0
votes

I am trying to add a variable called 'DeployNSG' as a true/false Boolean. When I reference the variable in the resource creation for the NSG using 'Count', I am then trying to associate the NSG with Azurerm_Network_security_group_association with a subnet and it's saying that I need to use count index in the association.. however If I then try and use element to reference an item, it says you can't use element if count isn't used within the subnet association.


resource "azurerm_network_security_group" "ProdNSG" {
  count = "${var.DeployNSG ? 1 : 0}"
  name                = "${var.ProdNSG}"
  location            = "${var.location}"
  resource_group_name = "${azurerm_resource_group.ProdNetworkRG.name}"

  security_rule {
    name                       = "AllowRDP"
    priority                   = 100
    direction                  = "Inbound"
    access                     = "Allow"
    protocol                   = "Tcp"
    source_port_range          = "*"
    destination_port_range     = "3389"
    source_address_prefix      = "*"
    destination_address_prefix = "*"
  }
}

resource "azurerm_virtual_network" "ProdVNet" {
  name          = "${var.ProdVNet}"
  resource_group_name = "${azurerm_resource_group.ProdNetworkRG.name}"
  address_space = "${var.ProdVNetAddressSpace}"
  location      = "${var.location}"


}

resource "azurerm_subnet" "ServersSubnet" {
  resource_group_name = "${azurerm_resource_group.ProdNetworkRG.name}"
  name = "${var.ServersSubnet}"
  address_prefix = "${var.ServersSubnetAddressPrefix}"
  virtual_network_name = "${azurerm_virtual_network.ProdVNet.name}"

}

resource "azurerm_subnet_network_security_group_association" "ServersNSGAssociation" {
  subnet_id                 = "${azurerm_subnet.ServersSubnet.id}"
  network_security_group_id = "${azurerm_network_security_group.ProdNSG.id}"
}

True/False condition works if I comment out the association, therefore I believe this is where it is stuck.

1

1 Answers

0
votes

If there are situations where the count for one resource might be zero, then in any other location where you refer to that resource you must tell Terraform how to handle the case where the other object doesn't exist.

In this case, it seems like you would not need the azurerm_subnet_network_security_group_association resource at all if the network security group doesn't exist, and so the easiest answer is to apply the same count to that other resource:

resource "azurerm_network_security_group" "ProdNSG" {
  count = var.DeployNSG ? 1 : 0

  # ...other arguments as you already have set...
}

resource "azurerm_subnet_network_security_group_association" "ServersNSGAssociation" {
  # Create one of this resource only if there is one of the other resource.
  count = length(azurerm_network_security_group.ProdNSG)

  subnet_id                 = azurerm_subnet.ServersSubnet.id
  network_security_group_id = azurerm_network_security_group.ProdNSG[count.index].id
}

Notice that we can now use count.index when referring to azurerm_network_security_group.ProdNSG, because azurerm_subnet_network_security_group_association.ServersNSGAssociation has the same count value as azurerm_network_security_group.ProdNSG. When one NSG exists, count.index will be 0 and thus it will select the first (and only) NSG instance. When no NSGs exist, no NSG attachments will exist either, and so count.index will never be evaluated.