpc.private-vpc-subnet_ids
  public-vpc-subnets = module.vpc.public-vpc-subnet_ids
}

已完成的检查

  • 确认Transit Gateway路由表ID(tgw-rtb-xxx)正确
  • 确认目标CIDR块(10.0.0.0/16)正确
  • 确认Terraform配置的AWS区域与资源所在区域一致

排查建议

  • 验证路由实际存在性:用AWS CLI执行aws ec2 search-transit-gateway-routes --transit-gateway-route-table-id tgw-rtb-xxx --filter Name=destination-cidr-block,Values=10.0.0.0/16,确认这条路由确实存在于指定路由表中。
  • 调整导入ID格式:尝试用空格替换下划线分隔ID,或去掉引号:terraform import module.gateway.aws_ec2_transit_gateway_route.private-vpc-route tgw-rtb-xxx 10.0.0.0/16。
  • 检查路由类型:如果该路由是VPC attachment自动传播的路由,Terraform的aws_ec2_transit_gateway_route仅支持管理静态路由,这类传播路由无法导入,需改用aws_ec2_transit_gateway_route_table_propagation管理。
  • 核对资源地址拼写:确认导入命令中的资源地址module.gateway.aws_ec2_transit_gateway_route.private-vpc-route与模块内资源名完全一致,无拼写错误。
  • 验证AWS凭证权限:确保Terraform使用的凭证拥有ec2:SearchTransitGatewayRoutes和ec2:DescribeTransitGatewayRoutes权限,避免因权限不足无法检测资源。

内容的提问来源于stack exchange,提问作者Çağrı BIYIK

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 11:56:35