You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform Plan报错:aws_api_gateway_authorizer.authorizer为空元组

解决Terraform中API Gateway授权器的索引错误

问题场景

创建API Gateway端点时,计划根据Lambda函数是否存在动态添加自定义授权器,相关Terraform配置如下:

模块配置

module "data_sources_api_report" {
  source = "..."

  pipeline_environment = var.pipeline_environment
  pipeline_vertical    = var.pipeline_vertical
  iam_boundary         = var.horizon_iam_boundary
  region               = var.aws_region
  allow_origin         = "*"

  is_with_vpc_link_connected = true
  vpc_link_id                = aws_api_gateway_vpc_link.datasource_vpc_link.id

  path_part                           = "devices"
  resource_endpoint_vpc_link_url_part = "api/v2/partitions/{partitionId}/report-datasource"
  request_path_parameters             = ["partitionId"]
  request_query_parameters            = []
  request_headers                     = []
  authorizer                          = var.enforcement_lambda_function_name == null ? null : aws_api_gateway_authorizer.authorizer[0].id

  rest_api_id            = aws_api_gateway_rest_api.reporting_services_api.id
  parent_resource_id     = aws_api_gateway_resource.http_resource_report-datasource_v2.id
  resource_http_method   = "GET"
  nlb_dns_name           = local.vpc_remote_state.datasource_load_balancer_dns_name
  integration_input_type = "HTTP_PROXY"

  tags = local.common_tags
}

授权器资源配置

resource "aws_api_gateway_authorizer" "authorizer" {
  count = var.enforcement_lambda_function_name != null ? 1 : 0

  name                   = "enforcement_layer_auth_${random_string.random.result}"
  rest_api_id            = aws_api_gateway_rest_api.reporting_services_api.id
  authorizer_uri         = join(",", data.aws_lambda_function.authorizer_lambda_function.*.invoke_arn)
  authorizer_credentials = join("", aws_iam_role.invocation_role.*.arn)
  type                   = "REQUEST"

  authorizer_result_ttl_in_seconds = 0
  identity_source                  = join(",", ["method.request.header.Authorization", "context.httpMethod", "context.path"])
}

执行terraform plan时触发以下错误:

Error: Invalid index
  on api_gateway.tf line 281, in module "data_sources_api_report":
 281:   authorizer                          = var.enforcement_lambda_function_name == null ? null : aws_api_gateway_authorizer.authorizer[0].id
    |----------------
    | aws_api_gateway_authorizer.authorizer is empty tuple

已定义enforcement_lambda_function_name变量,但仍触发该错误。

错误原因

问题核心是变量判断逻辑与资源count条件的一致性冲突:

  • 模块通过var.enforcement_lambda_function_name == null决定是否传递授权器ID,但授权器资源的count条件是var.enforcement_lambda_function_name != null ? 1 : 0
  • 若变量实际值为**空字符串("")**而非null,模块判断会认为变量不为null,尝试读取aws_api_gateway_authorizer.authorizer[0].id;但此时授权器资源虽因"" != null触发count=1,却可能因Lambda函数不存在等问题导致资源未生成,最终出现空元组索引错误。也可能是变量实际为null但用户误以为已设置有效值,导致count=0时模块仍执行了取索引的分支。

解决方案

方案1:基于资源存在性判断(推荐)

修改模块中authorizer参数的判断逻辑,直接检查授权器资源的实际存在情况,避免依赖变量判断的误差:

authorizer = length(aws_api_gateway_authorizer.authorizer) > 0 ? aws_api_gateway_authorizer.authorizer[0].id : null

这种方式以资源是否实际创建为判断依据,无需和变量条件强绑定,逻辑更可靠。

方案2:规范变量定义与赋值

确保enforcement_lambda_function_name变量的默认值为null,且赋值时严格区分空字符串和null:

variable "enforcement_lambda_function_name" {
  type        = string
  description = "Name of the enforcement lambda function"
  default     = null
}

不需要授权器时,显式将变量设为null;需要授权器时,传入有效的Lambda函数名称,确保count条件和模块判断逻辑完全匹配。

方案3:校验Lambda数据源有效性

确认data.aws_lambda_function.authorizer_lambda_function能正确查询到指定名称的Lambda函数,避免因数据源查询失败导致授权器资源无法创建:

data "aws_lambda_function" "authorizer_lambda_function" {
  count = var.enforcement_lambda_function_name != null ? 1 : 0
  function_name = var.enforcement_lambda_function_name
}

让数据源仅在变量有效时才执行查询,避免无意义的查询失败。

内容的提问来源于stack exchange,提问作者Dev Gourav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 10:40:35