You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从Terraform状态文件提取dev-devic-efs对应的KMS ARN

Got it, let's walk through how to pull that specific KMS ARN tied to the dev-devic-efs alias from your Terraform state data. I've got a couple of practical methods for you depending on what you need to do:

First, just to recap the relevant snippet from your Terraform state:

"efs_key": {
  "value": {
    "alias": {
      "1-efs": "arn:aws:kms:eu-east-1:144382646821:key/e1b7e7fd-5ec3-41ce-94a8-8d34d43164ca",
      "2-efs": "arn:aws:kms:eu-east-1:144382646821:key/2de9045a-96bc-4bc0-83ef-b420d9ff3dc1",
      "3-efs": "arn:aws:kms:eu-east-1:144382646821:key/e379f46e-a36d-47e8-9652-d40b00f385ba",
      "4-efs": "arn:aws:kms:eu-east-1:144382646821:key/69d0bd86-53ea-4a51-b4a0-76754c7ed8fd",
      "5-efs": "arn:aws:kms:eu-east-1:144382646821:key/dfc1ead3-1b72-4c01-bdf2-c624ee565fca",
      "dev-devic-efs": "arn:aws:kms:eu-east-1:144382646821:key/e1652537-a360-4086-813d-4fc6668425a6"
    }
  },
  "type": [
    "object",
    {
      "alias": [
        "object",
        {
          "1-efs": "string",
          "2-efs": "string",
          "3-efs": "string",
          "4-efs": "string",
          "5-efs": "string",
          "dev-devic-efs": "string"
        }
      ]
    }
  ]
}

If efs_key is already defined as an output in your Terraform config, you can extract the ARN directly with this command:

terraform output -json efs_key | jq '.value.alias."dev-devic-efs"'
  • terraform output -json efs_key: Exports the efs_key output in JSON format, which makes it easy to parse
  • jq '.value.alias."dev-devic-efs"': Traverses the JSON structure to grab the value tied to dev-devic-efs (we wrap the key in quotes because it has hyphens, which jq needs to handle correctly)

This will output the ARN wrapped in double quotes. If you want a raw, unquoted string, add the -r flag to jq:

terraform output -json efs_key | jq -r '.value.alias."dev-devic-efs"'

Method 2: Directly Query the Terraform State File (For Quick Ad-Hoc Checks)

If you just need a one-off look without relying on Terraform outputs, you can read the terraform.tfstate file directly with jq:

jq '.outputs.efs_key.value.alias."dev-devic-efs"' terraform.tfstate

Again, use -r to get the unquoted ARN:

jq -r '.outputs.efs_key.value.alias."dev-devic-efs"' terraform.tfstate

Method 3: Reference the ARN in Your Terraform Code

If you need to use this ARN as a value in other parts of your Terraform configuration (like attaching it to an S3 bucket for encryption), here's how you'd reference it:

If pulling from a remote state:

data "terraform_remote_state" "my_state" {
  backend = "s3" # Replace with your actual backend type
  config = {
    bucket = "your-terraform-state-bucket"
    key    = "path/to/statefile.tfstate"
    region = "eu-east-1"
  }
}

# Example: Using the ARN in an S3 bucket encryption rule
resource "aws_s3_bucket" "secure_bucket" {
  bucket = "my-secure-bucket"

  server_side_encryption_configuration {
    rule {
      apply_server_side_encryption_by_default {
        kms_master_key_id = data.terraform_remote_state.my_state.outputs.efs_key.value.alias["dev-devic-efs"]
      }
    }
  }
}

If referencing a local module output:

# Assuming the efs_key is an output from a local module
module "my_efs_module" {
  source = "./modules/efs"
  # ... module parameters
}

resource "aws_s3_bucket" "secure_bucket" {
  bucket = "my-secure-bucket"

  server_side_encryption_configuration {
    rule {
      apply_server_side_encryption_by_default {
        kms_master_key_id = module.my_efs_module.efs_key.value.alias["dev-devic-efs"]
      }
    }
  }
}

内容的提问来源于stack exchange,提问作者sakworld

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 00:37:45