如何通过Terraform创建Amazon DocumentDB Elastic集群
使用Terraform创建AWS DocumentDB Elastic集群
目前AWS Terraform Provider中,专门用于创建DocumentDB Elastic集群的资源是aws_docdb_elastic_cluster,而非传统实例型集群使用的aws_docdb_cluster,你之前查看的文档仅覆盖了后者。
以下是基础的Terraform配置示例,可直接用于创建支持MongoDB分片API的DocumentDB Elastic集群:
terraform { required_providers { aws = { source = "hashicorp/aws" version = ">= 4.67.0" # 此资源在该版本后正式引入,需确保版本达标 } } } provider "aws" { region = "us-east-1" # 替换为你的目标AWS区域 } resource "aws_docdb_elastic_cluster" "my_elastic_cluster" { cluster_name = "docdb-elastic-sharded-cluster" admin_user_name = "cluster-admin" admin_user_password = "your-compliant-password" # 建议用Terraform变量/Secrets Manager存储,禁止硬编码 shard_count = 2 # 分片数量,决定数据分区能力 shard_capacity = 2 # 单分片资源规格,对应2vCPU+16GiB存储 vpc_security_group_ids = [aws_security_group.docdb_elastic_sg.id] subnet_ids = [aws_subnet.private_subnet_a.id, aws_subnet.private_subnet_b.id] } # 配套安全组配置(按需调整) resource "aws_security_group" "docdb_elastic_sg" { name = "docdb-elastic-access-sg" description = "Allow MongoDB client access to DocumentDB Elastic Cluster" vpc_id = aws_vpc.main.id # 替换为你的VPC ID ingress { from_port = 27017 to_port = 27017 protocol = "tcp" cidr_blocks = ["10.0.0.0/16"] # 替换为允许访问的客户端IP段 } egress { from_port = 0 to_port = 0 protocol = "-1" cidr_blocks = ["0.0.0.0/0"] } }
关键参数说明
shard_count:集群的分片总数,直接决定MongoDB分片API的可用能力shard_capacity:单分片的计算与存储资源配比,可选值为1、2、4、8、16vpc_security_group_ids/subnet_ids:必须指定私有子网,确保集群的网络安全性
注意事项
- 更新本地Terraform AWS Provider至指定版本以上,否则会识别不到
aws_docdb_elastic_cluster资源 - 敏感信息(如管理员密码)禁止硬编码,推荐使用
terraform variable结合环境变量,或集成AWS Secrets Manager管理 - 创建完成后,可通过
aws_docdb_elastic_cluster.my_elastic_cluster.cluster_endpoint获取集群连接地址,用于MongoDB客户端接入
内容的提问来源于stack exchange,提问作者Yagel
相关产品推荐
相关产品推荐

