You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Terraform模块创建资源时如何将SQS与对应S3存储桶绑定

实现修改步骤

你只需要按以下步骤调整代码即可实现不同SQS队列绑定对应S3存储桶的需求:

1. 修改 SQS/variables.tf 新增关联S3存储桶变量

variable "sqs_queue_name"{
  description = "The name of different SQS to be created"
  type        = string
}

variable "dead_queue_name"{
  description = "The name of different Dead Queues to be created"
  type        = string
}

variable "max_receive_count" {
    type = number
}

# 新增:当前队列绑定的S3存储桶名称
variable "associated_s3_bucket_name" {
  description = "Name of the S3 bucket associated with current SQS queue"
  type        = string
}

2. 修正 SQS/iam.tf 队列资源引用+替换存储桶变量

原代码中策略引用的SQS资源名和main.tf中定义的不一致,同步修改后用新增的存储桶变量替换原全局变量:

# 若该策略文档无其他地方引用可直接删除
data "aws_iam_policy_document" "policy_document"{
  statement{
    actions = [
      "sqs:DeleteMessage",
      "sqs:GetQueueUrl",
      "sqs:ReceiveMessage",
      "sqs:SendMessage",
      "sqs:SetQueueAttributes"
    ]
    effect = "Allow"
    resources = [aws_sqs_queue.sqs.arn]
  }
}

resource "aws_sqs_queue_policy" "Cloudtrail_SQS_Policy" {
  queue_url = aws_sqs_queue.sqs.id
  policy = <<POLICY
{
  "Version": "2012-10-17",
  "Id": "sqspolicy",
  "Statement": [
    {
      "Sid": "AllowSQSInvocation",
      "Effect": "Allow",
      "Principal": {"AWS":"*"},
      "Action": "sqs:*",
      "Resource": "${aws_sqs_queue.sqs.arn}",
      "Condition": {
        "ArnEquals": {
          "aws:SourceArn": "arn:aws:s3:::${var.associated_s3_bucket_name}"
        }
      }
    }
  ]
}
POLICY
}

resource "aws_sqs_queue_policy" "CloudTrail_SQS_DLQ"{
    queue_url = aws_sqs_queue.dlq.id
    policy = <<POLICY
{
  "Version": "2012-10-17",
  "Id": "sqspolicy",
  "Statement": [
    {
      "Sid": "DLQ Policy",
      "Effect": "Allow",
      "Principal": {"AWS":"*"},
      "Action": "sqs:*",
      "Resource": "${aws_sqs_queue.dlq.arn}",
      "Condition": {
        "ArnEquals": {
          "aws:SourceArn": "arn:aws:s3:::${var.associated_s3_bucket_name}"
        }
      }
    }
  ]
}
POLICY
}

3. 修改根目录variable.tf,给每个队列配置对应绑定的存储桶

variable "queue_names" {
  default = [
    {
      sqs_name = "CloudTrail_SQS_Management_Event"
      dlq_name = "CloudTrail_DLQ_Management_Event"
      associated_bucket = "management_sqs_bucket"
    },
    {
      sqs_name = "CloudTrail_SQS_Data_Event"
      dlq_name = "CloudTrail_DLQ_Data_Event"
      associated_bucket = "data_sqs_bucket"
    }
  ]
}

4. 修改根目录module调用,传入关联存储桶参数

module "sqs_queue" {
  source = "../SQS"
  for_each = {
    for idx, queue in var.queue_names : queue.sqs_name => queue
  }
  sqs_queue_name    = each.value.sqs_name
  dead_queue_name   = each.value.dlq_name
  max_receive_count = var.max_receive_count 
  # 新增:传入对应绑定的存储桶名称
  associated_s3_bucket_name = each.value.associated_bucket
}

可选:修正SQS/output.tf错误

原output错误使用了集合取值方式,子模块内SQS为单个资源,调整如下:

output "sqs_queue_id"{
    value       =   aws_sqs_queue.sqs.id
    description = "The URL for the created Amazon SQS queue."
}

output "sqs_queue_arn" {
  value       =  aws_sqs_queue.sqs.arn
  description = "The ARN of the SQS queue."
}

output "dlq_queue_id"{
    value       =   aws_sqs_queue.dlq.id
    description = "The URL for the created dead letter queue."
}

output "dlq_queue_arn" {
  value       =  aws_sqs_queue.dlq.arn
  description = "The ARN of the dead letter queue."
}

内容的提问来源于stack exchange,提问作者bibi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.29 23:18:01