You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform导入EC2后Plan显示UserData变更但无实际修改的问题排查

导入EC2实例后Terraform Plan显示UserData哈希变更排查请求

我们正在通过Terraform将EC2实例导入基础设施即代码体系,导入操作成功后运行terraform plan,发现输出中显示UserData的哈希值存在变更,但我们并未对UserData相关内容做任何修改。以下是相关配置代码、导入输出及Plan输出,请求协助排查问题原因,如需更多信息请告知。

配置文件

module.tf

module "ec2_app_demo" {
  source = "./aws-ec2-application/"
  ec2_instances     = var.ec2_instances

}

main.tf

resource "aws_instance" "instances" {
  for_each = { for instance in var.ec2_instances : instance.name => instance }

  ami                    = each.value.ami
  instance_type          = each.value.type
  key_name               = each.value.key_name
  subnet_id              = join("\"", "", data.aws_subnet_ids.subnet_id["${each.value.subnet_name}"].ids)
  user_data = each.value.user_data != "" ? file("${path.module}/../${each.value.user_data}") : null
  vpc_security_group_ids = data.aws_security_groups.sg_id[each.value.name].ids
  secondary_private_ips  = each.value.secondary_private_ips
  iam_instance_profile   = each.value.instance_profile
  disable_api_termination = each.value.disable_api_termination

  root_block_device  {
    volume_type = each.value.root_block_device_volume_type
    volume_size = each.value.root_block_device_volume_size
    # tags = each.value.tags
    tags = each.value.tags_root_volume
    kms_key_id = each.value.kms_key != "" ? each.value.kms_key : null
    
  }

  tags = each.value.tags

}

tfvars 文件

ec2_instances=[ {
    "additional_eni": 0,
    "ami": "ami-xxxxx",
    "disable_api_termination": true,
    "instance_profile": "iam-profile-ec2",
    "key_name": "keypair",
    "kms_key": "",
    "name": "Iacshell",
    "root_block_device_volume_size": 300,
    "root_block_device_volume_type": "gp3",
    "secondary_private_ips": [],
    "security_groups": [],
    "subnet_name": "Test-VPC-Subnet1A",
    "tags": {
      "Environment": "dev",
    },
    "tags_root_volume": {
      "Budget": "IaC",
      "Environment": "dev",
    },
    "type": "m5.2xlarge",
    "user_data": "Iacshell.sh",
    "vpc_name": "Test-VPC"
  }
]

导入操作输出

[0m[0m
[0m[1mmodule.ec2_app_demo.aws_instance.instances["Iacshell"]: Importing from ID "i-0a6833b201f1fea6a"...[0m
[0m[1m[32mmodule.ec2_app_demo.aws_instance.instances["Iacshell"]: Import prepared![0m
[0m[32m  Prepared aws_instance for import[0m
[0m[1mmodule.ec2_app_demo.aws_instance.instances["Iacshell"]: Refreshing state... [id=i-0a6833b201f1fea6a][0m
[0m[32m
Import successful!

Terraform Plan 输出

Terraform will perform the following actions:

  # module.ec2_app_demo.aws_instance.instances["devmedagent01"] will be updated in-place
  ~ resource "aws_instance" "instances" {
        id                                   = "i-0a6833b201f1fea6a"
        tags                                 = {
            "Environment"    = "dev"
        }
      ~ user_data                            = "af77afc8379a0a220e8772fd5d8670d66d12978f" -> "f543ec5ca251db148930f92e4bad4de6705f2dd6"
      + user_data_replace_on_change          = false
        # (29 unchanged attributes hidden)
        # (9 unchanged blocks hidden)
    }

Plan: 0 to add, 1 to change, 0 to destroy.

Iacshell.sh 内容

#!/bin/bash
#echo "sshd_config";;
sed -i 's|PasswordAuthentication no|PasswordAuthentication yes|g' /etc/ssh/sshd_config ;
sed -i 's|#PubkeyAuthentication yes|PubkeyAuthentication yes|g' /etc/ssh/sshd_config ;
sed -i 's|PermitRootLogin no|PermitRootLogin yes|g' /etc/ssh/sshd_config ;
systemctl restart sshd;
echo "g0tsh0t3" | passwd --stdin root
hostnamectl set-hostname iacshell.xxx.com
echo "HOSTNAME=Iacshell" >>/etc/sysconfig/network
yum install nmve-cli lvm2 -y

内容的提问来源于stack exchange,提问作者Maya Ray

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 01:20:42