You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform传递tfvar变量时EventBridge连接缺失必填字段问题排查

Terraform EventBridge Connection 配置错误排查

问题背景

项目结构:

\modules
 dev.tfvars
 \app
  \main
   main.tf, output.tf, providers.tf, variables.tf
  \sub-modules
   \eventbridge
    main.tf, output.tf, variables.tf

主模块和子模块的variables.tf均定义变量:

variable "secrets" {
    description = "map for secret manager"
    type = map(string)
}

顶层main.tf调用子模块:

module "a-eventbridge-trigger" {
    source          = "../sub-modules/eventbridge"
    secrets         = var.secrets
}

子模块main.tf中的资源配置:

resource "aws_cloudwatch_event_connection" "auth" {
  name               = "request-token"
  description        = "Gets token"
  authorization_type = "OAUTH_CLIENT_CREDENTIALS"

  auth_parameters {
    oauth {
      authorization_endpoint = "${var.apiurl}"
      http_method            = "POST"

      oauth_http_parameters {
        body {
          key             = "grant_type"
          value           = "client_credentials"
          is_value_secret = true
        }
        
        body {
          key             = "client_id"
          value           = var.secrets.Client_Id
          is_value_secret = true
        }
        
        body {
          key             = "client_secret"
          value           = var.secrets.Client_Secret
          is_value_secret = true
        }
      }
    }
  }
}

执行terraform apply时出现错误:

Error: error creating EventBridge connection (request-token): InvalidParameter: 2 validation error(s) found.
- missing required field, CreateConnectionInput.AuthParameters.OAuthParameters.ClientParameters.ClientID.
- missing required field, CreateConnectionInput.AuthParameters.OAuthParameters.ClientParameters.ClientSecret.

已知tfvars内容存在,顶层能输出完整secrets变量,子模块其他资源可正常使用该变量。


问题原因与解决方案

这是资源定义本身的问题,和变量传递无关。

AWS Provider的aws_cloudwatch_event_connection资源在使用OAUTH_CLIENT_CREDENTIALS授权类型时,要求在auth_parameters.oauth下显式配置client_parameters块来传递ClientID和ClientSecret,而不是将这两个参数放在oauth_http_parameters的body中。EventBridge会自动将client_parameters中的内容处理为OAuth请求的body参数,无需手动添加。

修正后的资源配置:

resource "aws_cloudwatch_event_connection" "auth" {
  name               = "request-token"
  description        = "Gets token"
  authorization_type = "OAUTH_CLIENT_CREDENTIALS"

  auth_parameters {
    oauth {
      authorization_endpoint = var.apiurl
      http_method            = "POST"

      # 新增client_parameters块传递凭证
      client_parameters {
        client_id     = var.secrets.Client_Id
        client_secret = var.secrets.Client_Secret
      }

      oauth_http_parameters {
        body {
          key             = "grant_type"
          value           = "client_credentials"
          is_value_secret = true
        }
      }
    }
  }
}

说明:

  • client_parameters是OAUTH_CLIENT_CREDENTIALS模式下的必填块,用于指定OAuth客户端的ID和密钥
  • 移除原来body中的client_id和client_secret配置,避免重复或冲突
  • 变量传递逻辑正常,因为子模块其他资源能正常使用secrets变量,排除变量传递类问题

内容的提问来源于stack exchange,提问作者Matt W

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 00:10:35