Terraform配置google_cloudfunctions_function时secret_environment_variables块报错
解决Terraform Google Provider中
secret_environment_variables块不支持的问题 报错原因
你使用的Google Provider v3.90.1版本中,google_cloudfunctions_function资源还未引入secret_environment_variables配置块——这个特性是在Provider v4.0.0及以上版本才新增的。旧版本不识别该块类型,因此触发了Unsupported block type错误。
解决办法
方案一:升级Google Provider到支持的版本
修改你的Provider配置文件(通常是versions.tf),指定最低版本为v4.0.0:
terraform { required_providers { google = { source = "hashicorp/google" version = ">= 4.0.0" } } }
执行以下命令完成Provider升级:
terraform init -upgrade
升级后即可正常使用secret_environment_variables块,你的原有代码无需大幅调整,只需修正secret字段的引用(比如替换为具体的Secret资源ID或名称):
secret_environment_variables { key = "KEY" secret = "projects/your-project/secrets/your-secret-name" version = "latest" }
方案二:不升级Provider,使用旧版本兼容写法
如果无法升级Provider,可通过environment_variables直接配置Secret Manager的完整资源路径来实现相同效果,格式为projects/<项目ID>/secrets/<密钥名称>/versions/<版本号>:
resource "google_cloudfunctions_function" "dbex-function" { name = "function-test" description = "My function" runtime = "python39" # 其他原有配置... entry_point = "dbex_conn" environment_variables = { TARGET = "test.com" KEY = "projects/your-project-id/secrets/your-secret-name/versions/latest" } }
注意:需确保Cloud Functions的服务账号拥有目标Secret的roles/secretmanager.secretAccessor权限,否则函数运行时无法读取密钥内容。
内容的提问来源于stack exchange,提问作者Keyur Shah
相关产品推荐
相关产品推荐

