{"id":33147,"date":"2023-04-25T19:42:44","date_gmt":"2023-02-12T01:06:06","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/"},"modified":"2024-04-30T01:16:51","modified_gmt":"2024-04-29T17:16:51","slug":"%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/","title":{"rendered":"\u4f7f\u7528Terraform\uff08Fargate\uff09\u90e8\u7f72Nginx"},"content":{"rendered":"<h1>\u9996\u5148<\/h1>\n<p>\u8fd9\u662f\u4e00\u4e2a\u5173\u4e8e\u5b66\u4e60Terraform\u7684\u5907\u5fd8\u5f55\u3002<\/p>\n<p>\u8bf7\u70b9\u51fb\u8fd9\u91cc\u67e5\u770b\u76ee\u5f55\u3002<\/p>\n<p>&nbsp;<\/p>\n<h1>terraform\u914d\u7f6e<\/h1>\n<h2>\u6587\u4ef6\u7ed3\u6784<\/h2>\n<pre class=\"post-pre\"><code>.\r\n\u251c\u2500\u2500 Dockerfile\r\n\u251c\u2500\u2500 nginx\r\n\u2502   \u2514\u2500\u2500 index.html\r\n\u2514\u2500\u2500 terraform\r\n    \u251c\u2500\u2500 main.tf\r\n    \u251c\u2500\u2500 modules\r\n    \u2502   \u251c\u2500\u2500 bash\r\n    \u2502   \u2502   \u2514\u2500\u2500 null_resource.tf\r\n    \u2502   \u251c\u2500\u2500 ecr\r\n    \u2502   \u2502   \u2514\u2500\u2500 ecr.tf\r\n    \u2502   \u251c\u2500\u2500 ecs\r\n    \u2502   \u2502   \u251c\u2500\u2500 ecs.tf\r\n    \u2502   \u2502   \u251c\u2500\u2500 ecs_service.tf\r\n    \u2502   \u2502   \u2514\u2500\u2500 ecs_task_definition.tf\r\n    \u2502   \u251c\u2500\u2500 iam\r\n    \u2502   \u2502   \u251c\u2500\u2500 aws_iam_policy.tf\r\n    \u2502   \u2502   \u251c\u2500\u2500 aws_iam_policy_attachment.tf\r\n    \u2502   \u2502   \u251c\u2500\u2500 aws_iam_role.tf\r\n    \u2502   \u2502   \u2514\u2500\u2500 outputs.tf\r\n    \u2502   \u2514\u2500\u2500 network\r\n    \u2502       \u251c\u2500\u2500 aws_vpc.tf\r\n    \u2502       \u251c\u2500\u2500 igw.tf\r\n    \u2502       \u251c\u2500\u2500 outputs.tf\r\n    \u2502       \u251c\u2500\u2500 route_table.tf\r\n    \u2502       \u251c\u2500\u2500 security_group.tf\r\n    \u2502       \u251c\u2500\u2500 security_group_rule.tf\r\n    \u2502       \u2514\u2500\u2500 subnet.tf\r\n    \u251c\u2500\u2500 terraform.tfstate\r\n    \u251c\u2500\u2500 terraform.tfstate.backup\r\n    \u2514\u2500\u2500 variables.tf\r\n<\/code><\/pre>\n<h2>\u7f51\u7edc\u914d\u7f6e<\/h2>\n<p>\u6211\u4eec\u91c7\u7528\u4ece\u672c\u5730\u63a8\u9001\u5230ECR\u7684dockerimage\uff0c\u5728fargate\u4e0a\u62c9\u53d6\u5e76\u90e8\u7f72\u7684\u65b9\u6cd5\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d15f237434c4406bffc19\/9-0.png\" alt=\"fargate.png\" \/><\/div>\n<h2>Dockerfile\u548cHTML\u6587\u4ef6<\/h2>\n<p>\u6211\u8bbe\u5b9a\u4e86\u4e00\u4e2a\u7b80\u5355\u7684\u6784\u6210\uff0c\u4ee5\u5728\u753b\u9762\u4e0a\u8f93\u51fa&#8221;Hello world!!!!!!!!!!!&#8221;\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"k\">FROM<\/span><span class=\"s\"> nginx:latest<\/span>\r\n\r\n<span class=\"k\">COPY<\/span><span class=\"s\"> .\/nginx \/usr\/share\/nginx\/html<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"cp\">&lt;!DOCTYPE html&gt;<\/span>\r\n<span class=\"nt\">&lt;html<\/span> <span class=\"na\">lang=<\/span><span class=\"s\">\"ja\"<\/span><span class=\"nt\">&gt;<\/span>\r\n\r\n<span class=\"nt\">&lt;head&gt;<\/span>\r\n    <span class=\"nt\">&lt;meta<\/span> <span class=\"na\">charset=<\/span><span class=\"s\">\"UTF-8\"<\/span> <span class=\"nt\">\/&gt;<\/span>\r\n    <span class=\"nt\">&lt;meta<\/span> <span class=\"na\">http-equiv=<\/span><span class=\"s\">\"X-UA-Compatible\"<\/span> <span class=\"na\">content=<\/span><span class=\"s\">\"IE=edge\"<\/span> <span