如何在app1-networking_nsgs.tf中引用TFVARS里的security_rules
如何在app1-networking_nsgs.tf中引用TFVARS文件里的security_rules?
本人从一开始就使用CI/CD流程,所有变量均定义在TFVARS文件中,希望得到相关帮助。
module-nsg-main.tf
resource "azurerm_network_security_group" "nsg" { name = var.nsg_name resource_group_name = var.resource_group_name location = var.location # tags = var.tags dynamic "security_rule" { for_each = var.security_rules content { name = lookup(security_rule.value, "name", null) priority = lookup(security_rule.value, "priority", null) direction = lookup(security_rule.value, "direction", null) access = lookup(security_rule.value, "access", null) protocol = lookup(security_rule.value, "protocol", null) source_port_range = lookup(security_rule.value, "source_port_range", null) source_port_ranges = lookup(security_rule.value, "source_port_ranges", null) destination_port_range = lookup(security_rule.value, "destination_port_range", null) destination_port_ranges = lookup(security_rule.value, "destination_port_ranges", null) source_address_prefix = lookup(security_rule.value, "source_address_prefix", null) source_address_prefixes = lookup(security_rule.value, "source_address_prefixes", null) destination_address_prefix = lookup(security_rule.value, "destination_address_prefix", null) destination_address_prefixes = lookup(security_rule.value, "destination_address_prefixes", null) source_application_security_group_ids = lookup(security_rule.value, "source_application_security_group_ids ", null) destination_application_security_group_ids = lookup(security_rule.value, "destination_application_security_group_ids ", null) } } }
module-nsg-outputs.tf
output "nsg_id" { description = "The ID of the newly created Network Security Group" value = azurerm_network_security_group.nsg.id } output "nsg_name" { description = "The name of the new NSG" value = azurerm_network_security_group.nsg.name }
module-nsg-variables.tf
variable "resource_group_name" { description = "description" type = string } variable "nsg_name" { description = "description" type = string } variable "location" { description = "description" type = string # default = "West Europe" } variable "security_rules" { description = "A list of security rules to add to the security group. Each rule should be a map of values to add. See the Readme.md file for further details." type = list(object({ name = string priority = number direction = string access = string protocol = string source_port_range = string destination_port_range = string source_address_prefix = string destination_address_prefix = string })) }
app1-networking_nsgs.tf
module "nsg-app1" { source = "git@gitlab.com:*/*" # version = "1.0.0" nsg_name = "dev-nsg" resource_group_name = module.rg-sharegate.resource_group_name location = module.rg-sharegate.location # tags = local.tags # security_rules = [ # { # name = "Inbound Rule", # priority = "100" # direction = "Inbound" # access = "Allow" # protocol = "Tcp" # source_port_range = "*" # destination_port_range = "22" # source_address_prefix = "*" # destination_address_prefix = "*" # } # ] }
dev.tfvars
environment = "non-prod" environment_code = "d" deployment_code = "lxr" location_code = "aus" location = "Australia Southeast" name_suffix = "app1" network_octets = "10.1" host_octets = ".0.0/16" subnet_octet = "0" cidr_prefix = "0/24" dns_servers = ["1.1.1.1", "9.9.9.9"] security_rules = [ { name = "Inbound Rule", priority = "100" direction = "Inbound" access = "Allow" protocol = "Tcp" source_port_range = "*" destination_port_range = "22" source_address_prefix = "*" destination_address_prefix = "*" } ]
执行报错
执行terraform plan -var-file=dev.tfvars时出现如下报错:
╷ │ Warning: Value for undeclared variable │ │ The root module does not declare a variable named "security_rules" but a value was found in file "dev.tfvars". If you meant to use this value, add a "variable" block to the │ configuration. │ │ To silence these warnings, use TF_VAR_... environment variables to provide certain "global" settings to all configurations in your organization. To reduce the verbosity of │ these warnings, use the -compact-warnings option. ╵ ╷ │ Error: Missing required argument │ │ on networking_nsgs.tf line 2, in module "nsg-app1": │ 2: module "nsg-app1" { │ │ The argument "security_rules" is required, but no definition was found.
问题原因
- 根模块未声明
security_rules变量,导致tfvars中的该变量无法被根模块识别 - 调用
nsg-app1模块时未传入必填的security_rules参数 dev.tfvars中priority的值是字符串类型,与模块定义的number类型不匹配
解决步骤
1. 在根模块添加security_rules变量声明
在根目录下创建或修改variables.tf文件,添加以下内容:
variable "security_rules" { description = "NSG安全规则列表" type = list(object({ name = string priority = number direction = string access = string protocol = string source_port_range = string destination_port_range = string source_address_prefix = string destination_address_prefix = string })) }
2. 在app1-networking_nsgs.tf中传入变量
修改模块调用代码,将security_rules参数指向根模块变量:
module "nsg-app1" { source = "git@gitlab.com:*/*" # version = "1.0.0" nsg_name = "dev-nsg" resource_group_name = module.rg-sharegate.resource_group_name location = module.rg-sharegate.location # tags = local.tags security_rules = var.security_rules }
3. 修正dev.tfvars中的类型错误
将priority的字符串值改为数字类型(去掉引号):
security_rules = [ { name = "Inbound Rule", priority = 100 direction = "Inbound" access = "Allow" protocol = "Tcp" source_port_range = "*" destination_port_range = "22" source_address_prefix = "*" destination_address_prefix = "*" } ]
内容的提问来源于stack exchange,提问作者Cyborganizer
相关产品推荐
相关产品推荐

