为什么在 Terraform aws_route53_record 中出现错误“别名目标名称不在目标区域内”?

Joh*_*hee 10 amazon-route53 terraform-provider-aws

使用 Terraform 0.12,我在 S3 存储桶中创建了一个静态网站:

...

resource "aws_s3_bucket" "www" {
  bucket = "example.com"
  acl    = "public-read"
  policy = <<-POLICY
    {
      "Version": "2012-10-17",
      "Statement": [{
        "Sid": "AddPerm",
        "Effect": "Allow",
        "Principal": "*",
        "Action": ["s3:GetObject"],
        "Resource": ["arn:aws:s3:::example.com/*"]
      }]
    }
    POLICY
  website {
    index_document = "index.html"
    error_document = "404.html"
  }

  tags = {
    Environment = var.environment
    Terraform = "true"
  }
}

resource "aws_route53_zone" "main" {
  name = "example.com"

  tags = {
    Environment = var.environment
    Terraform = "true"
  }
}

resource "aws_route53_record" "main-ns" {
  zone_id = aws_route53_zone.main.zone_id
  name    = "example.com"
  type    = "A"
  alias {
    name                   = aws_s3_bucket.www.website_endpoint
    zone_id                = aws_route53_zone.main.zone_id
    evaluate_target_health = false
  }
}
Run Code Online (Sandbox Code Playgroud)

我收到错误:

Error: [ERR]: Error building changeset: InvalidChangeBatch:
[Tried to create an alias that targets example.com.s3-website-us-west-2.amazonaws.com., type A in zone Z1P...9HY, but the alias target name does not lie within the target zone, 
 Tried to create an alias that targets example.com.s3-website-us-west-2.amazonaws.com., type A in zone Z1P...9HY, but that target was not found]
    status code: 400, request id: 35...bc

  on main.tf line 132, in resource "aws_route53_record" "main-ns":
 132: resource "aws_route53_record" "main-ns" {
Run Code Online (Sandbox Code Playgroud)

怎么了?

Joh*_*hee 17

所述zone_idalias是S3桶区ID,而不是路由53区ID。正确的aws_route53_record资源是:

resource "aws_route53_record" "main-ns" {
  zone_id = aws_route53_zone.main.zone_id
  name    = "example.com"
  type    = "A"
  alias {
    name                   = aws_s3_bucket.www.website_endpoint
    zone_id                = aws_s3_bucket.www.hosted_zone_id    # Corrected
    evaluate_target_health = false
  }
}
Run Code Online (Sandbox Code Playgroud)

这是 CloudFront 的示例。变量是:

base_url = example.com
cloudfront_distribution = "EXXREDACTEDXXX"
domain_names = ["example.com", "www.example.com"]
Run Code Online (Sandbox Code Playgroud)

Terraform 代码是:

data "aws_route53_zone" "this" {
  name = var.base_url
}

data "aws_cloudfront_distribution" "this" {
  id = var.cloudfront_distribution
}

resource "aws_route53_record" "this" {
  for_each = toset(var.domain_names)
  zone_id = data.aws_route53_zone.this.zone_id
  name = each.value
  type = "A"
  alias {
    name    = data.aws_cloudfront_distribution.this.domain_name
    zone_id = data.aws_cloudfront_distribution.this.hosted_zone_id
    evaluate_target_health = false
  }
}
Run Code Online (Sandbox Code Playgroud)

许多用户指定 CloudFrontzone_id = "Z2FDTNDATAQYW2"是因为它总是Z2FDTNDATAQYW2......直到有一天可能不是。我喜欢通过使用 data source 计算它来避免文字字符串aws_cloudfront_distribution

  • 将其放在这里供任何寻找它的人使用:https://docs.aws.amazon.com/Route53/latest/APIReference/API_AliasTarget.html 对于 Cloudfront,它是标准的“HostedZoneID:Z2FDTNDATAQYW2” (3认同)