class=\"nt\">\/&gt;<\/span>\r\n    <span class=\"nt\">&lt;meta<\/span> <span class=\"na\">name=<\/span><span class=\"s\">\"viewport\"<\/span> <span class=\"na\">content=<\/span><span class=\"s\">\"width=device-width, initial-scale=1.0\"<\/span> <span class=\"nt\">\/&gt;<\/span>\r\n    <span class=\"nt\">&lt;title&gt;<\/span>Document<span class=\"nt\">&lt;\/title&gt;<\/span>\r\n<span class=\"nt\">&lt;\/head&gt;<\/span>\r\n\r\n<span class=\"nt\">&lt;body&gt;<\/span>\r\n    <span class=\"nt\">&lt;div<\/span> <span class=\"na\">style=<\/span><span class=\"s\">\"  line-height: 200px;height: 200px;text-align: center;\"<\/span><span class=\"nt\">&gt;<\/span>\r\n        <span class=\"nt\">&lt;p<\/span> <span class=\"na\">style=<\/span><span class=\"s\">\"  line-height: 1.5;display: inline-block;vertical-align: middle;\"<\/span><span class=\"nt\">&gt;<\/span>\r\n            Hello world!!!!!!!!!!!\r\n        <span class=\"nt\">&lt;\/p&gt;<\/span>\r\n    <span class=\"nt\">&lt;\/div&gt;<\/span>\r\n<span class=\"nt\">&lt;\/body&gt;<\/span>\r\n\r\n<span class=\"nt\">&lt;\/html&gt;<\/span>\r\n\r\n<\/code><\/pre>\n<h2>\u4e3b\u8981\u7684.tf\u6587\u4ef6<\/h2>\n<p>\u6bcf\u4e2aoutput.tf\u662f\u4e3a\u4e86\u901a\u8fc7main.tf\u5c06\u6570\u636e\u4f20\u8f93\u7ed9\u5176\u4ed6\u6a21\u5757\u800c\u5b58\u5728\u7684\uff0c\u4e0d\u8fc7\u8fd9\u91cc\u7701\u7565\u4e86\u89e3\u91ca\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"k\">provider<\/span> <span class=\"s2\">\"aws\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">region<\/span>      <span class=\"p\">=<\/span> <span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">region<\/span>\r\n<span class=\"p\">}<\/span>\r\n\r\n<span class=\"c1\"># IAM<\/span>\r\n<span class=\"k\">module<\/span> <span class=\"s2\">\"iam\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">source<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\".\/modules\/iam\"<\/span>\r\n<span class=\"p\">}<\/span>\r\n\r\n<span class=\"c1\"># ECR<\/span>\r\n<span class=\"k\">module<\/span> <span class=\"s2\">\"ecr\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">source<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\".\/modules\/ecr\"<\/span>\r\n  <span class=\"nx\">image_name<\/span> <span class=\"p\">=<\/span> <span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">image_name<\/span>\r\n<span class=\"p\">}<\/span>\r\n\r\n<span class=\"c1\"># Null Resource<\/span>\r\n<span class=\"k\">module<\/span> <span class=\"s2\">\"after_ecr\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">source<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\".\/modules\/bash\"<\/span>\r\n  <span class=\"nx\">region<\/span> <span class=\"p\">=<\/span> <span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">region<\/span>\r\n  <span class=\"nx\">image_name<\/span> <span class=\"p\">=<\/span> <span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">image_name<\/span>\r\n<span class=\"p\">}<\/span>\r\n\r\n<span class=\"c1\"># network<\/span>\r\n<span class=\"k\">module<\/span> <span class=\"s2\">\"network\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">source<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\".\/modules\/network\"<\/span>\r\n  <span class=\"nx\">app_name<\/span> <span class=\"p\">=<\/span> <span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">app_name<\/span>\r\n<span class=\"p\">}<\/span>\r\n\r\n<span class=\"c1\"># ECS<\/span>\r\n<span class=\"k\">module<\/span> <span class=\"s2\">\"ecs\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">source<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\".