如何在Terraform中按需为CloudFront配置可选的ordered_cache_behaviors?
实现Terraform CloudFront按需添加有序缓存行为
完全可以实现默认不生成任何ordered_cache_behavior,按需传入可空数组来添加指定行为的需求,核心是利用Terraform的dynamic块结合可空列表变量来实现动态生成。
具体实现步骤
1. 定义可空的有序缓存行为变量
首先在配置中定义一个类型为list(object)的变量,默认值设为空数组,这样默认情况下不会生成任何有序缓存行为:
variable "ordered_cache_behaviors" { type = list(object({ path_pattern = string allowed_methods = list(string) cached_methods = list(string) target_origin_id = string viewer_protocol_policy = string forwarded_values = object({ query_string = bool cookies = object({ forward = string }) }) # 按需添加其他需要的字段,比如compress、default_ttl等 })) default = [] description = "CloudFront有序缓存行为列表,默认不添加任何行为" }
2. 修改CloudFront资源配置,使用dynamic块生成行为
将原有硬编码的ordered_cache_behavior块替换为dynamic块,通过遍历上述变量来动态生成行为:
resource "aws_cloudfront_distribution" "proxy_cdn" { enabled = true price_class = "PriceClass_100" origin { origin_id = var.cdn_proxy_origin_id domain_name = var.cdn_domain_name custom_origin_config { origin_protocol_policy = "https-only" http_port = "80" https_port = "443" origin_ssl_protocols = ["TLSv1", "TLSv1.1", "TLSv1.2"] } } # 动态生成有序缓存行为:变量为空数组时,不会生成任何块 dynamic "ordered_cache_behavior" { for_each = var.ordered_cache_behaviors content { path_pattern = ordered_cache_behavior.value.path_pattern allowed_methods = ordered_cache_behavior.value.allowed_methods cached_methods = ordered_cache_behavior.value.cached_methods target_origin_id = ordered_cache_behavior.value.target_origin_id viewer_protocol_policy = ordered_cache_behavior.value.viewer_protocol_policy forwarded_values { query_string = ordered_cache_behavior.value.forwarded_values.query_string cookies { forward = ordered_cache_behavior.value.forwarded_values.cookies.forward } } } } default_cache_behavior { viewer_protocol_policy = "redirect-to-https" allowed_methods = ["GET", "HEAD", "OPTIONS", "PUT", "POST", "PATCH", "DELETE"] cached_methods = ["GET", "HEAD"] target_origin_id = var.cdn_proxy_origin_id forwarded_values { query_string = true cookies { forward = "all" } } } restrictions { geo_restriction { restriction_type = "none" } } viewer_certificate { acm_certificate_arn = aws_acm_certificate.proxy_certificate.arn ssl_support_method = "sni-only" } aliases = ["${var.proxy_subdomain}.myurl.com"] depends_on = [ aws_acm_certificate_validation.proxy_certificate_validation, ] }
关键说明
dynamic块的for_each绑定变量,当变量为空数组时,不会生成任何ordered_cache_behavior块,完美满足默认不添加的需求。- 变量的
object结构完全匹配ordered_cache_behavior的字段要求,确保传入的参数合法。 - 数组的顺序即为CloudFront有序缓存行为的优先级顺序,第一个元素优先级最高。
内容的提问来源于stack exchange,提问作者nolwww
相关产品推荐
相关产品推荐

