You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform生成AWS Network Firewall Suricata规则sid不唯一问题求助

解决AWS Network Firewall Suricata规则SID重复问题

问题背景

当前用Terraform结合YAML配置生成AWS Network Firewall的Suricata规则时,同一规则组下多条规则的*SID(规则ID)*重复。比如APPSTREAM组下的两个域名规则SID都是1,TEST组下的都是2,无法实现每条规则SID从1到4唯一递增的需求。

问题根源

原代码外层循环遍历rule_groups(索引为0、1),内层循环遍历每个组下的allowed-domains,但所有内层循环的规则都复用了外层循环的index + 1作为SID,导致同一组内的多条规则SID完全相同。

解决方案

通过扁平化所有域名规则条目,将每个域名对应为一个独立的规则条目,再遍历这个扁平化后的列表生成规则,即可保证SID唯一递增。

修改后的完整代码

1. 更新locals定义

替换原有的fw_group_rule为扁平化规则列表,每个条目对应一条Suricata规则:

locals {
  list = yamldecode(file("${path.module}/settings.yaml"))["rule_groups"]
  # 扁平化所有域名规则,每个条目对应一条独立的Suricata规则
  fw_domain_rules = flatten([
    for rule in local.list : [
      for domain in rule.allowed-domains : {
        name     = rule.name
        domain   = domain
        source   = rule.source
      }
    ]
  ])
}

2. 更新aws_networkfirewall_rule_group资源的规则生成逻辑

遍历扁平化后的fw_domain_rules列表,用列表索引+1作为SID:

resource "aws_networkfirewall_rule_group" "limit-Domain-Access-v1" {
  name     = "suricata-automation-test"
  capacity = 1000
  type     = "STATEFUL"
  rule_group {
    rule_variables {
      ip_sets {
        key = "SQUID_EP"
        ip_set {
          definition = ["10.143.60.158/32","10.143.60.17/32","10.143.60.164/32"]
        }
      }
      dynamic "ip_sets" {
        for_each = { for r in local.fw_domain_rules : r.name => r.source }
        content {
          key = ip_sets.key
          ip_set {
            definition = [ip_sets.value]
          }
        }
      }
    }
    rules_source {
      rules_string = <<EOF
%{for index, rule in local.fw_domain_rules~}
pass http $${rule.name} any -> $SQUID_EP any (http.host; dotprefix; content:"${rule.domain}"; endswith; msg:"matching HTTP allowlisted FQDNs"; priority:1; flow:to_server, established; sid:${index + 1}; rev:1;)
%{endfor~}
EOF
    }
  }
  tags = {
    Name = "suricata-automation-test"
  }
}

3. 更新输出验证部分

同样使用扁平化列表生成输出,验证SID的唯一性:

output "fw-group-rule" {
  value = <<EOF
%{for index, rule in local.fw_domain_rules~}
pass http $${rule.name} any -> $SQUID_EP any (http.host; dotprefix; content:"${rule.domain}"; endswith; msg:"matching HTTP allowlisted FQDNs"; priority:1; flow:to_server, established; sid:${index + 1}; rev:1;)
%{endfor~}
EOF
}

效果说明

修改后,fw_domain_rules会包含4个条目(对应4个域名),遍历列表时索引从0到3,index + 1会生成1、2、3、4的唯一SID,完全符合需求。

内容的提问来源于stack exchange,提问作者Dani-Bholenath

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 17:09:33