能否通过Terraform为IAM用户账户启用MFA?
Absolutely! You can handle MFA setup for both individual IAM users and batches of users using Terraform. Let’s break down both scenarios clearly:
1. Enabling MFA for a Single IAM User
Yes, Terraform fully supports setting up MFA for a single IAM user. You’ll usually work with two key resources here:
aws_iam_virtual_mfa_device: Creates a virtual MFA device (for apps like Google Authenticator or Authy)aws_iam_user_mfa_device: Links the MFA device to your user and completes activation (requires two consecutive codes from the device)
Here’s a complete, actionable example:
# Example IAM user (skip this if your user is already defined) resource "aws_iam_user" "john_doe" { name = "john.doe" path = "/" } # Create a virtual MFA device tied to the user resource "aws_iam_virtual_mfa_device" "john_mfa" { name = "mfa-john-doe" path = "/" virtual_mfa_device_name = "john-doe-virtual-mfa" } # Activate the MFA device for the user (requires two codes from the MFA app) resource "aws_iam_user_mfa_device" "john_mfa_activated" { user_name = aws_iam_user.john_doe.name serial_number = aws_iam_virtual_mfa_device.john_mfa.serial_number authentication_code_1 = "123456" # Replace with first code from your MFA app authentication_code_2 = "654321" # Replace with second consecutive code } # Output the QR code URL so you can scan it with your MFA app output "john_mfa_qr_code" { value = aws_iam_virtual_mfa_device.john_mfa.qr_code_png_url }
Note: First scan the QR code URL output by Terraform into your MFA app, then grab two consecutive codes to fill in the authentication fields. For hardware MFA devices, skip the aws_iam_virtual_mfa_device resource and use the device’s serial number directly in aws_iam_user_mfa_device.
2. Enabling MFA for Multiple IAM Users (Bulk)
You can automate MFA setup across multiple users using Terraform’s for_each meta-argument to iterate over a list or map of user accounts. This ensures consistent MFA configuration across your team.
Here’s an example using a list of user names:
# Define a list of users to enable MFA for variable "target_users" { type = list(string) default = ["jane.doe", "bob.smith", "alice.jones"] } # Create the IAM users (skip if users already exist) resource "aws_iam_user" "bulk_users" { for_each = toset(var.target_users) name = each.value path = "/" } # Create a virtual MFA device for each user resource "aws_iam_virtual_mfa_device" "bulk_mfa_devices" { for_each = aws_iam_user.bulk_users name = "mfa-${each.value.name}" path = "/" virtual_mfa_device_name = "${each.value.name}-virtual-mfa" } # Activate MFA for each user (you'll need their respective MFA codes) resource "aws_iam_user_mfa_device" "bulk_mfa_activated" { for_each = aws_iam_user.bulk_users user_name = each.value.name serial_number = aws_iam_virtual_mfa_device.bulk_mfa_devices[each.key].serial_number authentication_code_1 = "USER_FIRST_CODE" # Replace with each user's first code authentication_code_2 = "USER_SECOND_CODE" # Replace with each user's second code } # Output all QR code URLs to share with users output "all_mfa_qr_codes" { value = { for user in aws_iam_user.bulk_users : user.name => aws_iam_virtual_mfa_device.bulk_mfa_devices[user.name].qr_code_png_url } }
Key notes for bulk setup:
- Each user will need to scan their unique QR code and provide their two MFA codes. Share the output URLs with your team to complete this step.
- For hardware MFA devices, replace the virtual device resource with a map that links each user to their device’s serial number, then use that map in the activation resource.
内容的提问来源于stack exchange,提问作者Mahela Wickramasekara

