You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform中为azurerm_windows_function_app基于for_each动态生成ip_restriction优先级

解决azurerm_windows_function_app中通过for_each动态生成ip_restriction优先级的问题

你当前的配置里,第二个dynamic "ip_restriction"块使用了for_each但同时引用了count.index,这会触发Terraform错误——因为count和for_each不能在同一个块中混用,且使用for_each的块不存在count变量。以下是两种可行的修正方案:

方案1:基于子网列表的索引生成优先级

如果data.azurerm_subnet.lt-subnets是列表类型,可以用index函数获取每个子网在列表中的位置,以此计算唯一优先级:

resource "azurerm_windows_function_app" "win-func-app" {
  for_each            = var.func_app
  name                = each.key
  resource_group_name = var.rg1_name
  location            = var.ea2_location

  storage_account_name       = data.azurerm_storage_account.sa.name
  storage_account_access_key = data.azurerm_storage_account.sa.primary_access_key
  service_plan_id            = azurerm_service_plan.asp[each.value.asp].id

  site_config {
    ftps_state          = "FtpsOnly"
    minimum_tls_version = 1.2
    
    application_stack {
      dotnet_version = each.value.dotnet_version
    }
    
    ip_restriction_default_action = "Deny"
   
    dynamic "ip_restriction" {
      for_each = local.vpn
      content {
        ip_address = ip_restriction.value["ip_address"]
        action     = "Allow"
        priority   = ip_restriction.value["priority"]
        name       = ip_restriction.value["name"]
      }
    }
    dynamic "ip_restriction" {
      for_each = data.azurerm_subnet.lt-subnets
      content {
        name                     = ip_restriction.value.name
        virtual_network_subnet_id = ip_restriction.value.id
        # 从100开始递增,确保与vpn的优先级不冲突
        priority                 = format("%03d", index(data.azurerm_subnet.lt-subnets, ip_restriction.value) + 100)
      }
    }
  }

  identity {
    type = "SystemAssigned"
  }
}

方案2:基于子网映射的键生成优先级

如果data.azurerm_subnet.lt-subnets是映射类型(键值对),可以先获取所有键的列表,再通过键的索引计算优先级:

resource "azurerm_windows_function_app" "win-func-app" {
  for_each            = var.func_app
  name                = each.key
  resource_group_name = var.rg1_name
  location            = var.ea2_location

  storage_account_name       = data.azurerm_storage_account.sa.name
  storage_account_access_key = data.azurerm_storage_account.sa.primary_access_key
  service_plan_id            = azurerm_service_plan.asp[each.value.asp].id

  site_config {
    ftps_state          = "FtpsOnly"
    minimum_tls_version = 1.2
    
    application_stack {
      dotnet_version = each.value.dotnet_version
    }
    
    ip_restriction_default_action = "Deny"
   
    dynamic "ip_restriction" {
      for_each = local.vpn
      content {
        ip_address = ip_restriction.value["ip_address"]
        action     = "Allow"
        priority   = ip_restriction.value["priority"]
        name       = ip_restriction.value["name"]
      }
    }
    dynamic "ip_restriction" {
      for_each = data.azurerm_subnet.lt-subnets
      # 提前获取子网映射的键列表
      subnet_keys = keys(data.azurerm_subnet.lt-subnets)
      content {
        name                     = ip_restriction.value.name
        virtual_network_subnet_id = ip_restriction.value.id
        # 根据键在列表中的位置计算优先级
        priority                 = format("%03d", index(subnet_keys, ip_restriction.key) + 100)
      }
    }
  }

  identity {
    type = "SystemAssigned"
  }
}

注意事项

  • 确保优先级唯一:如果local.vpn中的优先级范围是1-99,子网的优先级从100开始递增可以避免冲突;如果需要更灵活的范围,可以根据实际情况调整起始值。
  • 格式化为三位数:format("%03d", ...)是为了保证优先级按数字顺序排序(Azure会按优先级数值从小到大匹配规则),如果不需要固定位数,可以直接使用数值(比如index(...) + 100)。

内容的提问来源于stack exchange,提问作者NickP

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 19:50:16