You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何正确编写azurerm_virtual_machine_extension的settings块?

问题:Azure Monitor Linux Agent扩展状态异常无法连接Log Analytics Workspace

背景

我们在Azure中托管的VM需要使用「AzureMonitorLinuxAgent」虚拟机扩展,采用Terraform模板搭建基础设施及VM,已配置VM基础参数(如名称、virtual_machine_id等)和settings块,并为VM添加了该扩展。

预期结果

该扩展应处于Plugin enabled状态(与门户安装的扩展状态一致)。

当前问题

扩展状态始终为Enable succeeded(在Azure门户VM的「设置->扩展+应用程序」中查看),未达到预期的「Plugin enabled」状态,且无法连接Log Analytics Workspace,未收到该机器的数据。需要确认扩展的settings块是否需要调整,以及如何正确编写该settings块。

资源模板代码

resource "azurerm_virtual_machine_extension" "monitor_agent" {
  name                       = "AzureMonitorLinuxAgent"
  virtual_machine_id         = azurerm_linux_virtual_machine.monitorsimple.id
  publisher                  = "Microsoft.Azure.Monitor"
  type                       = "AzureMonitorLinuxAgent"
  type_handler_version       = "1.33"
  auto_upgrade_minor_version = false
  settings = jsonencode({
    azureMonitorConfiguration = {
      workspaceId               = azurerm_log_analytics_workspace.monitorsimple.id
      azureResourceId           = azurerm_linux_virtual_machine.monitorsimple.id
      stopOnMultipleConnections = false
      authentication = {
        managedIdentity = {
          identifier-name  = "mi_res_id"
          identifier-value = azurerm_user_assigned_identity.monitorsimple.id
        }
      }
    }
  })
  
  protected_settings = jsonencode({
    "workspaceKey" = azurerm_log_analytics_workspace.monitorsimple.primary_shared_key
  })
}

已尝试操作

  • 查阅Microsoft官方代理源代码
  • 修改type_handler_version至旧版本(如1.6)及其他版本
  • 将模板与Azure门户安装扩展生成的资源JSON(创建DCR)进行对比
  • 按论坛建议等待约10分钟并多次重启VM

问题分析与修正方案

核心问题点

  1. 身份认证冲突:同时配置托管身份认证和workspaceKey,导致扩展无法正确识别认证方式,无法完成插件启用流程。
  2. workspaceId格式错误:Log Analytics Workspace的ID应使用其客户ID(Customer ID),而非Terraform返回的资源路径ID。
  3. settings结构冗余:Azure Monitor Linux Agent的settings无需嵌套azureMonitorConfiguration,直接使用顶层配置即可。

修正后的Terraform代码

resource "azurerm_virtual_machine_extension" "monitor_agent" {
  name                       = "AzureMonitorLinuxAgent"
  virtual_machine_id         = azurerm_linux_virtual_machine.monitorsimple.id
  publisher                  = "Microsoft.Azure.Monitor"
  type                       = "AzureMonitorLinuxAgent"
  type_handler_version       = "1.33"
  auto_upgrade_minor_version = true # 建议开启自动升级小版本,避免兼容性问题

  settings = jsonencode({
    workspaceId               = azurerm_log_analytics_workspace.monitorsimple.workspace_id # 使用客户ID而非资源ID
    azureResourceId           = azurerm_linux_virtual_machine.monitorsimple.id
    stopOnMultipleConnections = false
    authentication = {
      managedIdentity = {
        identifier-name  = "mi_res_id"
        identifier-value = azurerm_user_assigned_identity.monitorsimple.id
      }
    }
  })

  # 移除protected_settings,托管身份认证无需workspaceKey
}

额外注意事项

  • 托管身份权限配置:确保用户分配的托管身份拥有Log Analytics Workspace的Log Analytics Contributor或Monitoring Metrics Publisher权限,否则无法完成数据上报。
  • DCR关联:Azure Monitor Agent需要通过数据收集规则(DCR)定义收集规则,需创建DCR并通过azurerm_monitor_data_collection_rule_association资源将VM与DCR关联,否则即使扩展状态正常,也不会有数据流入Workspace。
  • 状态验证:重新部署后等待5-10分钟,可通过Azure CLI命令az vm extension show --resource-group <资源组名> --vm-name <VM名> --name AzureMonitorLinuxAgent查看详细状态,确认status.message显示插件已启用。

内容的提问来源于stack exchange,提问作者rdsmgo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 09:22:08