You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决Terraform创建私有子网EMR集群的VALIDATION_ERROR错误

Fixing EMR Cluster Validation Error in Terraform 0.11.7 (Private Subnet)

Hey there, let's work through this EMR cluster issue you're hitting! That VALIDATION_ERROR about needing a ServiceAccessSecurityGroup when using custom security groups in a private subnet is a common gotcha with older Terraform AWS provider versions. Since you're on Terraform 0.11.7 (which pairs with an older provider that doesn't include the GitHub fix you found), here are concrete steps to resolve it:

1. Manually Specify the Service Access Security Group

The core issue is that AWS requires a dedicated security group for EMR service-to-cluster communication when launching clusters in private subnets with custom security groups, and your Terraform provider version doesn't auto-handle this yet. Here's how to set it up:

Step 1: Create the Service Access Security Group

First, define a security group that allows EMR service traffic to communicate with your cluster nodes. This security group should reference your cluster's main security group as the allowed source:

resource "aws_security_group" "emr_service_access" {
  name        = "emr-service-access-sg"
  description = "Enables EMR service to communicate with cluster nodes"
  vpc_id      = "${aws_vpc.your_vpc.id}" # Replace with your actual VPC ID

  # Allow incoming traffic from your cluster's custom security group
  ingress {
    from_port                = 0
    to_port                  = 65535
    protocol                 = "tcp"
    source_security_group_id = "${aws_security_group.emr_cluster_sg.id}" # Your cluster's SG
  }

  # Allow all outbound traffic (adjust based on your security requirements)
  egress {
    from_port   = 0
    to_port     = 65535
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }
}

Step 2: Attach It to Your EMR Cluster

Add the service_access_security_group_id parameter to your aws_emr_cluster resource, pointing to the security group you just created:

resource "aws_emr_cluster" "emr-test-cluster" {
  # ... Your existing cluster configuration (name, release_label, instance groups, etc.) ...

  # Add this line to resolve the validation error
  service_access_security_group_id = "${aws_security_group.emr_service_access.id}"
}

2. Upgrade the AWS Provider (If Feasible)

The GitHub fix you referenced addresses this issue by automatically handling the service access security group for private subnet clusters. If you can upgrade your AWS provider version (without upgrading Terraform 0.11.7 itself), specify a provider version that includes this fix.

For Terraform 0.11.7, a compatible provider version with the fix is around ~> 1.10.0 (you can confirm via the provider's release notes). Update your provider block like this:

provider "aws" {
  version = "~> 1.10.0"
  region  = "your-aws-region" # e.g., us-east-1
}

Note: Always test provider upgrades in a non-production environment first to catch any compatibility quirks with your existing configuration.

3. Verify Bidirectional Security Group Rules

Double-check that your cluster's main custom security group allows traffic from the service access security group too—bidirectional communication is required for EMR to manage the cluster properly. Add this ingress rule if missing:

resource "aws_security_group" "emr_cluster_sg" {
  # ... Existing configuration ...

  # Allow traffic from the service access security group
  ingress {
    from_port                = 0
    to_port                  = 65535
    protocol                 = "tcp"
    source_security_group_id = "${aws_security_group.emr_service_access.id}"
  }
}

This should resolve the TERMINATED_WITH_ERRORS: VALIDATION_ERROR and let your EMR cluster launch successfully in the private subnet.

内容的提问来源于stack exchange,提问作者Raghunandan Sk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:25:11