You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform AzAPI更新Key Vault密钥时遇类型错误求助

解决Terraform更新Azure Key Vault密钥的类型不匹配错误

问题根源在于azapi_update_resource资源的body参数处理:该字段接受原生HCL对象,不需要用jsonencode()转换为字符串。你当前用jsonencode()把HCL对象转成了JSON字符串,导致Terraform检测到类型不匹配,抛出"The value must not be a string"错误。

修正后的配置代码:

resource "azapi_update_resource" "keyvault_secret_update_function_app_id" {
  type                   = "Microsoft.KeyVault/vaults/secrets@2022-07-01"
  resource_id            = "/subscriptions/myguid/resourceGroups/resource-group-name/providers/Microsoft.KeyVault/vaults/ali-test-remotely-kv-dev/secrets/remotely-managed"
  response_export_values = ["*"]
  body = {
    properties = {
      value = "test value"
    }
  }
}

直接移除jsonencode()包裹,让body使用原生HCL对象结构即可解决类型错误。另外需确保Terraform执行账号在目标Key Vault的访问策略中拥有secrets/set权限,避免后续出现权限相关问题。

内容的提问来源于stack exchange,提问作者Ali

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 12:59:51