\/modules\/ecs\"<\/span>\r\n  <span class=\"nx\">app_name<\/span> <span class=\"p\">=<\/span> <span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">app_name<\/span>\r\n  <span class=\"nx\">vpc_id<\/span>       <span class=\"p\">=<\/span> <span class=\"k\">module<\/span><span class=\"p\">.<\/span><span class=\"nx\">network<\/span><span class=\"p\">.<\/span><span class=\"nx\">security<\/span><span class=\"err\">-<\/span><span class=\"nx\">group<\/span><span class=\"err\">-<\/span><span class=\"nx\">id<\/span>\r\n  <span class=\"nx\">subnet_id<\/span>    <span class=\"p\">=<\/span> <span class=\"k\">module<\/span><span class=\"p\">.<\/span><span class=\"nx\">network<\/span><span class=\"p\">.<\/span><span class=\"nx\">subnet<\/span><span class=\"err\">-<\/span><span class=\"nx\">public<\/span><span class=\"err\">-<\/span><span class=\"mi\">1<\/span><span class=\"nx\">a<\/span><span class=\"err\">-<\/span><span class=\"nx\">id<\/span>\r\n  <span class=\"nx\">aws_iam_role<\/span> <span class=\"p\">=<\/span>  <span class=\"k\">module<\/span><span class=\"p\">.<\/span><span class=\"nx\">iam<\/span><span class=\"p\">.<\/span><span class=\"nx\">aws_iam_role<\/span>\r\n\r\n<span class=\"p\">}<\/span>\r\n\r\n<\/code><\/pre>\n<h2>\u6211\u7ec4\u6210<\/h2>\n<pre class=\"post-pre\"><code><span class=\"k\">resource<\/span> <span class=\"s2\">\"aws_iam_role\"<\/span> <span class=\"s2\">\"newworld_role\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">name<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"newworld_role\"<\/span>\r\n\r\n  <span class=\"nx\">assume_role_policy<\/span> <span class=\"p\">=<\/span> <span class=\"nx\">jsonencode<\/span><span class=\"p\">({<\/span>\r\n    <span class=\"nx\">Version<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"2012-10-17\"<\/span>\r\n    <span class=\"nx\">Statement<\/span> <span class=\"p\">=<\/span> <span class=\"p\">[<\/span>\r\n      <span class=\"p\">{<\/span>\r\n        <span class=\"nx\">Sid<\/span><span class=\"err\">:<\/span> <span class=\"s2\">\"\"<\/span>\r\n        <span class=\"nx\">Action<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"sts:AssumeRole\"<\/span>\r\n        <span class=\"nx\">Effect<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"Allow\"<\/span>\r\n        <span class=\"nx\">Principal<\/span> <span class=\"p\">=<\/span> <span class=\"p\">{<\/span>\r\n          <span class=\"nx\">Service<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"ecs-tasks.amazonaws.com\"<\/span>\r\n        <span class=\"p\">}<\/span>\r\n      <span class=\"p\">},<\/span>\r\n    <span class=\"p\">]<\/span>\r\n  <span class=\"p\">})<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<p>&#8220;ecr:*&#8221;\u7684\u63cf\u8ff0\u4f7f\u5f97Fargate\u80fd\u591f\u8fdb\u884c\u62c9\u53d6\u3002<br \/>\n\u5982\u679c\u6ca1\u6709\u8fd9\u4e2a\u63cf\u8ff0\uff0c\u5c06\u4f1a\u51fa\u73b0400\u9519\u8bef\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"k\">resource<\/span> <span class=\"s2\">\"aws_iam_policy\"<\/span> <span class=\"s2\">\"newworld_policy\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">name<\/span>        <span class=\"p\">=<\/span> <span class=\"s2\">\"test_policy\"<\/span>\r\n\r\n  <span class=\"nx\">policy<\/span> <span class=\"p\">=<\/span> <span class=\"nx\">jsonencode<\/span><span class=\"p\">({<\/span>\r\n    <span