Terraform导入AWS Transit Gateway Route失败,提示对象不存在
Transit Gateway Route导入Terraform项目失败求助
问题概述
尝试将现有AWS Transit Gateway Route导入到名为gateway的Terraform模块中,已核对路由表ID、目标CIDR块及AWS区域,但导入操作仍失败。
Gateway模块配置
resource "aws_ec2_transit_gateway" "tgw" { description = "gateway for vpn" tags = { "Name" = "openvpn-gateway" "managed_by_terraform" = "true" } } resource "aws_ec2_transit_gateway_vpc_attachment" "tgw-attachments-private-vpc" { transit_gateway_id = aws_ec2_transit_gateway.tgw.id vpc_id = var.private-vpc-id subnet_ids = var.private-vpc-subnets tags = { "Name" = "private-vpc-gateway-attachment" "managed_by_terraform" = "true" } } resource "aws_ec2_transit_gateway_route_table" "tgw-route-table" { transit_gateway_id = aws_ec2_transit_gateway.tgw.id tags = { "Name" = "openvpn-gateawy-route-table" "managed_by_terraform" = "true" } } resource "aws_ec2_transit_gateway_route" "private-vpc-route" { destination_cidr_block = var.private-vpc-cidr transit_gateway_attachment_id = aws_ec2_transit_gateway_vpc_attachment.tgw-attachments-private-vpc.id transit_gateway_route_table_id = aws_ec2_transit_gateway_route_table.tgw-route-table.id }
执行的导入命令
terraform import 'module.gateway.aws_ec2_transit_gateway_route.private-vpc-route' 'tgw-rtb-xxx_10.0.0.0/16'
错误提示
Error: Cannot import non-existent remote object
While attempting to import an existing object to "module.gateway.aws_ec2_transit_gateway_route.private-vpc-route", the provider detected that no object exists with the given id. Only pre-existing objects can be imported; check that the id is correct and that it is associated with the provider's configured region or endpoint, or use "terraform apply" to create a new remote object for this resource.
模块调用方式
module "vpc" { source = "../modules/vpc" public-subnets-name = var.public-subnets-name public-subnets-cidr = var.public-subnets-cidr private-cidr = var.private-cidr private-subnets-name = var.private-subnets-name private-subnets-cidr = var.private-subnets-cidr igw-id = module.gateway.igw-id private-igw-id = module.gateway.private-igw-id tg-id = module.gateway.tgw-id pcx-id = var.pcx-id nat-id = module.gateway.nat-id development-private-vpc-cidr = var.development-private-vpc-cidr } module "gateway" { source = "../modules/gateway" public-vpc-id = module.vpc.public-vpc-id public-vpc-cidr = var.public-cidr private-vpc-id = module.vpc.private-vpc-id private-vpc-cidr = var.private-cidr nat-subnet = module.vpc.private-vpcs_public-subnet-id nat-allocation = var.nat-allocation private-vpc-subnets = module.vpc.private-vpc-subnet_ids public-vpc-subnets = module.vpc.public-vpc-subnet_ids }
已完成的检查
- 确认Transit Gateway路由表ID(
tgw-rtb-xxx)正确 - 确认目标CIDR块(
10.0.0.0/16)正确 - 确认Terraform配置的AWS区域与资源所在区域一致
排查建议
- 验证路由实际存在性:用AWS CLI执行
aws ec2 search-transit-gateway-routes --transit-gateway-route-table-id tgw-rtb-xxx --filter Name=destination-cidr-block,Values=10.0.0.0/16,确认这条路由确实存在于指定路由表中。 - 调整导入ID格式:尝试用空格替换下划线分隔ID,或去掉引号:
terraform import module.gateway.aws_ec2_transit_gateway_route.private-vpc-route tgw-rtb-xxx 10.0.0.0/16。 - 检查路由类型:如果该路由是VPC attachment自动传播的路由,Terraform的
aws_ec2_transit_gateway_route仅支持管理静态路由,这类传播路由无法导入,需改用aws_ec2_transit_gateway_route_table_propagation管理。 - 核对资源地址拼写:确认导入命令中的资源地址
module.gateway.aws_ec2_transit_gateway_route.private-vpc-route与模块内资源名完全一致,无拼写错误。 - 验证AWS凭证权限:确保Terraform使用的凭证拥有
ec2:SearchTransitGatewayRoutes和ec2:DescribeTransitGatewayRoutes权限,避免因权限不足无法检测资源。
内容的提问来源于stack exchange,提问作者Çağrı BIYIK
相关产品推荐
相关产品推荐

