You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Terraform定义K8s Job中挂载Secret列表项的Volume配置

问题原因

报错的根本原因是Kubernetes Terraform Provider中,secret 配置块下的items不属于可赋值的列表参数,而是需要独立定义的重复嵌套块,不能使用items = [{}]的数组赋值语法。

修正要点

  • 每个需要投射的Secret条目单独定义一个items块,不需要外层数组包裹
  • key和path的取值为字符串类型,必须用双引号包裹
  • 注意语法结构层级,volume块属于Pod Spec层级,要放在container块外部,避免嵌套错误

完整正确配置

resource "kubernetes_job" "xxx" {
  metadata {
    name      = "xxxxx"
    namespace = "test"
  }
  wait_for_completion = true

  spec {
    template {
      metadata {}
      spec {
        container {
          name              = "test"
          image             = "test"
          image_pull_policy = "Always"
          volume_mount {
            name       = "certs"
            mount_path = "/app/certs"
          }
          volume_mount {
            name       = "ca-certs"
            mount_path = "/app/ca-certs"
          }
        }

        volume {
          name = "certs"
          secret {
            secret_name = "tls-cert-internal"
            items {
              key  = "tls.crt"
              path = "crt.pem"
            }
            items {
              key  = "tls.key"
              path = "key.pem"
            }
          } 
        }

        volume {
          name = "ca-certs"
          secret {
            secret_name = "ca-bundle"
            items {
              key  = "tls.crt"
              path = "ca_crt.pem"
            }
          }
        }
      }
    }
  }
}

内容的提问来源于stack exchange,提问作者Ruchir Bharadwaj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 11:24:04