Azure WAF自定义Terraform配置因match_variables块缺失报错求助
解决Azure WAF Terraform配置的匹配规则错误
错误原因
你遇到的两个错误本质是Terraform Azure WAF自定义规则的语法问题:
match_conditions块必须包含至少1个match_variables子块,不能直接使用match_variable属性- 不存在
match_variable这个属性,正确写法是在match_variables块内用variable_name指定要匹配的对象
修正后的配置代码
resource "azurerm_web_application_firewall_policy" "example" { name = "example-wafpolicy" resource_group_name = azurerm_resource_group.rg.name location = "Global" custom_rules { name = "MatchPublicKey" priority = 1 rule_type = "MatchRule" action = "Block" match_conditions { # 替换原错误的match_variable属性为match_variables块 match_variables { variable_name = "RequestBody" } operator = "RegexMatch" match_values = ["--BEGIN PUBLIC KEY---"] # 若不需要正则匹配,也可改用Contains运算符 # operator = "Contains" } } managed_rules { managed_rule_set { type = "AzureDefaultRuleSet" # 补充规则集类型,原代码缺失会触发额外错误 version = "1.1" } } }
关键修改点
- 在
match_conditions内新增match_variables块,通过variable_name指定要检查的请求体(RequestBody) - 删除原错误的
match_variable = "RequestBody"属性 - 补充
managed_rule_set的type字段,原代码仅指定version会导致Terraform报错
内容的提问来源于stack exchange,提问作者Saikumar
相关产品推荐
相关产品推荐

