You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否通过Terraform为Google Cloud Functions Gen2配置密钥?

Google Cloud Functions Gen2 用Terraform配置密钥

可以在main.tf中为Cloud Functions Gen2配置密钥,配置逻辑和Gen1类似,但需要适配Gen2的资源结构——密钥环境变量需要定义在service_config块内部的secret_environment_variables中。

以下是修改后的完整示例代码:

resource "google_cloudfunctions2_function" "function" {
  name        = "function"
  location    = "us-central1"
  description = "a new function"

  build_config {
    runtime        = "nodejs16"
    entry_point    = "helloPubSub"
    environment_variables = {
      BUILD_CONFIG_TEST = "build_test"
    }
    source {
      storage_source {
        bucket = google_storage_bucket.bucket.name
        object = google_storage_bucket_object.object.name
      }
    }
  }

  service_config {
    max_instance_count             = 3
    min_instance_count             = 1
    available_memory               = "256M"
    timeout_seconds                = 60
    environment_variables          = {
      SERVICE_CONFIG_TEST = "config_test"
    }
    ingress_settings               = "ALLOW_INTERNAL_ONLY"
    all_traffic_on_latest_revision = true
    service_account_email          = google_service_account.account.email

    # 配置密钥环境变量
    secret_environment_variables {
      key    = "myvar"
      secret = "mysecret_id"
      # 可选:指定密钥版本,不填默认使用最新版本
      # version = "latest"
    }
  }

  event_trigger {
    trigger_region = "us-central1"
    event_type     = "google.cloud.pubsub.topic.v1.messagePublished"
    pubsub_topic   = google_pubsub_topic.topic.id
    retry_policy   = "RETRY_POLICY_RETRY"
  }
}

配置字段说明:

  • key:云函数运行时可读取的环境变量名称
  • secret:Google Secret Manager中存储的密钥ID
  • version(可选):指定要使用的密钥版本,默认值为latest(即最新版本)

内容的提问来源于stack exchange,提问作者gamble27

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 09:10:28