class=\"nx\">Version<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"2012-10-17\"<\/span>\r\n    <span class=\"nx\">Statement<\/span> <span class=\"p\">=<\/span> <span class=\"p\">[<\/span>\r\n      <span class=\"p\">{<\/span>\r\n        <span class=\"nx\">Action<\/span> <span class=\"p\">=<\/span> <span class=\"p\">[<\/span>\r\n          <span class=\"s2\">\"ecr:*\"<\/span><span class=\"p\">,<\/span>\r\n        <span class=\"p\">]<\/span>\r\n        <span class=\"nx\">Effect<\/span>   <span class=\"p\">=<\/span> <span class=\"s2\">\"Allow\"<\/span>\r\n        <span class=\"nx\">Resource<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"*\"<\/span>\r\n      <span class=\"p\">},<\/span>\r\n    <span class=\"p\">]<\/span>\r\n  <span class=\"p\">})<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"k\">resource<\/span> <span class=\"s2\">\"aws_iam_policy_attachment\"<\/span> <span class=\"s2\">\"attach\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">name<\/span>       <span class=\"p\">=<\/span> <span class=\"s2\">\"iam-attach\"<\/span>\r\n  <span class=\"nx\">roles<\/span>      <span class=\"p\">=<\/span> <span class=\"p\">[<\/span><span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"nx\">aws_iam_role<\/span><span class=\"p\">.<\/span><span class=\"nx\">newworld_role<\/span><span class=\"p\">.<\/span><span class=\"nx\">name<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span><span class=\"p\">]<\/span>\r\n  <span class=\"nx\">policy_arn<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"nx\">aws_iam_policy<\/span><span class=\"p\">.<\/span><span class=\"nx\">newworld_policy<\/span><span class=\"p\">.<\/span><span class=\"nx\">arn<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<h2>ECR\u5efa\u7acb<\/h2>\n<pre class=\"post-pre\"><code><span class=\"k\">variable<\/span> <span class=\"s2\">\"image_name\"<\/span> <span class=\"p\">{}<\/span>\r\n\r\n<span class=\"k\">resource<\/span> <span class=\"s2\">\"aws_ecr_repository\"<\/span> <span class=\"s2\">\"repository\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">name<\/span>                 <span class=\"p\">=<\/span> <span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">image_name<\/span>\r\n  <span class=\"nx\">image_tag_mutability<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"IMMUTABLE\"<\/span>\r\n  <span class=\"nx\">force_delete<\/span>         <span class=\"p\">=<\/span> <span class=\"kc\">true<\/span>\r\n\r\n  <span class=\"nx\">image_scanning_configuration<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">scan_on_push<\/span> <span class=\"p\">=<\/span> <span class=\"kc\">true<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<h2>\u7a7a\u7f3a\u8d44\u6e90\u7684\u6784\u6210<\/h2>\n<p>\u5b8c\u6210ECR\u6784\u5efa\u540e\uff0c\u5c06docker\u955c\u50cf\u81ea\u52a8\u63a8\u9001\u81f3ECR\u3002\u6211\u4eec\u6b63\u5728\u4f7f\u7528terraform\u6267\u884c\u4ee5\u4e0b\u63cf\u8ff0\u7684\u64cd\u4f5c\u3002<\/p>\n<blockquote><p>aws ecr get-login-password &#8211;region ap-northeast-1 | docker login &#8211;username AWS &#8211;password-stdin AWS\u7684\u8d26\u53f7ID.dkr.ecr.ap-northeast-1.amazonaws.com<br \/>\ndocker tag hello-world-from-ecs:latest AWS\u7684\u8d26\u53f7ID.dkr.ecr.ap-northeast-1.amazonaws.com\/hello-world-from-ecs:latest<br \/>\ndocker push AWS\u7684\u8d26\u53f7ID.dkr.ecr.ap-northeast-1.amazonaws.com\/hello-world-from-ecs:latest<\/p><\/blockquote>\n<p>aws_caller_identity\u8c03\u7528\u4e86AWS\u7684\u8d26\u6237ID\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"k\">data<\/span> <span