You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置AWS站点到站点VPN时遇不可配置属性错误

问题描述

我是Terraform新手,此前使用过程均正常,但在配置站点到站点VPN时,尝试指定内部IP地址遇到问题。删除代码最后4行(指定tunnel1_cgw_inside_address等属性的代码)后配置可正常运行;保留则触发如下错误:

Error: Value for unconfigurable attribute
│
│   with aws_vpn_connection.vpn_home,
│   on main.tf line 194, in resource "aws_vpn_connection" "vpn_home":
│  194:   tunnel1_cgw_inside_address = "169.254.47.238"
│
│ Can't configure a value for "tunnel1_cgw_inside_address": its value will be decided automatically based on the result
│ of applying this configuration.
╵
╷
│ Error: Value for unconfigurable attribute
│
│   with aws_vpn_connection.vpn_home,
│   on main.tf line 195, in resource "aws_vpn_connection" "vpn_home":
│  195:   tunnel1_vgw_inside_address = "169.254.47.237"
│
│ Can't configure a value for "tunnel1_vgw_inside_address": its value will be decided automatically based on the result
│ of applying this configuration.
╵
╷
│ Error: Value for unconfigurable attribute
│
│   with aws_vpn_connection.vpn_home,
│   on main.tf line 196, in resource "aws_vpn_connection" "vpn_home":
│  196:   tunnel2_cgw_inside_address = "169.254.47.242"
│
│ Can't configure a value for "tunnel2_cgw_inside_address": its value will be decided automatically based on the result
│ of applying this configuration.
╵
╷
│ Error: Value for unconfigurable attribute
│
│   with aws_vpn_connection.vpn_home,
│   on main.tf line 197, in resource "aws_vpn_connection" "vpn_home":
│  197:   tunnel2_vgw_inside_address = "169.254.47.241"
│
│ Can't configure a value for "tunnel2_vgw_inside_address": its value will be decided automatically based on the result
│ of applying this configuration.

我的Terraform配置代码如下:

# Attach  TGW to Edge VPC
resource "aws_ec2_transit_gateway_vpc_attachment" "tgw_attach_edge" {
  subnet_ids         = [aws_subnet.subnet-01.id ]
  transit_gateway_id = aws_ec2_transit_gateway.demo_tgw.id
  vpc_id = aws_vpc.Prod-VPC-01.id
}

resource "aws_customer_gateway" "main" {
  bgp_asn    = 65000
  ip_address = "x.x.x.x"
  type       = "ipsec.1"
  tags = {
    Name = "House-test"
  }
}
resource "aws_vpn_connection" "vpn_home" {
  customer_gateway_id = aws_customer_gateway.main.id
  transit_gateway_id = aws_ec2_transit_gateway.demo_tgw.id
  type                = aws_customer_gateway.main.type

  static_routes_only  = true
  local_ipv4_network_cidr = "10.0.0.0/16"
  remote_ipv4_network_cidr  = "10.16.0.0/16"
  tunnel1_preshared_key = "###########"
  tunnel2_preshared_key = "###########"
  tunnel1_inside_cidr = "169.254.47.148/30"
  tunnel2_inside_cidr = "169.254.47.152/30"
  tunnel1_cgw_inside_address = "169.254.47.238"
  tunnel1_vgw_inside_address = "169.254.47.237"
  tunnel2_cgw_inside_address = "169.254.47.242"
  tunnel2_vgw_inside_address = "169.254.47.241"
}
解决办法

tunnel1_cgw_inside_address、tunnel1_vgw_inside_address、tunnel2_cgw_inside_address、tunnel2_vgw_inside_address属于只读属性,Terraform会在VPN连接创建完成后自动分配这些值,用户无法手动配置。

你已经通过tunnel1_inside_cidr和tunnel2_inside_cidr指定了隧道的内部CIDR段,AWS会自动从这些CIDR中分配对应的客户网关(CGW)和中转网关(TGW)内部地址,无需手动指定具体IP。

直接删除这4行手动指定IP的代码即可正常完成配置。如果后续需要获取这些自动生成的地址,可以通过输出变量读取:

output "vpn_tunnel1_cgw_address" {
  value = aws_vpn_connection.vpn_home.tunnel1_cgw_inside_address
}

output "vpn_tunnel1_vgw_address" {
  value = aws_vpn_connection.vpn_home.tunnel1_vgw_inside_address
}

output "vpn_tunnel2_cgw_address" {
  value = aws_vpn_connection.vpn_home.tunnel2_cgw_inside_address
}

output "vpn_tunnel2_vgw_address" {
  value = aws_vpn_connection.vpn_home.tunnel2_vgw_inside_address
}

内容的提问来源于stack exchange,提问作者Sky Blue Why

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 22:30:54