如何解决Terraform创建私有子网EMR集群的VALIDATION_ERROR错误
Hey there, let's work through this EMR cluster issue you're hitting! That VALIDATION_ERROR about needing a ServiceAccessSecurityGroup when using custom security groups in a private subnet is a common gotcha with older Terraform AWS provider versions. Since you're on Terraform 0.11.7 (which pairs with an older provider that doesn't include the GitHub fix you found), here are concrete steps to resolve it:
1. Manually Specify the Service Access Security Group
The core issue is that AWS requires a dedicated security group for EMR service-to-cluster communication when launching clusters in private subnets with custom security groups, and your Terraform provider version doesn't auto-handle this yet. Here's how to set it up:
Step 1: Create the Service Access Security Group
First, define a security group that allows EMR service traffic to communicate with your cluster nodes. This security group should reference your cluster's main security group as the allowed source:
resource "aws_security_group" "emr_service_access" { name = "emr-service-access-sg" description = "Enables EMR service to communicate with cluster nodes" vpc_id = "${aws_vpc.your_vpc.id}" # Replace with your actual VPC ID # Allow incoming traffic from your cluster's custom security group ingress { from_port = 0 to_port = 65535 protocol = "tcp" source_security_group_id = "${aws_security_group.emr_cluster_sg.id}" # Your cluster's SG } # Allow all outbound traffic (adjust based on your security requirements) egress { from_port = 0 to_port = 65535 protocol = "-1" cidr_blocks = ["0.0.0.0/0"] } }
Step 2: Attach It to Your EMR Cluster
Add the service_access_security_group_id parameter to your aws_emr_cluster resource, pointing to the security group you just created:
resource "aws_emr_cluster" "emr-test-cluster" { # ... Your existing cluster configuration (name, release_label, instance groups, etc.) ... # Add this line to resolve the validation error service_access_security_group_id = "${aws_security_group.emr_service_access.id}" }
2. Upgrade the AWS Provider (If Feasible)
The GitHub fix you referenced addresses this issue by automatically handling the service access security group for private subnet clusters. If you can upgrade your AWS provider version (without upgrading Terraform 0.11.7 itself), specify a provider version that includes this fix.
For Terraform 0.11.7, a compatible provider version with the fix is around ~> 1.10.0 (you can confirm via the provider's release notes). Update your provider block like this:
provider "aws" { version = "~> 1.10.0" region = "your-aws-region" # e.g., us-east-1 }
Note: Always test provider upgrades in a non-production environment first to catch any compatibility quirks with your existing configuration.
3. Verify Bidirectional Security Group Rules
Double-check that your cluster's main custom security group allows traffic from the service access security group too—bidirectional communication is required for EMR to manage the cluster properly. Add this ingress rule if missing:
resource "aws_security_group" "emr_cluster_sg" { # ... Existing configuration ... # Allow traffic from the service access security group ingress { from_port = 0 to_port = 65535 protocol = "tcp" source_security_group_id = "${aws_security_group.emr_service_access.id}" } }
This should resolve the TERMINATED_WITH_ERRORS: VALIDATION_ERROR and let your EMR cluster launch successfully in the private subnet.
内容的提问来源于stack exchange,提问作者Raghunandan Sk