class=\"s2\">\"aws_caller_identity\"<\/span> <span class=\"s2\">\"self\"<\/span> <span class=\"p\">{<\/span> <span class=\"p\">}<\/span>\r\n<span class=\"k\">variable<\/span> <span class=\"s2\">\"image_name\"<\/span> <span class=\"p\">{}<\/span>\r\n<span class=\"k\">variable<\/span> <span class=\"s2\">\"region\"<\/span> <span class=\"p\">{}<\/span>\r\n\r\n<span class=\"k\">resource<\/span> <span class=\"s2\">\"null_resource\"<\/span> <span class=\"s2\">\"default\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"k\">provisioner<\/span> <span class=\"s2\">\"local-exec\"<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">command<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"aws ecr get-login-password --region <\/span><span class=\"k\">${<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">region<\/span><span class=\"k\">}<\/span><span class=\"s2\"> | docker login --username AWS --password-stdin <\/span><span class=\"k\">${data<\/span><span class=\"p\">.<\/span><span class=\"nx\">aws_caller_identity<\/span><span class=\"p\">.<\/span><span class=\"nx\">self<\/span><span class=\"p\">.<\/span><span class=\"nx\">account_id<\/span><span class=\"k\">}<\/span><span class=\"s2\">.dkr.ecr.ap-northeast-1.amazonaws.com\"<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"k\">provisioner<\/span> <span class=\"s2\">\"local-exec\"<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">command<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"docker tag <\/span><span class=\"k\">${<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">image_name<\/span><span class=\"k\">}<\/span><span class=\"s2\">:latest <\/span><span class=\"k\">${data<\/span><span class=\"p\">.<\/span><span class=\"nx\">aws_caller_identity<\/span><span class=\"p\">.<\/span><span class=\"nx\">self<\/span><span class=\"p\">.<\/span><span class=\"nx\">account_id<\/span><span class=\"k\">}<\/span><span class=\"s2\">.dkr.ecr.ap-northeast-1.amazonaws.com\/<\/span><span class=\"k\">${<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">image_name<\/span><span class=\"k\">}<\/span><span class=\"s2\">:latest\"<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"k\">provisioner<\/span> <span class=\"s2\">\"local-exec\"<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">command<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"docker push <\/span><span class=\"k\">${data<\/span><span class=\"p\">.<\/span><span class=\"nx\">aws_caller_identity<\/span><span class=\"p\">.<\/span><span class=\"nx\">self<\/span><span class=\"p\">.<\/span><span class=\"nx\">account_id<\/span><span class=\"k\">}<\/span><span class=\"s2\">.dkr.ecr.ap-northeast-1.amazonaws.com\/<\/span><span class=\"k\">${<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">image_name<\/span><span class=\"k\">}<\/span><span class=\"s2\">:latest\"<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<span class=\"p\">}<\/span>\r\n\r\n<\/code><\/pre>\n<h2>\u7f51\u7edc\u6784\u5efa<\/h2>\n<p>\u56e0\u4e3a\u592a\u957f\uff0c\u6211\u4f1a\u7b80\u7565\u5730\u8bf4\u3002<\/p>\n<h2>\u4e91\u8ba1\u7b97\u7cfb\u7edf\u67b6\u6784<\/h2>\n<pre class=\"post-pre\"><code><span class=\"k\">variable<\/span> <span class=\"s2\">\"app_name\"<\/span> <span class=\"p\">{}<\/span>\r\n\r\n<span class=\"k\">resource<\/span> <span class=\"s2\">\"aws_ecs_cluster\"<\/span> <span