You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform中基于execution_type的ALB动态配置报错排查求助

核心问题分析

你遇到的问题根源在于Terraform规划阶段需要确认条件表达式两侧的类型完全一致,当前写法中,虽然表面都是列表,但当var.execution_type为monitoring时,分支里的目标组仍间接引用了仅在screening模式下存在的module.screening_machine,导致Terraform无法在规划阶段解析类型。此外,当screening_machine模块count=0时,直接访问instance_id会触发空列表访问错误。

解决方案

1. 拆分重复配置,用局部变量复用基础内容

把重复的frontend目标组、基础listener规则提取为局部变量,避免代码冗余,同时让条件判断逻辑更清晰。

2. 条件性生成目标组与规则列表

通过concat函数合并基础配置和仅在screening模式下才添加的专属配置,确保monitoring模式下完全不引用screening_machine模块。

3. 安全引用实例ID

使用try函数处理screening_machine模块为空列表的情况,避免规划阶段报错。

修改后的完整代码

locals {
  # 复用frontend目标组配置
  frontend_target_group = {
    name             = "frontend-target-group"
    backend_protocol = "HTTP"
    backend_port     = 80
    target_type      = "ip"
    health_check = {
      enabled             = true
      interval            = 30
      path                = "/"
      port                = "traffic-port"
      healthy_threshold   = 5
      unhealthy_threshold = 2
      timeout             = 2
      protocol            = "HTTP"
      matcher             = "200"
    }
  }

  # 复用基础的listener规则(monitoring和screening共通部分)
  base_listener_rule = {
    https_listener_index = 0
    priority             = 5000
    actions = [
      {
        type = "authenticate-cognito"
        user_pool_arn       = module.cognito.cognito_user_pool_arn
        user_pool_client_id = module.cognito.cognito_user_pool_client_id
        user_pool_domain    = module.cognito.cognito_user_pool_domain
      },
      {
        type               = "forward"
        target_group_index = 0
      }
    ]
    conditions = [{
      path_patterns = ["/csv-table", "/json-display/*", "/processed-files", "/results/*"]
    }]
  }
}

module "alb" {
  source  = "terraform-aws-modules/alb/aws"
  version = "6.6.1"

  name = "${local.resource_prefix}-lb-frontend"

  load_balancer_type = "application"

  vpc_id          = module.vpc.vpc_id
  subnets         = module.vpc.public_subnets
  security_groups = ["${module.vpc.default_security_group_id}", "${aws_security_group.allow_http.id}"]

  # 条件生成目标组列表:monitoring模式下仅保留frontend,screening模式下添加screening目标组
  target_groups = concat(
    [local.frontend_target_group],
    var.execution_type == "screening" ? [
      {
        name             = "screening_machine"
        backend_protocol = "HTTP"
        backend_port     = 80
        target_type      = "instance"
        health_check = {
          enabled             = true
          interval            = 30
          path                = "/ec"
          port                = "traffic-port"
          healthy_threshold   = 5
          unhealthy_threshold = 2
          timeout             = 2
          protocol            = "HTTP"
          matcher             = "200"
        }
        targets = {
          screening_machine = {
            # 使用try函数处理实例不存在的情况
            target_id = try(module.screening_machine[0].instance_id, null)
            port      = 80
          }
        }
      }
    ] : []
  )

  http_tcp_listeners = [
    {
      port        = 80
      protocol    = "HTTP"
      action_type = "redirect"
      redirect = {
        port        = "443"
        protocol    = "HTTPS"
        status_code = "HTTP_301"
      }
    }
  ]

  https_listeners = [
    {
      port               = 443
      protocol           = "HTTPS"
      certificate_arn    = data.aws_acm_certificate.subdomain_certificate.arn
      target_group_index = 0
    }
  ]

  # 条件生成listener规则:screening模式下添加额外的/ec路径规则
  https_listener_rules = concat(
    [local.base_listener_rule],
    var.execution_type == "screening" ? [
      {
        https_listener_index = 0
        priority             = 4000
        actions = [
          {
            type = "authenticate-cognito"
            user_pool_arn       = module.cognito.cognito_user_pool_arn
            user_pool_client_id = module.cognito.cognito_user_pool_client_id
            user_pool_domain    = module.cognito.cognito_user_pool_domain
          },
          {
            type               = "forward"
            target_group_index = 1
          }
        ]
        conditions = [{
          path_patterns = ["/ec", "/ec/*"]
        }]
      }
    ] : []
  )

  tags = local.tags
}

关键修改点说明

  • 局部变量复用:将重复的基础配置提取到locals中,减少冗余代码,降低维护成本。
  • concat条件合并:用concat替代三元表达式直接生成列表,确保monitoring模式下完全不包含screening相关配置,避免引用不存在的模块。
  • try函数容错:在引用screening_machine实例ID时,用try处理模块为空列表的情况,避免规划阶段报错。
  • 索引正确性:screening模式下新增的目标组位于索引1,对应的listener规则中target_group_index = 1保持正确指向。

内容的提问来源于stack exchange,提问作者Kevin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 05:54:09