Terraform创建GCP NAT网关失败,报错element无法处理空列表
element() may not be used with an empty list Let's break down what's happening here and how to fix it. First, let's recap your setup: you're using the GoogleCloudPlatform/nat-gateway module (v1.1.3) to deploy a NAT gateway, but you're hitting an error that stops terraform apply and terraform destroy from completing.
Your Configuration Snippets
Here's the module and supporting resources you're using:
NAT Gateway Module:
module "nat" { source = "GoogleCloudPlatform/nat-gateway/google" region = "${var.gcloud-region}" network = "${google_compute_network.vpc-network.name}" subnetwork = "${google_compute_subnetwork.vpc-subnetwork-public.name}" machine_type = "${var.vm-type-nat-gateway}" }
Variables & Network Resources:
variable "gcloud-region" { default = "europe-west1" } variable "vm-type-nat-gateway" { default = "n1-standard-2"} resource "google_compute_network" "vpc-network" { name = "foobar-vpc-network" auto_create_subnetworks = false } resource "google_compute_subnetwork" "vpc-subnetwork-public" { name = "foobar-vpc-subnetwork-public" ip_cidr_range = "10.0.1.0/24" network = "${google_compute_network.vpc-network.self_link}" region = "${var.gcloud-region}" private_ip_google_access = false }
The Error You're Seeing
module.nat.google_compute_route.nat-gateway: 1 error(s) occurred:
module.nat.google_compute_route.nat-gateway: element: element() may not be used with an empty list in:
${element(split("/", element(module.nat-gateway.instances[0], 0)), 10)}
Root Cause
This error happens because the nat-gateway module's instances list is empty. The module tries to reference the first instance in this list to create the compute route, but if no instances were successfully created (or initialized), the list is empty—and the element() function can't operate on an empty list.
Common Reasons & Fixes
1. Subnet Private IP Google Access is Disabled
Your public subnet has private_ip_google_access = false, but the NAT gateway instance needs access to Google's metadata server (to fetch configuration like internal IPs, routes, etc.). Disabling this can prevent the instance from initializing properly, so it never gets added to the module's instances list.
Fix: Update your subnet to enable private IP Google access:
resource "google_compute_subnetwork" "vpc-subnetwork-public" { name = "foobar-vpc-subnetwork-public" ip_cidr_range = "10.0.1.0/24" network = "${google_compute_network.vpc-network.self_link}" region = "${var.gcloud-region}" private_ip_google_access = true # Enable this setting }
2. Outdated Module Version
Version 1.1.3 of the nat-gateway module is quite old, and it likely has a bug where it doesn't handle failed instance creation gracefully. Newer versions of the module have better error handling and compatibility with recent Terraform and GCP API changes.
Fix: Upgrade the module to a newer stable version. Update the source line to include the newer version (note: newer versions may have minor variable changes, so check the module's documentation for adjustments):
module "nat" { source = "GoogleCloudPlatform/nat-gateway/google" version = "3.1.0" # Use a recent stable version region = "${var.gcloud-region}" network = "${google_compute_network.vpc-network.name}" subnetwork = "${google_compute_subnetwork.vpc-subnetwork-public.name}" machine_type = "${var.vm-type-nat-gateway}" }
3. Insufficient Permissions
The service account you're using to run Terraform might not have the necessary permissions to create Compute Engine instances or network routes. Without these permissions, the instance creation silently fails, leaving the instances list empty.
Fix: Ensure your service account has at least these roles:
Compute Instance Admin (v1)(roles/compute.instanceAdmin.v1)Compute Network Admin(roles/compute.networkAdmin)
You can assign roles via the GCP Console or using the gcloud CLI:
gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \ --member="serviceAccount:YOUR_SERVICE_ACCOUNT@YOUR_PROJECT_ID.iam.gserviceaccount.com" \ --role="roles/compute.instanceAdmin.v1"
4. Instance Creation Failures (Check GCP Console)
Sometimes the module doesn't surface the exact reason the instance failed to create. Head to the Compute Engine > VM Instances page in the GCP Console and look for any failed or terminated instances related to your NAT gateway. Check the instance's logs for errors like insufficient resources, network issues, or startup script failures.
5. Validate Machine Type & Region Compatibility
Double-check that the n1-standard-2 machine type is available in the europe-west1 region. You can verify this with the gcloud CLI:
gcloud compute machine-types list --filter="name=n1-standard-2 AND region:europe-west1"
If it's not available, switch to a machine type that is supported in your region.
Next Steps
- First, try enabling
private_ip_google_accesson your subnet and re-runterraform planto see if the error goes away. - If that doesn't work, check the GCP Console for instance creation errors.
- Consider upgrading the module to a newer version to benefit from bug fixes.
内容的提问来源于stack exchange,提问作者Ruwan Ranganath Senarathne

