创建带DeployIfNoExists效果的Azure标签策略遇阻,求技术指导
实现DeployIfNoExists效果的Azure标签策略指导
需求概述
需要创建一个Azure Policy,通过DeployIfNoExists效果为新创建的资源自动添加特定标签Environment:Cloud,但修改内置Modify/DeployIfNoExists策略时反复报错,无法实现预期效果。
你尝试的策略代码
{ "mode": "Indexed", "policyRule": { "if": { "field": "[concat('tags[', parameters('tag_BuildBy'), ']')]", "exists": "false" }, "then": { "effect": "[parameters('effect')]", "details": { "type": "Microsoft.Resources/tags", "roleDefinitionIds": [ "/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c" ], "deployment": { "properties": { "mode": "incremental", "template": { "$schema": "http://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ { "type": "Microsoft.Resources/tags", "apiVersion": "2019-10-01", "name": "[concat(parameters('tagResourceId'))]", "properties": { "tags": { "[parameters('tag_BuildBy')]": "hello" } } } ] }, "parameters": { "tagResourceId": { "value": "[concat(resourceGroup().id, '/providers/Microsoft.Resources/tags/default')]" } } } } } } }, "parameters": { "effect": { "type": "String", "metadata": { "displayName": "Effect", "description": "Enable or disable the execution of the policy" }, "allowedValues": [ "DeployIfNotExists", "Disabled" ], "defaultValue": "DeployIfNotExists" }, "tag_BuildBy": { "type": "String", "metadata": { "displayName": "build", "description": "Enable or disable the execution of the policy" } } } }
问题分析与修正后的策略示例
当前代码存在几个关键问题:
- 目标标签是
Environment:Cloud,但代码参数化了无关标签且值不符需求 Microsoft.Resources/tags资源的名称格式错误,无需拼接资源ID- 部署模板未保留现有标签,会覆盖资源原有标签
以下是符合需求的修正版策略:
{ "mode": "Indexed", "policyRule": { "if": { "field": "tags['Environment']", "exists": "false" }, "then": { "effect": "[parameters('effect')]", "details": { "type": "Microsoft.Resources/tags", "roleDefinitionIds": [ "/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c" ], "deployment": { "properties": { "mode": "incremental", "template": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ { "type": "Microsoft.Resources/tags", "apiVersion": "2021-04-01", "name": "default", "properties": { "tags": "[union(resourceGroup().tags, createObject('Environment', 'Cloud'))]" } } ] } } } } } }, "parameters": { "effect": { "type": "String", "metadata": { "displayName": "效果", "description": "启用或禁用策略执行" }, "allowedValues": [ "DeployIfNotExists", "Disabled" ], "defaultValue": "DeployIfNotExists" } } }
关键说明
- 模式设置:
Indexed模式确保策略仅作用于支持标签的资源 - 条件判断:直接检查
Environment标签是否不存在,逻辑更简洁 - 标签处理:使用
union函数合并现有标签与新标签,避免覆盖原有标签 - API版本:采用较新的
2021-04-01版本API,提升兼容性 - 角色权限:
b24988ac-6180-42a0-ab88-20f7382dd24c是内置"资源策略参与者"角色,具备修改标签的必要权限
内容的提问来源于stack exchange,提问作者Quies
相关产品推荐
相关产品推荐

