【发布时间】:2020-12-31 00:16:54
【问题描述】:
每次我运行 terraform apply 时,aws_flow_log 资源的每个实例都需要更改
# module.us-west-2.aws_flow_log.flow_log[1] must be replaced
-/+ resource "aws_flow_log" "flow_log" {
...
+ iam_role_arn = "arn:aws:iam::xxx:role/vpc-flow-log-role" # forces replacement
...
当我在 AWS 控制台中访问 vpc 时,我发现 IAM 角色 ARN 不存在。
还有其他人遇到过这个问题吗?在这种情况下,日志目标是 s3 存储桶,而不是 cloudwatch_log_group。所以,这无关紧要:https://github.com/hashicorp/terraform-provider-aws/pull/6377。
【问题讨论】:
标签: terraform amazon-vpc