如何在资源作用域配置azurerm_role_management_policy?
资源级别配置Azure RM角色管理策略的作用域问题解决
问题背景
已搭建Terraform模块分别在订阅、资源组、资源三个级别管理权限作用域,前两个级别运行正常,但在资源级别配置azurerm_role_management_policy时,出现作用域解析错误。
配置代码
resource "azurerm_role_management_policy" "role_policy_resource" { for_each = toset(var.role_definition_names) scope = data.azurerm_key_vault.statickv.id # Scope of the role management policy role_definition_id = data.azurerm_role_definition.roles[each.value].id # ID of the role definition active_assignment_rules { expire_after = var.role_policy_rules.active_assignment_rules_expire_after # Expiration period for active assignments } eligible_assignment_rules { expiration_required = false # Whether expiration is required for eligible assignments } activation_rules { maximum_duration = var.role_policy_rules.activation_rules_maximum_duration # Maximum duration for activation require_approval = var.role_policy_rules.activation_rules_require_approval # Whether approval is required for activation dynamic "approval_stage" { for_each = var.role_policy_rules.activation_rules_require_approval ? ["this"] : [] content{ primary_approver { object_id = var.role_policy_rules.activation_rules_approver_object_id # Primary approver for activation type = var.role_policy_rules.activation_rules_approver_type # Type of the primary approver } } } } notification_rules { eligible_assignments { admin_notifications { notification_level = var.role_policy_rules.notification_rules_eligible_assignments_admin_notifications_notification_level # Notification level for admin notifications default_recipients = var.role_policy_rules.notification_rules_eligible_assignments_admin_notifications_default_recipients # Whether to use default recipients for admin notifications additional_recipients = var.role_policy_rules.notification_rules_eligible_assignments_admin_notifications_additional_recipients # Additional recipients for admin notifications } approver_notifications { notification_level = var.role_policy_rules.notification_rules_eligible_assignments_approver_notifications_notification_level # Notification level for approver notifications default_recipients = var.role_policy_rules.notification_rules_eligible_assignments_approver_notifications_default_recipients # Whether to use default recipients for approver notifications additional_recipients = var.role_policy_rules.notification_rules_eligible_assignments_approver_notifications_additional_recipients # Additional recipients for approver notifications } assignee_notifications { notification_level = var.role_policy_rules.notification_rules_eligible_assignments_assignee_notifications_notification_level # Notification level for assignee notifications default_recipients = var.role_policy_rules.notification_rules_eligible_assignments_assignee_notifications_default_recipients # Whether to use default recipients for assignee notifications additional_recipients = var.role_policy_rules.notification_rules_eligible_assignments_assignee_notifications_additional_recipients } } eligible_activations { admin_notifications { notification_level = var.role_policy_rules.notification_rules_eligible_activations_admin_notifications_notification_level # Notification level for assignee notifications default_recipients = var.role_policy_rules.notification_rules_eligible_activations_admin_notifications_default_recipients # Whether to use default recipients for assignee notifications additional_recipients = var.role_policy_rules.notification_rules_eligible_activations_admin_notifications_additional_recipients } assignee_notifications { notification_level = var.role_policy_rules.notification_rules_eligible_activations_assignee_notifications_notification_level # Notification level for assignee notifications default_recipients = var.role_policy_rules.notification_rules_eligible_activations_assignee_notifications_default_recipients # Whether to use default recipients for assignee notifications additional_recipients = var.role_policy_rules.notification_rules_eligible_activations_assignee_notifications_additional_recipients } } active_assignments { admin_notifications { notification_level = var.role_policy_rules.notification_rules_active_assignments_admin_notifications_notification_level # Notification level for assignee notifications default_recipients = var.role_policy_rules.notification_rules_active_assignments_admin_notifications_default_recipients # Whether to use default recipients for assignee notifications additional_recipients = var.role_policy_rules.notification_rules_active_assignments_admin_notifications_additional_recipients } approver_notifications { notification_level = var.role_policy_rules.notification_rules_active_assignments_approver_notifications_notification_level # Notification level for assignee notifications default_recipients = var.role_policy_rules.notification_rules_active_assignments_approver_notifications_default_recipients # Whether to use default recipients for assignee notifications additional_recipients = var.role_policy_rules.notification_rules_active_assignments_approver_notifications_additional_recipients } assignee_notifications { notification_level = var.role_policy_rules.notification_rules_active_assignments_assignee_notifications_notification_level # Notification level for assignee notifications default_recipients = var.role_policy_rules.notification_rules_active_assignments_assignee_notifications_default_recipients # Whether to use default recipients for assignee notifications additional_recipients = var.role_policy_rules.notification_rules_active_assignments_assignee_notifications_additional_recipients } } } timeouts { create = "10m" delete = "10m" } }
报错信息
Error: parsing "/subscriptions/XXXXX-1081-4bff-9256-9feda89161f1/resourceGroups/XXXX-static-rg/providers/Microsoft.KeyVault/vaults/XXXX-static-kv": parsing segment "providers": parsing the ManagementGroup ID: the segment at position 0 didn't match │ │ Expected a ManagementGroup ID that matched: │ │ > /providers/Microsoft.Management/managementGroups/groupIdValue │ │ However this value was provided: │ │ > /subscriptions/XXXXX-1081-4bff-9256-9feda89161f1/resourceGroups/XXXX-static-rg/providers/Microsoft.KeyVault/vaults/XXXX-static-kv │ │ The parsed Resource ID was missing a value for the segment at position 0 │ (which should be the literal value "providers"). │ │ │ │ with module.pim-assignment-re.azurerm_role_management_policy.role_policy_resource["Contributor"], │ on pim-assignment-re\role_policy_rule.tf line 6, in resource "azurerm_role_management_policy" "role_policy_resource": │ 6: scope = data.azurerm_key_vault.statickv.id # Scope of the role management policy │ ╵ ╷ │ Error: parsing "/subscriptions/XXXXX-1081-4bff-9256-9feda89161f1/resourceGroups/XXXX-static-rg/providers/Microsoft.KeyVault/vaults/XXXX-static-kv": unexpected segment "providers/Microsoft.KeyVault/vaults/XXXX-static-kv" present at the end of the URI (input "/subscriptions/XXXXX-1081-4bff-9256-9feda89161f1/resourceGroups/XXXX-static-rg/providers/Microsoft.KeyVault/vaults/XXXX-static-kv") │ │ with module.pim-assignment-re.azurerm_role_management_policy.role_policy_resource["Contributor"], │ on pim-assignment-re\role_policy_rule.tf line 6, in resource "azurerm_role_management_policy" "role_policy_resource": │ 6: scope = data.azurerm_key_vault.statickv.id # Scope of the role management policy │ ╵ ╷ │ Error: parsing "/subscriptions/XXXXX-1081-4bff-9256-9feda89161f1/resourceGroups/XXXX-static-rg/providers/Microsoft.KeyVault/vaults/XXXX-static-kv": unexpected segment "resourceGroups/XXXX-static-rg/providers/Microsoft.KeyVault/vaults/XXXX-static-kv" present at the end of the URI (input "/subscriptions/XXXXX-1081-4bff-9256-9feda89161f1/resourceGroups/XXXX-static-rg/providers/Microsoft.KeyVault/vaults/XXXX-static-kv") │ │ with module.pim-assignment-re.azurerm_role_management_policy.role_policy_resource["Contributor"], │ on pim-assignment-re\role_policy_rule.tf line 6, in resource "azurerm_role_management_policy" "role_policy_resource": │ 6: scope = data.azurerm_key_vault.statickv.id # Scope of the role management policy
解决方法
问题根源
azurerm_role_management_policy的scope参数在资源级别配置时,不能直接使用资源ID,必须指向该资源下的Microsoft.Authorization provider端点,这是Azure角色管理策略(PIM配置)的要求,只有这样Terraform才能正确解析作用域并关联到资源级别的权限管理。
修改配置
将scope字段修改为资源ID拼接/providers/Microsoft.Authorization:
resource "azurerm_role_management_policy" "role_policy_resource" { for_each = toset(var.role_definition_names) # 修改此处的scope值 scope = "${data.azurerm_key_vault.statickv.id}/providers/Microsoft.Authorization" role_definition_id = data.azurerm_role_definition.roles[each.value].id # 其余配置保持不变... }
或者使用Terraform的字符串拼接函数提高可读性:
scope = join("/", [data.azurerm_key_vault.statickv.id, "providers/Microsoft.Authorization"])
验证逻辑
修改后,作用域将变为类似:/subscriptions/XXXXX-1081-4bff-9256-9feda89161f1/resourceGroups/XXXX-static-rg/providers/Microsoft.KeyVault/vaults/XXXX-static-kv/providers/Microsoft.Authorization
这个格式符合Azure对资源级别角色管理策略的作用域要求,Terraform可以正确解析并创建对应的策略。
内容的提问来源于stack exchange,提问作者ankur kapoor
相关产品推荐
相关产品推荐

