Terraform AWS subnet_id 列表被视为 ec2 实例的单值字符串

Terraform AWS subnet_id list is treated as single value string for ec2 instance

我有创建 VPC 的代码,有 2 个私有子网,私有的 2xec2 实例和 public 中的堡垒。

ec2 代码使用 VPC 模块 subnet_ids 的 outputs.tf。因为有 2 个私有子网,所以生成了 2 个 subnet_ids。当这些生成的 subnet_ids 被送入 ec2 实例而不是一个 subnet_id 时,它一次送入 2 subnet_ids 作为单个值。

因此 terraform 找不到 subnet_ids 值,创建失败。

错误: 子网 ID 'subnet-0***********,subnet-0*************' 不存在

编辑子网* vpc.tf

private_subnets     = "10.10.20.#/#,10.10.20.#/#"

instanceec2.tf

subnet_id           = "${module.vpc.private_subnets}"

以下是模块:

vpc_main.tf

// Private subnet/s
resource "aws_subnet" "private" {
  vpc_id            = "${aws_vpc.vpc.id}"
  cidr_block        = "${element(split(",", var.private_subnets), count.index)}"
  availability_zone = "${element(split(",", var.azs), count.index)}"
  count             = "${length(split(",", var.private_subnets))}"

  tags {
    Name        = "${var.name}-private-${element(split(",", var.azs), count.index)}"
    Team        = "${var.team}"
    Environment = "${var.environment}"
    Service     = "${var.service}"
    Product     = "${var.product}"
    Owner       = "${var.owner}"
    Description = "${var.description}"
    managed_by  = "terraform"
  }
}

resource "aws_route_table" "private" {
  vpc_id = "${aws_vpc.vpc.id}"
  count  = "${length(split(",", var.private_subnets))}"

  tags {
    Name        = "${var.name}-private-${element(split(",", var.azs), count.index)}"
    Team        = "${var.team}"
    Environment = "${var.environment}"
    Service     = "${var.service}"
    Product     = "${var.product}"
    Owner       = "${var.owner}"
    Description = "${var.description}"
    managed_by  = "terraform"
  }
}

resource "aws_route_table_association" "private" {
  subnet_id      = "${element(aws_subnet.private.*.id, count.index)}"
  route_table_id = "${element(aws_route_table.private.*.id, count.index)}"
  count          = "${length(split(",", var.private_subnets))}"
}
``````


vpc_outputs.tf

```````

output "private_subnets" {
  value = "${join(",", aws_subnet.private.*.id)}"
}

期望值只有一个子网ID作为值:

错误:提供 2 个子网 ID 作为一个值。

aws_instance.ec2-instance[0]:发生 1 个错误:

由于您已经“合并”了结果,如果您只需要一个子网值,则必须再次拆分。 类似于:

element(split(",", var.private_subnets), 0) 

您要在输出变量中加入子网 ID:

output "private_subnets" {
  value = "${join(",", aws_subnet.private.*.id)}"
}

当您从 instanceec2.tf 访问此输出值时,您将只会收到此连接的 ID 字符串。 因此,您必须再次像以前那样滑动接收到的值,并使用 ec2 资源的计数索引访问相应的个人 ID:

resource "aws_instance" "default" {
    count     = "${length(split(",", module.vpc.private_subnets))}"
    subnet_id = "${element(split(",", module.vpc.private_subnets), count.index)}"
    ....
}    

这应该可以解决您的问题。

或者,您也可以直接将子网 ID 作为列表输出:

output "private_subnets" {
  description = "The IDs of the private subnets as list"
  value       = ["${aws_subnet.private.*.id}"]
}

然后通过以下方式访问它们:

subnet_id = "${element(module.vpc.private_subnets, count.index)}"