You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置google_cloudfunctions_function时secret_environment_variables块报错

解决Terraform Google Provider中secret_environment_variables块不支持的问题

报错原因

你使用的Google Provider v3.90.1版本中,google_cloudfunctions_function资源还未引入secret_environment_variables配置块——这个特性是在Provider v4.0.0及以上版本才新增的。旧版本不识别该块类型,因此触发了Unsupported block type错误。

解决办法

方案一:升级Google Provider到支持的版本

修改你的Provider配置文件(通常是versions.tf),指定最低版本为v4.0.0:

terraform {
  required_providers {
    google = {
      source  = "hashicorp/google"
      version = ">= 4.0.0"
    }
  }
}

执行以下命令完成Provider升级:

terraform init -upgrade

升级后即可正常使用secret_environment_variables块,你的原有代码无需大幅调整,只需修正secret字段的引用(比如替换为具体的Secret资源ID或名称):

secret_environment_variables {  
  key     = "KEY"
  secret  = "projects/your-project/secrets/your-secret-name"
  version = "latest"
 }

方案二:不升级Provider,使用旧版本兼容写法

如果无法升级Provider,可通过environment_variables直接配置Secret Manager的完整资源路径来实现相同效果,格式为projects/<项目ID>/secrets/<密钥名称>/versions/<版本号>:

resource "google_cloudfunctions_function" "dbex-function" {
  name        = "function-test"
  description = "My function"
  runtime     = "python39"
  # 其他原有配置...
  entry_point  = "dbex_conn"

  environment_variables = {
    TARGET = "test.com"
    KEY    = "projects/your-project-id/secrets/your-secret-name/versions/latest"
  }
}

注意:需确保Cloud Functions的服务账号拥有目标Secret的roles/secretmanager.secretAccessor权限,否则函数运行时无法读取密钥内容。

内容的提问来源于stack exchange,提问作者Keyur Shah

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 17:35:30