You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform关联已有安全组创建EKS集群失败问题排查

问题原因与修复方案

你使用的是terraform-aws-modules/eks/aws模块的v18.x版本,该版本对集群安全组的配置参数做了结构调整,不再支持顶层的create_cluster_security_group和cluster_security_group_id参数,这就是你报错和配置被忽略的核心原因。

修复步骤

将模块中原来的:

create_cluster_security_group=false ----------> ERROR: An argument named "cluster_create_security_group" is not expected here

cluster_security_group_id = "my-security-group-id"

替换为嵌套对象形式的cluster_security_group配置:

cluster_security_group = {
  create = false
  id     = "my-security-group-id" # 替换为你的现有安全组ID
}

完整修改后的模块配置片段

module "eks" {
  source  = "terraform-aws-modules/eks/aws"
  version = "~> 18.0"

  cluster_name    = "cluster-example"
  cluster_version = "1.21"

  cluster_endpoint_private_access = true
  cluster_endpoint_public_access  = true

  cluster_addons = {
    coredns = {
      resolve_conflicts = "OVERWRITE"
    }
    kube-proxy = {}
    vpc-cni = {
      resolve_conflicts = "OVERWRITE"
    }
  }

  vpc_id     = "vpc-12345"
  subnet_ids = ["subnet-123", "subnet-456", "subnet-789"]

  # 替换原来的两个参数为这个嵌套块
  cluster_security_group = {
    create = false
    id     = "my-security-group-id"
  }

  # EKS Managed Node Group(s)
  eks_managed_node_group_defaults = {
    disk_size      = 50
    instance_types = ["t3.medium"]
  }

  eks_managed_node_groups = {
    Test-Nodegroup = {
      min_size     = 2
      max_size     = 5
      desired_size = 2

      instance_types = ["t3.large"]
      capacity_type  = "SPOT"
    }
  }

  tags = {
    Environment = "dev"
    Terraform   = "true"
  }
}

额外说明

  • v18.x版本的EKS模块将集群安全组、节点安全组等相关配置改为嵌套对象结构,目的是让配置更模块化、清晰。
  • 确保你指定的现有安全组已配置EKS集群所需的必要规则(比如允许集群控制平面与节点通信、节点间通信等),否则可能导致集群无法正常运行。

内容的提问来源于stack exchange,提问作者Milos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 02:35:40