Terraform部署AWS EKS时aws-auth ConfigMap不存在问题求助
AWS EKS Terraform模块部署报错:"aws-auth" ConfigMap不存在
问题概述
使用terraform-aws-modules/eks/aws模块部署EKS 1.24集群,已设置manage_aws_auth_configmap = true并传入自定义IAM角色映射,terraform init执行正常,但terraform plan和apply时均报错提示The configmap "aws-auth" does not exist,预期模块会自动创建该ConfigMap,尝试社区同类解决方案未解决,需排查问题。
核心模块代码片段
module "eks" { source = "terraform-aws-modules/eks/aws" cluster_version = "1.24" # 省略其他配置项 manage_aws_auth_configmap = true aws_auth_roles = var.map_roles }
变量定义
variable "map_roles" { description = "List of role maps to add to the aws_auth configmap" type = list(object({ rolearn = string username = string groups = list(string) })) default = [] }
变量取值示例
map_roles = [ { rolearn = "arn:aws:iam::*account_id*:role/QADevelopersRole" username = "QADevelopersRole" groups = ["system:masters"] } ]
错误日志
Error: The configmap "aws-auth" does not exist with module.eks.kubernetes_config_map_v1_data.aws_auth[0], on .terraform/modules/eks/main.tf line 527, in resource "kubernetes_config_map_v1_data" "aws_auth": 527: resource "kubernetes_config_map_v1_data" "aws_auth" {
排查与解决步骤
- 检查模块版本兼容性:EKS 1.24需匹配对应版本的
terraform-aws-eks模块,建议使用v19.x系列版本(该版本适配Kubernetes 1.21-1.24),版本不匹配可能导致ConfigMap创建逻辑异常。 - 确认资源依赖顺序:检查模块内
kubernetes_config_map_v1_data.aws_auth资源是否正确依赖aws_eks_cluster.this的就绪状态,确保集群完全创建完成后再操作ConfigMap。若手动配置了Kubernetes Provider,需添加依赖声明:provider "kubernetes" { host = module.eks.cluster_endpoint cluster_ca_certificate = base64decode(module.eks.cluster_certificate_authority_data) token = data.aws_eks_cluster_auth.this.token depends_on = [module.eks.aws_eks_cluster] } - 清理异常Terraform状态:执行
terraform state list查看是否存在残留的kubernetes_config_map或kubernetes_config_map_v1_data资源,若有则执行terraform state rm <资源路径>移除后重新执行plan/apply。 - 验证IAM权限:确保部署Terraform使用的IAM角色拥有
eks:DescribeCluster权限,以及Kubernetes集群中configmaps的读写权限。 - 临时应急方案:先注释
manage_aws_auth_configmap = true和aws_auth_roles配置,执行apply创建基础集群;待集群就绪后恢复注释内容,再次执行apply完成auth配置。
内容的提问来源于stack exchange,提问作者James
相关产品推荐
相关产品推荐

