如何在地形中拆分地图的值以创建列表?

时间:2017-07-28 00:16:57

标签: dictionary terraform

我有一个包含许多值的地图变量(NACL规则)。我正在尝试相应地添加规则

variable "rules" {
  default = {
    a = "200,false,tcp,allow,0.0.0.0/0,23,23"
    b = "100,true,tcp,allow,0.0.0.0/0,1024,65535"
  }
}


resource "aws_network_acl_rule" "bar" {
  network_acl_id = "<id>"
  rule_number    = "${split(",",element(values(var.rules),count.index))[0]}"
  egress         = "${split(",",element(values(var.rules),count.index))[1]}"
  protocol       = "${split(",",element(values(var.rules),count.index))[2]}"
  rule_action    = "${split(",",element(values(var.rules),count.index))[3]}"
  cidr_block     = "${split(",",element(values(var.rules),count.index))[4]}"
  from_port      = "${split(",",element(values(var.rules),count.index))[5]}"
  to_port        = "${split(",",element(values(var.rules),count.index))[6]}"
  count          = "${length(values(var.rules))}"
}

错误: expected "}" but found "["

由于不支持带有列表值的地图,我试图拆分值并迭代

2 个答案:

答案 0 :(得分:12)

另一个更容易阅读的选项是使用lookup()

variable "rules" {
  default = [
    {
      rule_number = 200
      egress = false
      protocol = "tcp"
      rule_action = "allow"
      cidr_block = "0.0.0.0/0"
      from_port= 23
      to_port = 23
    },
    {
      rule_number = 100
      egress = true
      procotol = "tcp"
      rule_action = "allow"
      cidr_block = "0.0.0.0/0"
      from_port = 1024
      to_port = 65535
    },
  ]
}

resource "aws_network_acl_rule" "bar" {
  count          = "${length(var.rules)}"
  network_acl_id = "<id>"
  rule_number    = "${lookup(var.rules[count.index], "rule_number")}"
  egress         = "${lookup(var.rules[count.index], "egress")}"
  protocol       = "${lookup(var.rules[count.index], "protocol")}"
  rule_action    = "${lookup(var.rules[count.index], "rule_action")}"
  cidr_block     = "${lookup(var.rules[count.index], "cidr_block")}"
  from_port      = "${lookup(var.rules[count.index], "from_port")}"
  to_port        = "${lookup(var.rules[count.index], "to_port")}"
}

答案 1 :(得分:5)

以下是处理地图rules

的更简单方法
variable "rules" {
  default = {
   "0" = "200,false,tcp,allow,0.0.0.0/0,23,23"
   "1" = "100,true,tcp,allow,0.0.0.0/0,1024,65535"
  }
}

resource "aws_vpc" "main" {
  cidr_block = "10.0.0.0/16"
}

resource "aws_network_acl" "bar" {
  vpc_id = "${aws_vpc.main.id}"
}

resource "aws_network_acl_rule" "bar" {
  count          = "${length(var.rules)}"
  network_acl_id = "${aws_network_acl.bar.id}"
  rule_number    = "${element(split(",",var.rules[count.index]),0)}"
  egress         = "${element(split(",",var.rules[count.index]),1)}"
  protocol       = "${element(split(",",var.rules[count.index]),2)}"
  rule_action    = "${element(split(",",var.rules[count.index]),3)}"
  cidr_block     = "${element(split(",",var.rules[count.index]),4)}"
  from_port      = "${element(split(",",var.rules[count.index]),5)}"
  to_port        = "${element(split(",",var.rules[count.index]),6)}"
}

如果你坚持使用旧地图,键是“a,b,...”,你需要调整资源

variable "rules" {
  default = {
    "a" = "200,false,tcp,allow,0.0.0.0/0,23,23"
    "b" = "100,true,tcp,allow,0.0.0.0/0,1024,65535"
  }
}

resource "aws_network_acl_rule" "bar" {
  count          = "${length(var.rules)}"
  network_acl_id = "${aws_network_acl.bar.id}"
  rule_number    = "${element(split(",",element(values(var.rules),count.index)),0)}"
  egress         = "${element(split(",",element(values(var.rules),count.index)),1)}"
  protocol       = "${element(split(",",element(values(var.rules),count.index)),2)}"
  rule_action    = "${element(split(",",element(values(var.rules),count.index)),3)}"
  cidr_block     = "${element(split(",",element(values(var.rules),count.index)),4)}"
  from_port      = "${element(split(",",element(values(var.rules),count.index)),5)}"
  to_port        = "${element(split(",",element(values(var.rules),count.index)),6)}"
}