Terraform创建跨项目Shared VPC的GKE集群报错404求助
尝试在cluster-project项目中创建GKE集群,使用network-project项目中的Shared VPC网络。通过Terraform的data模块导入网络信息后,执行terraform apply时出现以下错误:
Error: googleapi: Error 404: Not found: project "cluster-project" does not have a subnetwork named "terraform-test" in region "us-central1"., notFound
以下是完整的main.tf文件:
data "google_compute_network" "main-default-vpc" { name = "default" project = "network-project" } data "google_compute_subnetwork" "subnet-for-k8s" { name = "terraform-test" project = "network-project" region = "us-central1" self_link = "https://www.googleapis.com/compute/v1/projects/project-name/regions/us-central1/subnetworks/terraform-test" } resource "google_container_cluster" "primary" { location = "us-central1" project = cluster-project name = var.cluster_name node_locations = var.zones network = data.google_compute_network.main-default-vpc.name subnetwork = data.google_compute_subnetwork.subnet-for-k8s.name initial_node_count = "1" remove_default_node_pool = "true" master_authorized_networks_config { cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { display_name = "cloud-nat-2 " cidr_block = "ip" } cidr_blocks { display_name = "cloud-nat-3 " cidr_block = "ip" } cidr_blocks { display_name = "cloud-nat-4" cidr_block = "ip" } cidr_blocks { display_name = "cloud-nat-5" cidr_block = "ip" } } ip_allocation_policy { cluster_secondary_range_name = data.google_compute_subnetwork.subnet-for-k8s.secondary_ip_range.0.range_name services_secondary_range_name = data.google_compute_subnetwork.subnet-for-k8s.secondary_ip_range.1.range_name } monitoring_config { enable_components = ["APISERVER","CONTROLLER_MANAGER","SYSTEM_COMPONENTS"] } } resource "google_container_node_pool" "primary_preemptible_nodes" { name = "default" cluster = google_container_cluster.primary.name autoscaling { max_node_count = var.minnode min_node_count = var.maxnode } node_config { machine_type = "n1-standard-2" preemptible = false disk_type = "pd-standard" disk_size_gb = var.disksize } }
1. 修正跨项目子网引用方式
对于Shared VPC的跨项目资源,不能仅使用子网名称,必须使用完整的资源self_link或者带项目前缀的格式。在google_container_cluster中修改network和subnetwork字段:
network = data.google_compute_network.main-default-vpc.self_link subnetwork = data.google_compute_subnetwork.subnet-for-k8s.self_link
2. 清理data块冗余配置
google_compute_subnetwork数据块中同时指定name、project、region和self_link会导致参数冲突,删除错误的self_link字段(保留name、project、region即可自动获取正确的self_link):
data "google_compute_subnetwork" "subnet-for-k8s" { name = "terraform-test" project = "network-project" region = "us-central1" }
如果要保留self_link,则修正其中的项目名称为network-project,并删除name、project、region字段:
data "google_compute_subnetwork" "subnet-for-k8s" { self_link = "https://www.googleapis.com/compute/v1/projects/network-project/regions/us-central1/subnetworks/terraform-test" }
3. 修复project字段语法错误
google_container_cluster中的project值缺少引号,修正为:
project = "cluster-project"
4. 纠正Node Pool自动扩缩容参数
autoscaling块中max_node_count和min_node_count参数倒置,修正为:
autoscaling { max_node_count = var.maxnode min_node_count = var.minnode }
data "google_compute_network" "main-default-vpc" { name = "default" project = "network-project" } data "google_compute_subnetwork" "subnet-for-k8s" { name = "terraform-test" project = "network-project" region = "us-central1" } resource "google_container_cluster" "primary" { location = "us-central1" project = "cluster-project" name = var.cluster_name node_locations = var.zones network = data.google_compute_network.main-default-vpc.self_link subnetwork = data.google_compute_subnetwork.subnet-for-k8s.self_link initial_node_count = "1" remove_default_node_pool = "true" master_authorized_networks_config { cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { cidr_block = "ip" display_name = "" } cidr_blocks { display_name = "cloud-nat-2 " cidr_block = "ip" } cidr_blocks { display_name = "cloud-nat-3 " cidr_block = "ip" } cidr_blocks { display_name = "cloud-nat-4" cidr_block = "ip" } cidr_blocks { display_name = "cloud-nat-5" cidr_block = "ip" } } ip_allocation_policy { cluster_secondary_range_name = data.google_compute_subnetwork.subnet-for-k8s.secondary_ip_range.0.range_name services_secondary_range_name = data.google_compute_subnetwork.subnet-for-k8s.secondary_ip_range.1.range_name } monitoring_config { enable_components = ["APISERVER","CONTROLLER_MANAGER","SYSTEM_COMPONENTS"] } } resource "google_container_node_pool" "primary_preemptible_nodes" { name = "default" cluster = google_container_cluster.primary.name autoscaling { max_node_count = var.maxnode min_node_count = var.minnode } node_config { machine_type = "n1-standard-2" preemptible = false disk_type = "pd-standard" disk_size_gb = var.disksize } }
内容的提问来源于stack exchange,提问作者Senan T

