如何从Terraform状态文件提取dev-devic-efs对应的KMS ARN
Got it, let's walk through how to pull that specific KMS ARN tied to the dev-devic-efs alias from your Terraform state data. I've got a couple of practical methods for you depending on what you need to do:
First, just to recap the relevant snippet from your Terraform state:
"efs_key": { "value": { "alias": { "1-efs": "arn:aws:kms:eu-east-1:144382646821:key/e1b7e7fd-5ec3-41ce-94a8-8d34d43164ca", "2-efs": "arn:aws:kms:eu-east-1:144382646821:key/2de9045a-96bc-4bc0-83ef-b420d9ff3dc1", "3-efs": "arn:aws:kms:eu-east-1:144382646821:key/e379f46e-a36d-47e8-9652-d40b00f385ba", "4-efs": "arn:aws:kms:eu-east-1:144382646821:key/69d0bd86-53ea-4a51-b4a0-76754c7ed8fd", "5-efs": "arn:aws:kms:eu-east-1:144382646821:key/dfc1ead3-1b72-4c01-bdf2-c624ee565fca", "dev-devic-efs": "arn:aws:kms:eu-east-1:144382646821:key/e1652537-a360-4086-813d-4fc6668425a6" } }, "type": [ "object", { "alias": [ "object", { "1-efs": "string", "2-efs": "string", "3-efs": "string", "4-efs": "string", "5-efs": "string", "dev-devic-efs": "string" } ] } ] }
Method 1: Use Terraform Output + jq (Recommended for Workflow Integration)
If efs_key is already defined as an output in your Terraform config, you can extract the ARN directly with this command:
terraform output -json efs_key | jq '.value.alias."dev-devic-efs"'
terraform output -json efs_key: Exports theefs_keyoutput in JSON format, which makes it easy to parsejq '.value.alias."dev-devic-efs"': Traverses the JSON structure to grab the value tied todev-devic-efs(we wrap the key in quotes because it has hyphens, which jq needs to handle correctly)
This will output the ARN wrapped in double quotes. If you want a raw, unquoted string, add the -r flag to jq:
terraform output -json efs_key | jq -r '.value.alias."dev-devic-efs"'
Method 2: Directly Query the Terraform State File (For Quick Ad-Hoc Checks)
If you just need a one-off look without relying on Terraform outputs, you can read the terraform.tfstate file directly with jq:
jq '.outputs.efs_key.value.alias."dev-devic-efs"' terraform.tfstate
Again, use -r to get the unquoted ARN:
jq -r '.outputs.efs_key.value.alias."dev-devic-efs"' terraform.tfstate
Method 3: Reference the ARN in Your Terraform Code
If you need to use this ARN as a value in other parts of your Terraform configuration (like attaching it to an S3 bucket for encryption), here's how you'd reference it:
If pulling from a remote state:
data "terraform_remote_state" "my_state" { backend = "s3" # Replace with your actual backend type config = { bucket = "your-terraform-state-bucket" key = "path/to/statefile.tfstate" region = "eu-east-1" } } # Example: Using the ARN in an S3 bucket encryption rule resource "aws_s3_bucket" "secure_bucket" { bucket = "my-secure-bucket" server_side_encryption_configuration { rule { apply_server_side_encryption_by_default { kms_master_key_id = data.terraform_remote_state.my_state.outputs.efs_key.value.alias["dev-devic-efs"] } } } }
If referencing a local module output:
# Assuming the efs_key is an output from a local module module "my_efs_module" { source = "./modules/efs" # ... module parameters } resource "aws_s3_bucket" "secure_bucket" { bucket = "my-secure-bucket" server_side_encryption_configuration { rule { apply_server_side_encryption_by_default { kms_master_key_id = module.my_efs_module.efs_key.value.alias["dev-devic-efs"] } } } }
内容的提问来源于stack exchange,提问作者sakworld

