You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform中迭代列表以配置OCI安全列表多子网入站规则

代码修改方案

核心通过Terraform的dynamic动态嵌套块语法,遍历列表类型的compute_subnet_cidr参数,为每个CIDR生成对应的入站安全规则,修改后完整代码如下:

# 首先调整变量定义(如果原有变量是string类型需替换为如下定义)
variable "compute_subnet_cidr" {
  type        = list(string)
  description = "计算层子网CIDR列表"
  default     = ["10.10.10.0/24", "10.10.10.1/24", "10.10.10.2/24"]
}

resource "oci_core_security_list" "db_security_list" {
  count          = var.deploy_database ? 1 : 0
  compartment_id = var.network_compartment_id
  vcn_id         = var.vcn_id
  freeform_tags  = { "Component" = "Database" }
  display_name   = "test-db-sl"

  # 动态迭代生成所有入站规则
  dynamic "ingress_security_rules" {
    for_each = var.compute_subnet_cidr
    content {
      protocol = "6" # TCP
      source   = ingress_security_rules.value
      tcp_options {
        max = "1522"
        min = "1522"
      }
    }
  }
}

关键逻辑说明:

  • dynamic "ingress_security_rules" 声明需要动态生成ingress_security_rules嵌套块
  • for_each 指定迭代数据源为CIDR列表,列表有多少个元素就会生成多少条对应规则
  • ingress_security_rules.value 取当前迭代项的CIDR值作为规则的源地址

内容的提问来源于stack exchange,提问作者cloudbud

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 04:06:08