0

阿罗哈,

TL&DR:

我正在尝试使用 terraform 而不是 awscli 或 awslocal 在本地创建一个 s3 存储桶,但我运行时遇到了一些错误。我想知道localstack是否支持这种方式。我不确定我在这里做错了什么,但我想我需要在这里使用 awscli 来创建 s3 存储桶。任何人都知道为什么不转发存储桶名称?

长版:

我正在使用 docker-compose.yaml 来定义 localstack docker 容器:

version: '3'

services:
  localstack:
    image: localstack/localstack:0.10.5
    ports:
    - "4572:4572"
    - "4584:4584"
    - "${PORT_WEB_UI-8080}:${PORT_WEB_UI-8080}"
    environment:
    - DEFAULT_REGION=eu-central-1
    - SERVICES=s3,secretsmanager
    - DEBUG=${DEBUG- }
    - DATA_DIR=${DATA_DIR- }
    - PORT_WEB_UI=${PORT_WEB_UI- }
    - DOCKER_HOST=${LOCALSTACK_DOCKER_HOST-unix:///var/run/docker.sock}
    - TF_VAR_localstack_host=localhost
    volumes:
    - "/var/run/docker.sock:/var/run/docker.sock"

我使用这个 terraform main.tf 来定义我想在 docker 容器中创建的内容:

variable "localstack_host" {
  default = "localhost"
}

provider "aws" {
  version = "~> 2.39.0"
  alias = "local"
  region = "eu-central-1"
  access_key = "This is not an actual access key."
  secret_key = "This is not an actual secret key."
  skip_credentials_validation = true
  skip_metadata_api_check     = true
  skip_requesting_account_id  = true
  endpoints {
    secretsmanager  = "http://${var.localstack_host}:4584"
    s3              = "http://${var.localstack_host}:4572"
  }
}

resource "aws_s3_bucket" "s3_encryption_test_bucket" {
  bucket = "s3-encryption-test-bucket"
  provider = "aws.local"
}

运行 docker 容器后,我将 terraform 文件应用到 localstack 的本地运行实例:

terraform plan
terraform apply

我从 terraform 得到的错误是:

aws_s3_bucket.s3_encryption_test_bucket: Creating...
  acceleration_status:         "" => "<computed>"
  acl:                         "" => "private"
  arn:                         "" => "<computed>"
  bucket:                      "" => "s3-encryption-test-bucket"
  bucket_domain_name:          "" => "<computed>"
  bucket_regional_domain_name: "" => "<computed>"
  force_destroy:               "" => "false"
  hosted_zone_id:              "" => "<computed>"
  region:                      "" => "<computed>"
  request_payer:               "" => "<computed>"
  versioning.#:                "" => "<computed>"
  website_domain:              "" => "<computed>"
  website_endpoint:            "" => "<computed>"
aws_s3_bucket.s3_encryption_test_bucket: Still creating... (10s elapsed)
aws_s3_bucket.s3_encryption_test_bucket: Still creating... (20s elapsed)
.....
aws_s3_bucket.s3_encryption_test_bucket: Still creating... (2m10s elapsed)
aws_s3_bucket.s3_encryption_test_bucket: Still creating... (2m20s elapsed)

Error: Error applying plan:

1 error(s) occurred:

* aws_s3_bucket.s3_encryption_test_bucket: 1 error(s) occurred:

* aws_s3_bucket.s3_encryption_test_bucket: error getting S3 Bucket CORS configuration: timeout while waiting for state to become 'success' (timeout: 2m0s)

我还查看了容器的日志并收到以下错误消息:

2019-12-12T13:24:45:ERROR:localstack.services.generic_proxy: Error forwarding request: Parameter validation failed:
Invalid bucket name "": Bucket name must match the regex "^[a-zA-Z0-9.\-_]{1,255}$" Traceback (most recent call last):
  File "/opt/code/localstack/localstack/services/generic_proxy.py", line 240, in forward
    path=path, data=data, headers=forward_headers).......
4

2 回答 2

0

我有同样的问题,我的解决方案是添加s3_force_path_style = trueprovider "aws"部分:

provider "aws" {
  ...
  s3_force_path_style = true
  ...
}
于 2021-10-05T07:56:14.850 回答
0

我遇到了同样的问题。简单地在资源块中定义 ACL 为我解决了它:

resource "aws_s3_bucket" "s3_encryption_test_bucket" {
  bucket = "s3-encryption-test-bucket"
  provider = "aws.local"
  acl = "private"
}
于 2020-05-07T06:37:10.793 回答