class=\"s2\">\"newworld-cluster\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">name<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">app_name<\/span><span class=\"k\">}<\/span><span class=\"s2\">-cluster\"<\/span>\r\n<span class=\"p\">}<\/span>\r\n\r\n<span class=\"k\">resource<\/span> <span class=\"s2\">\"aws_ecs_cluster_capacity_providers\"<\/span> <span class=\"s2\">\"newworld_capacity_providers\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">cluster_name<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">app_name<\/span><span class=\"k\">}<\/span><span class=\"s2\">-cluster\"<\/span>\r\n  <span class=\"nx\">capacity_providers<\/span> <span class=\"p\">=<\/span> <span class=\"p\">[<\/span><span class=\"s2\">\"FARGATE\"<\/span><span class=\"p\">]<\/span>\r\n\r\n  <span class=\"nx\">default_capacity_provider_strategy<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">base<\/span>              <span class=\"p\">=<\/span> <span class=\"mi\">1<\/span>\r\n    <span class=\"nx\">weight<\/span>            <span class=\"p\">=<\/span> <span class=\"mi\">100<\/span>\r\n    <span class=\"nx\">capacity_provider<\/span> <span class=\"p\">=<\/span> <span class=\"s2\">\"FARGATE\"<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"k\">variable<\/span> <span class=\"s2\">\"vpc_id\"<\/span> <span class=\"p\">{}<\/span>\r\n<span class=\"k\">variable<\/span> <span class=\"s2\">\"subnet_id\"<\/span> <span class=\"p\">{}<\/span>\r\n\r\n<span class=\"k\">resource<\/span> <span class=\"s2\">\"aws_ecs_service\"<\/span> <span class=\"s2\">\"newworld-service\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">name<\/span>            <span class=\"p\">=<\/span> <span class=\"s2\">\"nginx-service\"<\/span>\r\n  <span class=\"nx\">cluster<\/span>         <span class=\"p\">=<\/span> <span class=\"nx\">aws_ecs_cluster<\/span><span class=\"p\">.<\/span><span class=\"nx\">newworld<\/span><span class=\"err\">-<\/span><span class=\"nx\">cluster<\/span><span class=\"p\">.<\/span><span class=\"nx\">id<\/span>\r\n  <span class=\"nx\">task_definition<\/span> <span class=\"p\">=<\/span> <span class=\"nx\">aws_ecs_task_definition<\/span><span class=\"p\">.<\/span><span class=\"nx\">newworld<\/span><span class=\"err\">-<\/span><span class=\"nx\">definition<\/span><span class=\"p\">.<\/span><span class=\"nx\">arn<\/span>\r\n  <span class=\"nx\">desired_count<\/span>   <span class=\"p\">=<\/span> <span class=\"mi\">1<\/span>\r\n\r\n  <span class=\"nx\">network_configuration<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">security_groups<\/span>  <span class=\"p\">=<\/span> <span class=\"p\">[<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">vpc_id<\/span><span class=\"p\">]<\/span>\r\n    <span class=\"nx\">subnets<\/span>          <span class=\"p\">=<\/span> <span class=\"p\">[<\/span><span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">subnet_id<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span><span class=\"p\">]<\/span>\r\n    <span class=\"nx\">assign_public_ip<\/span> <span class=\"p\">=<\/span> <span class=\"kc\">true<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"nx\">lifecycle<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">ignore_changes<\/span> <span class=\"p\">=<\/span> <span class=\"p\">[<\/span><span class=\"nx\">desired_count<\/span><span class=\"p\">]<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"k\">variable<\/span> <span class=\"s2\">\"vpc_id\"<\/span> <span class=\"p\">{}<\/span>\r\n<span class=\"k\">variable<\/span> <span class=\"s2\">\"subnet_id\"<\/span> <span class=\"p\">{}<\/span>\r\n\r\n<span class=\"k\">resource<\/span> <span class=\"s2\">\"aws_ecs_service\"<\/span> <span class=\"s2\">\"newworld-service\"<\/span> <span class=\"p\">{<\/span>\r\n  <span class=\"nx\">name<\/span>            <span class=\"p\">=<\/span> <span class=\"s2\">\"nginx-service\"<\/span>\r\n  <span class=\"nx\">cluster<\/span>         <span class=\"p\">=<\/span> <span class=\"nx\">aws_ecs_cluster<\/span><span class=\"p\">.