Terraform Plan输出异常:ALB配置变更提示不符实际问题咨询
First, let's look at the problematic plan output you're seeing:
~ module.api-origin-demo-prod.aws_alb.origin-alb
enable_cross_zone_load_balancing: "" => "false"
enable_http2: "" => "true"
Let's break down each issue and how to resolve them:
Cross-Zone Load Balancing: Invalid Attribute for ALBs
Here's the critical detail to note: Cross-zone load balancing is a feature exclusive to AWS Classic Load Balancers (CLB)—it’s not a configurable setting for Application Load Balancers (ALB). For ALBs, cross-zone load balancing is always enabled by default, and there’s no way to toggle it via the AWS console or API.
Terraform is flagging this change because your aws_alb resource likely includes the enable_cross_zone_load_balancing attribute in your configuration. Since this attribute doesn’t apply to ALBs, Terraform tries to set it to false (the default value for the attribute) even though the setting doesn’t exist for your resource type.
Quick Fix: Delete the enable_cross_zone_load_balancing line entirely from your aws_alb resource configuration. This will eliminate the false positive change from future Terraform plans.
HTTP/2 Configuration Drift
You mentioned HTTP/2 is already enabled in the AWS Console, but Terraform is showing it as a pending change. This almost always stems from one of two scenarios:
- You didn’t explicitly set
enable_http2 = truein your Terraform code. AWS enables HTTP/2 for ALBs by default, but if Terraform doesn’t see the attribute in your config, it interprets the empty value as a mismatch with the actual enabled state in AWS. - There’s a discrepancy between Terraform’s local state file and the real-world state of your ALB in AWS.
Fixes to Try:
- Add
enable_http2 = truedirectly to youraws_albresource block. This aligns your code with the actual AWS configuration, so Terraform will stop flagging this as a change. - If the issue persists, run
terraform refreshto sync Terraform’s local state with the current state of your ALB in AWS. This updates the state file to reflect that HTTP/2 is already enabled, eliminating the drift.
内容的提问来源于stack exchange,提问作者greenpenguin

