使用Terraform管理Azure订阅策略分配遇资源类型错误求助
问题
尝试通过Terraform管理Azure订阅的策略分配,执行terraform plan时出现错误,提示hashicorp/azurerm provider不支持azurerm_policy_assignment资源类型,建议使用data块代替resource块。
相关代码(policy.tf)
provider "azurerm" { features {} subscription_id = "00000000-a0b0-0000-0a00-0f000000000" } resource "azurerm_policy_definition" "vm_sku_policy" { name = "OnlyAllowHostingCROSImages" policy_type = "Custom" mode = "All" display_name = "Limit allowed VM SKUs" description = "This policy restricts the VM SKUs that can be deployed in the subscription." policy_rule = <<POLICY_RULE { "if": { "allOf": [ { "field": "type", "in": [ "Microsoft.Compute/virtualMachines", "Microsoft.Compute/virtualMachineScaleSets" ] }, { "not": { "anyOf": [ { "field": "Microsoft.Compute/imageSku", "like": "*-Datacenter-gs" }, { "field": "Microsoft.Compute/imageSku", "like": "2022-Datacenter*" }, { "allOf": [ { "field": "Microsoft.Compute/imagePublisher", "equals": "Canonical" }, { "field": "Microsoft.Compute/imageOffer", "in": [ "0001-com-ubuntu-server-focal", "0001-com-ubuntu-server-jammy", "UbuntuServer" ] }, { "field": "Microsoft.Compute/imageSku", "in": [ "20_04-lts-gen2", "20_04-lts-cvm", "22_04-lts-cvm", "20_04-lts", "22_04-lts" ] } ] } ] } } ] }, "then": { "effect": "deny" } } POLICY_RULE } resource "azurerm_resource_group" "vm_sku_policy" { name = "test-resources" location = "West Europe" } resource "azurerm_policy_assignment" "vm_sku_policy" { name = "limit-vm-sku-assignment" policy_definition_id = azurerm_policy_definition.vm_sku_policy.id scope = "/subscriptions/00000000-a0b0-0000-0a00-0f000000000" display_name = azurerm_policy_definition.vm_sku_policy.display_name description = azurerm_policy_definition.vm_sku_policy.description }
错误信息
PS C:\WindowsFabric\policy> terraform plan ╷ │ Error: Invalid resource type │ │ on amir.tf line 105, in resource "azurerm_policy_assignment" "vm_sku_policy": │ 105: resource "azurerm_policy_assignment" "vm_sku_policy" { │ │ The provider hashicorp/azurerm does not support resource type "azurerm_policy_assignment". │ │ Did you intend to use the data source "azurerm_policy_assignment"? If so, declare this using a "data" block instead of a "resource" block.
解决方案
这个错误是因为Azurerm Provider v3.0及以上版本对策略分配资源做了拆分,原有的azurerm_policy_assignment已被废弃,需要根据策略分配的作用域选择对应的资源类型:
- 订阅级分配:使用
azurerm_subscription_policy_assignment - 资源组级分配:使用
azurerm_resource_group_policy_assignment - 管理组级分配:使用
azurerm_management_group_policy_assignment
针对你的订阅级策略分配场景,只需将原azurerm_policy_assignment资源替换为azurerm_subscription_policy_assignment即可,修改后的代码如下:
resource "azurerm_subscription_policy_assignment" "vm_sku_policy" { name = "limit-vm-sku-assignment" policy_definition_id = azurerm_policy_definition.vm_sku_policy.id scope = "/subscriptions/00000000-a0b0-0000-0a00-0f000000000" display_name = azurerm_policy_definition.vm_sku_policy.display_name description = azurerm_policy_definition.vm_sku_policy.description }
如果代码中未指定Provider版本,建议在versions.tf中明确指定v3.0及以上版本:
terraform { required_providers { azurerm = { source = "hashicorp/azurerm" version = "~> 3.0" } } }
内容的提问来源于stack exchange,提问作者Node.JS
相关产品推荐
相关产品推荐