<\/span><span class=\"nx\">newworld<\/span><span class=\"err\">-<\/span><span class=\"nx\">cluster<\/span><span class=\"p\">.<\/span><span class=\"nx\">id<\/span>\r\n  <span class=\"nx\">task_definition<\/span> <span class=\"p\">=<\/span> <span class=\"nx\">aws_ecs_task_definition<\/span><span class=\"p\">.<\/span><span class=\"nx\">newworld<\/span><span class=\"err\">-<\/span><span class=\"nx\">definition<\/span><span class=\"p\">.<\/span><span class=\"nx\">arn<\/span>\r\n  <span class=\"nx\">desired_count<\/span>   <span class=\"p\">=<\/span> <span class=\"mi\">1<\/span>\r\n\r\n  <span class=\"nx\">network_configuration<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">security_groups<\/span>  <span class=\"p\">=<\/span> <span class=\"p\">[<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">vpc_id<\/span><span class=\"p\">]<\/span>\r\n    <span class=\"nx\">subnets<\/span>          <span class=\"p\">=<\/span> <span class=\"p\">[<\/span><span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"kd\">var<\/span><span class=\"p\">.<\/span><span class=\"nx\">subnet_id<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span><span class=\"p\">]<\/span>\r\n    <span class=\"nx\">assign_public_ip<\/span> <span class=\"p\">=<\/span> <span class=\"kc\">true<\/span>\r\n  <span class=\"p\">}<\/span>\r\n\r\n  <span class=\"nx\">lifecycle<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"nx\">ignore_changes<\/span> <span class=\"p\">=<\/span> <span class=\"p\">[<\/span><span class=\"nx\">desired_count<\/span><span class=\"p\">]<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<h1>\u7ed3\u679c-<\/h1>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d15f237434c4406bffc19\/36-0.png\" alt=\"Screenshot 2023-02-25 at 20.44.16.png\" \/><\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u9996\u5148 \u8fd9\u662f\u4e00\u4e2a\u5173\u4e8e\u5b66\u4e60Terraform\u7684\u5907\u5fd8\u5f55\u3002 \u8bf7\u70b9\u51fb\u8fd9\u91cc\u67e5\u770b\u76ee\u5f55\u3002 &nbsp; terraform\u914d\u7f6e [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-33147","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u4f7f\u7528Terraform\uff08Fargate\uff09\u90e8\u7f72Nginx - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528terraform\uff08fargate\uff09\u90e8\u7f72nginx\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u4f7f\u7528Terraform\uff08Fargate\uff09\u90e8\u7f72Nginx\" \/>\n<meta property=\"og:description\" content=\"\u9996\u5148 \u8fd9\u662f\u4e00\u4e2a\u5173\u4e8e\u5b66\u4e60Terraform\u7684\u5907\u5fd8\u5f55\u3002 \u8bf7\u70b9\u51fb\u8fd9\u91cc\u67e5\u770b\u76ee\u5f55\u3002 &nbsp; terraform\u914d\u7f6e [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528terraform\uff08fargate\uff09\u90e8\u7f72nginx\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-12T01:06:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-29T17:16:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d15f237434c4406bffc19\/9-0.png\" \/>\n<meta