【问题标题】:Terraform Optional Parameter for List of String字符串列表的 Terraform 可选参数
【发布时间】:2021-08-31 04:41:49
【问题描述】:

尝试实现 Azure WAF policy and associate with http listener 代码工作正常,直到我尝试包含一个名为 http_listener_ids 的新可选参数

Tf 代码:

variable "http_listener_ids"{
  type = "list"
  description = "A list of HTTP Listener IDs from an azurerm_application_gateway"
  default = []
}



locals {  
  http_listener_ids ="${var.http_listener_ids}" == [] ? null: "${var.http_listener_ids}"
}
resource "azurerm_web_application_firewall_policy" "example" {
  name                = "example-wafpolicy"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location

  http_listener_ids   =  "${local.http_listener_ids}"

  custom_rules {
    name      = "Rule1"
    priority  = 1
    rule_type = "MatchRule"

    match_conditions {
      match_variables {
        variable_name = "RemoteAddr"
      }

      operator           = "IPMatch"
      negation_condition = false
      match_values       = ["192.168.1.0/24", "10.0.0.0/24"]
    }

    action = "Block"
  }

  custom_rules {
    name      = "Rule2"
    priority  = 2
    rule_type = "MatchRule"

    match_conditions {
      match_variables {
        variable_name = "RemoteAddr"
      }

      operator           = "IPMatch"
      negation_condition = false
      match_values       = ["192.168.1.0/24"]
    }

    match_conditions {
      match_variables {
        variable_name = "RequestHeaders"
        selector      = "UserAgent"
      }

      operator           = "Contains"
      negation_condition = false
      match_values       = ["Windows"]
    }

    action = "Block"
  }

  policy_settings {
    enabled                     = true
    mode                        = "Prevention"
    request_body_check          = true
    file_upload_limit_in_mb     = 100
    max_request_body_size_in_kb = 128
  }

  managed_rules {
    exclusion {
      match_variable          = "RequestHeaderNames"
      selector                = "x-company-secret-header"
      selector_match_operator = "Equals"
    }
    exclusion {
      match_variable          = "RequestCookieNames"
      selector                = "too-tasty"
      selector_match_operator = "EndsWith"
    }

    managed_rule_set {
      type    = "OWASP"
      version = "3.1"
      rule_group_override {
        rule_group_name = "REQUEST-920-PROTOCOL-ENFORCEMENT"
        disabled_rules = [
          "920300",
          "920440"
        ]
      }
    }
  }

}

我得到的错误是

错误:“http_listener_ids”:无法设置此字段

我认为http_listener_ids 属性没有跳过,而是尝试分配null 的值。所以我尝试实现动态块。但问题在于http_listener_ids 是一个简单的字符串列表,而不是这样的块。所以不知道在content里面放什么

    dynamic "http_listener_ids"{
    for_each = "${var.http_listener_ids}"
     content{
        ??
     }
   }

【问题讨论】:

    标签: terraform terraform-provider-azure terraform0.12+


    【解决方案1】:

    根据recent GitHub PR,http_listener_ids 是只读,不能设置。可能文档还没有更新。

    【讨论】:

      【解决方案2】:

      documentation for the azurerm_web_application_firewall_policy resource 已过期,但http_listener_ids and path_based_rule_ids are read only now(截至v2.55.0)因此您无法设置它们,只能将它们作为资源的属性读取。

      【讨论】:

        猜你喜欢
        • 1970-01-01
        • 2020-11-08
        • 2017-06-10
        • 2021-04-21
        • 2016-10-18
        • 2021-08-09
        • 2020-05-09
        • 2023-02-09
        • 2017-10-23
        相关资源
        最近更新 更多