You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在app1-networking_nsgs.tf中引用TFVARS里的security_rules

如何在app1-networking_nsgs.tf中引用TFVARS文件里的security_rules?

本人从一开始就使用CI/CD流程,所有变量均定义在TFVARS文件中,希望得到相关帮助。


module-nsg-main.tf

resource "azurerm_network_security_group" "nsg" {
  name                = var.nsg_name
  resource_group_name = var.resource_group_name
  location            = var.location
  # tags                = var.tags

  dynamic "security_rule" {
    for_each = var.security_rules
    content {
      name                                       = lookup(security_rule.value, "name", null)
      priority                                   = lookup(security_rule.value, "priority", null)
      direction                                  = lookup(security_rule.value, "direction", null)
      access                                     = lookup(security_rule.value, "access", null)
      protocol                                   = lookup(security_rule.value, "protocol", null)
      source_port_range                          = lookup(security_rule.value, "source_port_range", null)
      source_port_ranges                         = lookup(security_rule.value, "source_port_ranges", null)
      destination_port_range                     = lookup(security_rule.value, "destination_port_range", null)
      destination_port_ranges                    = lookup(security_rule.value, "destination_port_ranges", null)
      source_address_prefix                      = lookup(security_rule.value, "source_address_prefix", null)
      source_address_prefixes                    = lookup(security_rule.value, "source_address_prefixes", null)
      destination_address_prefix                 = lookup(security_rule.value, "destination_address_prefix", null)
      destination_address_prefixes               = lookup(security_rule.value, "destination_address_prefixes", null)
      source_application_security_group_ids      = lookup(security_rule.value, "source_application_security_group_ids ", null)
      destination_application_security_group_ids = lookup(security_rule.value, "destination_application_security_group_ids ", null)
    }
  }
}

module-nsg-outputs.tf

output "nsg_id" {
  description = "The ID of the newly created Network Security Group"
  value       = azurerm_network_security_group.nsg.id
}

output "nsg_name" {
  description = "The name of the new NSG"
  value       = azurerm_network_security_group.nsg.name
}

module-nsg-variables.tf

variable "resource_group_name" {
  description = "description"
  type        = string
}

variable "nsg_name" {
  description = "description"
  type        = string
}

variable "location" {
  description = "description"
  type        = string
  # default     = "West Europe"
}

variable "security_rules" {
  description = "A list of security rules to add to the security group. Each rule should be a map of values to add. See the Readme.md file for further details."

  type = list(object({
    name                       = string
    priority                   = number
    direction                  = string
    access                     = string
    protocol                   = string
    source_port_range          = string
    destination_port_range     = string
    source_address_prefix      = string
    destination_address_prefix = string
  }))
}

app1-networking_nsgs.tf

module "nsg-app1" {
  source = "git@gitlab.com:*/*"
  #   version = "1.0.0"
  nsg_name            = "dev-nsg"
  resource_group_name = module.rg-sharegate.resource_group_name
  location            = module.rg-sharegate.location
#   tags                = local.tags

  # security_rules = [
  #   {
  #     name                       = "Inbound Rule",
  #     priority                   = "100"
  #     direction                  = "Inbound"
  #     access                     = "Allow"
  #     protocol                   = "Tcp"
  #     source_port_range          = "*"
  #     destination_port_range     = "22"
  #     source_address_prefix      = "*"
  #     destination_address_prefix = "*"
  #   }
  # ]
}

dev.tfvars

environment      = "non-prod"
environment_code = "d"
deployment_code  = "lxr"
location_code    = "aus"
location         = "Australia Southeast"
name_suffix      = "app1"

network_octets = "10.1"
host_octets    = ".0.0/16"
subnet_octet   = "0"
cidr_prefix    = "0/24"
dns_servers    = ["1.1.1.1", "9.9.9.9"]

  security_rules = [
    {
      name                       = "Inbound Rule",
      priority                   = "100"
      direction                  = "Inbound"
      access                     = "Allow"
      protocol                   = "Tcp"
      source_port_range          = "*"
      destination_port_range     = "22"
      source_address_prefix      = "*"
      destination_address_prefix = "*"
    }
  ]

执行报错

执行terraform plan -var-file=dev.tfvars时出现如下报错:

╷
│ Warning: Value for undeclared variable
│ 
│ The root module does not declare a variable named "security_rules" but a value was found in file "dev.tfvars". If you meant to use this value, add a "variable" block to the
│ configuration.
│ 
│ To silence these warnings, use TF_VAR_... environment variables to provide certain "global" settings to all configurations in your organization. To reduce the verbosity of
│ these warnings, use the -compact-warnings option.
╵
╷
│ Error: Missing required argument
│ 
│   on networking_nsgs.tf line 2, in module "nsg-app1":
│    2: module "nsg-app1" {
│ 
│ The argument "security_rules" is required, but no definition was found.

问题原因

  1. 根模块未声明security_rules变量,导致tfvars中的该变量无法被根模块识别
  2. 调用nsg-app1模块时未传入必填的security_rules参数
  3. dev.tfvars中priority的值是字符串类型,与模块定义的number类型不匹配

解决步骤

1. 在根模块添加security_rules变量声明

在根目录下创建或修改variables.tf文件,添加以下内容:

variable "security_rules" {
  description = "NSG安全规则列表"
  type = list(object({
    name                       = string
    priority                   = number
    direction                  = string
    access                     = string
    protocol                   = string
    source_port_range          = string
    destination_port_range     = string
    source_address_prefix      = string
    destination_address_prefix = string
  }))
}

2. 在app1-networking_nsgs.tf中传入变量

修改模块调用代码,将security_rules参数指向根模块变量:

module "nsg-app1" {
  source = "git@gitlab.com:*/*"
  #   version = "1.0.0"
  nsg_name            = "dev-nsg"
  resource_group_name = module.rg-sharegate.resource_group_name
  location            = module.rg-sharegate.location
#   tags                = local.tags

  security_rules = var.security_rules
}

3. 修正dev.tfvars中的类型错误

将priority的字符串值改为数字类型(去掉引号):

security_rules = [
  {
    name                       = "Inbound Rule",
    priority                   = 100
    direction                  = "Inbound"
    access                     = "Allow"
    protocol                   = "Tcp"
    source_port_range          = "*"
    destination_port_range     = "22"
    source_address_prefix      = "*"
    destination_address_prefix = "*"
  }
]

内容的提问来源于stack exchange,提问作者Cyborganizer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 16:09:24