name=\"author\" content=\"\u5b87, \u534e\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u5b87, \u534e\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/\",\"name\":\"\u4f7f\u7528Terraform\uff08Fargate\uff09\u90e8\u7f72Nginx - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-02-12T01:06:06+00:00\",\"dateModified\":\"2024-04-29T17:16:51+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/513018e4e121d3add1b7c5de8be21458\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u4f7f\u7528Terraform\uff08Fargate\uff09\u90e8\u7f72Nginx\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/513018e4e121d3add1b7c5de8be21458\",\"name\":\"\u5b87, \u534e\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63cd45cbc05a35fc4ff7637a163c83c4962ef58d27472726c3a3e0c9c5194f0f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63cd45cbc05a35fc4ff7637a163c83c4962ef58d27472726c3a3e0c9c5194f0f?s=96&d=mm&r=g\",\"caption\":\"\u5b87, \u534e\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/yuhua\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u4f7f\u7528Terraform\uff08Fargate\uff09\u90e8\u7f72Nginx - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528terraform\uff08fargate\uff09\u90e8\u7f72nginx\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u4f7f\u7528Terraform\uff08Fargate\uff09\u90e8\u7f72Nginx","og_description":"\u9996\u5148 \u8fd9\u662f\u4e00\u4e2a\u5173\u4e8e\u5b66\u4e60Terraform\u7684\u5907\u5fd8\u5f55\u3002 \u8bf7\u70b9\u51fb\u8fd9\u91cc\u67e5\u770b\u76ee\u5f55\u3002 &nbsp; terraform\u914d\u7f6e [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528terraform\uff08fargate\uff09\u90e8\u7f72nginx\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-02-12T01:06:06+00:00","article_modified_time":"2024-04-29T17:16:51+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d15f237434c4406bffc19\/9-0.png"}],"author":"\u5b87, \u534e","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u5b87, \u534e","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"3 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/","name":"\u4f7f\u7528Terraform\uff08Fargate\uff09\u90e8\u7f72Nginx - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-02-12T01:06:06+00:00","dateModified":"2024-04-29T17:16:51+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/513018e4e121d3add1b7c5de8be21458"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u4f7f\u7528Terraform\uff08Fargate\uff09\u90e8\u7f72Nginx"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/513018e4e121d3add1b7c5de8be21458","name":"\u5b87, \u534e","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63cd45cbc05a35fc4ff7637a163c83c4962ef58d27472726c3a3e0c9c5194f0f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63cd45cbc05a35fc4ff7637a163c83c4962ef58d27472726c3a3e0c9c5194f0f?s=96&d=mm&r=g","caption":"\u5b87, \u534e"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/yuhua\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8terraform%ef%bc%88fargate%ef%bc%89%e9%83%a8%e7%bd%b2nginx%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/33147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=33147"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/33147\/revisions"}],"predecessor-version":[{"id":88798,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/33147\/revisions\/88798"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=33147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=33147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=33147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}