aws配置:安全组ID和名称不匹配

时间:2018-05-30 18:39:45

标签: amazon-web-services amazon-ec2 ssh terraform

我有以下配置:

resource "aws_security_group" "allow_ssh" {
  name = "allow_ssh"
  vpc_id = "${aws_default_vpc.default.id}"
  description = "Allow ssh connections on port 22"
  ingress {
      from_port = 22
      to_port = 22
      protocol = "tcp"
      cidr_blocks = ["0.0.0.0/0"]
  }
}

resource "aws_instance" "your-app" {
  ami           = "ami-2757f631"
  instance_type = "t2.micro"
  security_groups = ["${aws_security_group.allow_ssh.id}"]
  key_name = "${aws_key_pair.twilio_key.key_name}"
}

当我terraform apply时,我收到此错误:

* aws_instance.your-app: Error launching instance, possible mismatch of Security Group IDs and Names. See AWS Instance docs here: https://terraform.io/docs/providers/aws/r/instance.html.

        AWS Error: Value () for parameter groupId is invalid. The value cannot be empty

我该怎么做才能解决上述错误?

2 个答案:

答案 0 :(得分:3)

您必须将id更改为name才能使其正常工作:

resource "aws_instance" "twilio-app" {
  ami           = "ami-2757f631"
  instance_type = "t2.micro"
  key_name = "${aws_key_pair.twilio_key.key_name}"
  security_groups = [ "${aws_security_group.allow_ssh.name}" ]
}

它接受组名而不是id参数。

答案 1 :(得分:0)

我在这里添加另一个解决方案是因为遇到相同的问题,并且将安全组id更改为name并不能解决问题。

检查instance资源下的Terraform docs,我们可以看到security_groups参数的用法:

security_groups - (Optional, EC2-Classic and default VPC only) A list of security group names (EC2-Classic) or IDs (default VPC) to associate with.

在此之下,我们可以看到以下注释:

  

注意:如果要在VPC中创建实例,请使用   而是vpc_security_group_ids。

vpc_security_group_ids参数的描述:

vpc_security_group_ids - (Optional, VPC only) A list of security group IDs to associate with.

所以对我来说,从 security_groups 更改为 vpc_security_group_ids 已解决了该问题