You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Terraform中默认VPC与自定义VPC连接EC2的问题排查

问题修复方案

核心错误点

  1. vpc_security_group_ids 参数传值错误:该参数要求传入安全组的ID,但代码里用了aws_security_group.example.name(安全组名称),这是自定义VPC下报错的主要原因。
  2. EC2实例未指定子网:自定义VPC中创建EC2必须指定subnet_id,否则Terraform无法确定实例部署的子网。
  3. 硬编码VPC ID:安全组的vpc_id直接写死为vpc-xyz,改用变量可提升配置灵活性。
  4. 已定义变量未使用:声明了security_group_id变量但未实际调用,可按需调整。

修正后的完整代码

# 安全组资源
resource "aws_security_group" "example" {
  name        = "allow_specified_ports"
  vpc_id      = var.vpc_id  # 替换硬编码,改用变量
  description = "Allow specified inbound ports and all outbound traffic"

  # 入站规则
  dynamic "ingress" {
    for_each = var.security_group_ports
    content {
      from_port   = ingress.value
      to_port     = ingress.value
      protocol    = "tcp"
      cidr_blocks = ["0.0.0.0/0"]
    }
  }

  # 出站规则
  egress {
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }

  tags = {
    Name = "allow_specified_ports"
  }
}

# 公有子网EC2实例
resource "aws_instance" "ec2_public" {
  count         = var.instance_public_count
  instance_type = var.public_size
  subnet_id     = var.public_subnet_id  # 指定公有子网ID
  # 传入安全组ID而非名称
  vpc_security_group_ids = [aws_security_group.example.id]
  # 可选:公有子网实例需公网IP时添加
  associate_public_ip_address = true
}

# 私有子网EC2实例
resource "aws_instance" "ec2_private" {
  count         = var.instance_private_count
  instance_type = var.private_size
  subnet_id     = var.private_subnet_id  # 指定私有子网ID
  # 传入安全组ID而非名称
  vpc_security_group_ids = [aws_security_group.example.id]
}

# 变量定义
variable "instance_private_count" {
  type = number
}

variable "instance_public_count" {
  type = number
}

variable "public_subnet_id" {
  type = string
}

variable "private_subnet_id" {
  type = string
}

variable "security_group_id" {
  type    = string
  default = ""  # 设置默认值避免未传入报错
}

variable "vpc_id" {
  type = string
}

variable "public_size" {
  type = string
}

variable "private_size" {
  type = string
}

variable "security_group_ports" {
  type = list(number)
}

额外说明

  • 确保所有变量(如vpc_id、public_size等)都通过terraform.tfvars文件或命令行参数传入正确值。
  • 私有子网实例若需访问公网,需搭配NAT网关使用,此配置未包含该部分,可按需补充。

内容的提问来源于stack exchange,提问作者Malik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 22:45:25