我正在尝试做下面这样的事情。
dynamic "volume" {
for_each = var.volumes
content {
host_path = lookup(volume.value, "host_path", null)
name = volume.value.name
dynamic "efs_volume" {
for_each = var.efs_volumes
content {
name = efs_volume.value.name
efs_volume_configuration {
file_system_id = efs_volume.value.file_system_id
root_directory = efs_volume.value.root_directory
transit_encryption = efs_volume.value.transit_encryption != "ENABLED" ? "" : "ENABLED"
dynamic "authorization_config" {
for_each = efs_volume.value.access_point_id != "" ? [1] : []
content {
access_point_id = volume.value.access_point_id
}
}
}
}
}
}
}
它给了我,
错误:不支持的块类型
此处不应使用类型为"efs_volume"的块
谁能指出我这里有什么问题?我正在使用地形 0.12.24。
请注意,我知道 AWS 提供商仍然不支持"authorization_config",我希望当我看到 github 拉取请求后,该功能将很快推出。因此,我正在准备我的代码兼容性。基本上,我需要的是将主机卷和 EFS 卷都挂载到我的 ECS 任务定义中。
编辑
我按照你说的更新了代码。
dynamic "volume" {
for_each = var.volumes
content {
host_path = lookup(volume.value, "host_path", null)
name = volume.value.name
dynamic "efs_volume_configuration" {
for_each = lookup(volume.value, "efs_volume_configuration", [])
content {
file_system_id = lookup(efs_volume_configuration.value, "file_system_id", null)
root_directory = lookup(efs_volume_configuration.value, "root_directory", null)
}
}
}
}```
Now the problem is,
> efs_volume_configuration
getting added to each volume block. Which actually need to be null.
``` + volume { # forces replacement
+ host_path = "/var/run"
+ name = "docker-sock-folder"
+ efs_volume_configuration {}
}
+ volume { # forces replacement
+ host_path = "/var/run/docker/netns"
+ name = "docker-netns"
+ efs_volume_configuration {}
}
+ volume { # forces replacement
+ name = "efs_share"
+ efs_volume_configuration {
+ file_system_id = "fs-xxxxxx"
+ root_directory = "/"
}
}
编辑
这是我的变种..
type = list(object({
name = string
host_path = string
efs_volume_configuration = list(object({
file_system_id = string
root_directory = string
}))
}))
description = "Task volume definitions as list of configuration objects"
default = [
{
"name" : "data-folder",
"host_path" : "/var/lib/data",
"efs_volume_configuration" = [
{
"file_system_id" : "",
"root_directory" : ""
}
]
},
{
"name" : "docker-sock-folder",
"host_path" : "/var/run",
"efs_volume_configuration" = [
{
"file_system_id" : "",
"root_directory" : ""
}
]
},
{
"name" : "efs_share",
"host_path" : null,
"efs_volume_configuration" = [
{
"file_system_id" : "fs-xxxxxx",
"root_directory" : "/"
}
]
}
....
对于 ecs 任务定义资源efs_volume不是受支持的参数。如果您正在寻找一个完全工作的模块,也许我编写的运行良好并发布到 terraform 注册表的模块可能会有所帮助。https://github.com/umotif-public/terraform-aws-ecs-fargate-task-definition/blob/master/main.tf#L157
要使用 efs 卷,您可以定义以下动态块:
dynamic "volume" {
for_each = var.volume
content {
name = volume.value.name
host_path = lookup(volume.value, "host_path", null)
dynamic "docker_volume_configuration" {
for_each = lookup(volume.value, "docker_volume_configuration", [])
content {
scope = lookup(docker_volume_configuration.value, "scope", null)
autoprovision = lookup(docker_volume_configuration.value, "autoprovision", null)
driver = lookup(docker_volume_configuration.value, "driver", null)
driver_opts = lookup(docker_volume_configuration.value, "driver_opts", null)
labels = lookup(docker_volume_configuration.value, "labels", null)
}
}
dynamic "efs_volume_configuration" {
for_each = lookup(volume.value, "efs_volume_configuration", [])
content {
file_system_id = lookup(efs_volume_configuration.value, "file_system_id", null)
root_directory = lookup(efs_volume_configuration.value, "root_directory", null)
}
}
}
在这种情况下,efs_volume_configuration是一个支撑块。在模块中拥有它后,您可以通过以下方式传入 efs 配置:
module "ecs-task-definition" {
...
volume = [
{
name = "efs-html",
efs_volume_configuration = [
{
"file_system_id" : "efs_id",
"root_directory" : "/usr/share/nginx"
}
]
}
]
}
重要提示:您至少需要 2.64.0 版的 terraform aws 提供程序。