Azure Bicep跨订阅引用现有资源(三元运算符)报错求助
Azure Bicep跨订阅引用现有Application Insights资源报错处理需求
在Azure Bicep文件中尝试根据输入参数,引用不同订阅、资源组中的现有Application Insights资源时,设置scope属性触发如下错误:
The resource namespace 'subscriptions' is invalid. (Code: InvalidResourceNamespace)
当前使用的相关代码:
param prefix string = '' @allowed([ 'dev' 'test' 'prod' ]) @description('Deployment environment type.') param deploymentEnvironment string var isProd = deploymentEnvironment == 'prod' var isTest = deploymentEnvironment == 'dev' var usingExistingAin = prefix == 'mrax' && (isProd || isTest) var prodOrTestlabNameTest = isProd ? 'appInsightsName1' : 'appInsightsName2' var subscriptionIdTest = usingExistingAin ? (isProd && usingExistingAin ? 'subscriptionID1' : 'subscriptionID2') : subscription().id resource applicationInsightsResource 'Microsoft.Insights/components@2020-02-02' existing = { name: usingExistingAin ? prodOrTestlabNameTest : appInsightsName scope: resourceGroup(subscriptionIdTest, rsgNameTest) }
注:isTest的条件设置是正确的
另外,由于权限限制,无法采用定义两个资源分支的方式(如下示例代码会触发授权错误),因此需要其他解决办法:
AuthorizationFailed","message":"The client 'clientId' with object id 'objectId' does not have authorization to perform action 'Microsoft.Insights/components/read' over scope '/subscriptions/subID/resourcegroups/resourceGroupName/providers/Microsoft.Insights/components/appInsightsName' or the scope is invalid. If access was recently granted, please refresh your credentials."
分支方式的示例代码:
param storageAccountName string param location string = resourceGroup().location @allowed([ 'new' 'existing' ]) param newOrExisting string = 'new' resource saNew 'Microsoft.Storage/storageAccounts@2023-04-01' = if (newOrExisting == 'new') { name: storageAccountName location: location sku: { name: 'Standard_LRS' } kind: 'StorageV2' } resource saExisting 'Microsoft.Storage/storageAccounts@2023-04-01' existing = if (newOrExisting == 'existing') { name: storageAccountName } output storageAccountId string = ((newOrExisting == 'new') ? saNew.id : saExisting.id)
内容的提问来源于stack exchange,提问作者kopolomo
相关产品推荐
相关产品推荐

