You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

受Issue限制需用azurerm_virtual_machine,能否配置Trusted Launch?

使用azurerm_virtual_machine配置Trusted Launch的方案

不需要改用az_api,新版的azurerm provider已经在azurerm_virtual_machine资源中支持Trusted Launch配置,通过security_profile块即可实现,核心配置逻辑如下:

  • 在security_profile块内设置trusted_launch_enabled = true
  • 同时需启用Secure Boot和vTPM(Trusted Launch的必要组件),对应配置secure_boot_enabled = true和vtpm_enabled = true

示例配置片段:

resource "azurerm_virtual_machine" "example" {
  name                  = "example-vm"
  location              = azurerm_resource_group.example.location
  resource_group_name   = azurerm_resource_group.example.name
  network_interface_ids = [azurerm_network_interface.example.id]
  vm_size               = "Standard_D2s_v5"

  storage_image_reference {
    publisher = "MicrosoftWindowsServer"
    offer     = "WindowsServer"
    sku       = "2022-datacenter-g2"
    version   = "latest"
  }

  storage_os_disk {
    name              = "example-os-disk"
    caching           = "ReadWrite"
    create_option     = "FromImage"
    managed_disk_type = "Standard_LRS"
  }

  os_profile {
    computer_name  = "example-vm"
    admin_username = "adminuser"
    admin_password = "P@ssw0rd123!"
  }

  security_profile {
    trusted_launch_enabled = true
    secure_boot_enabled    = true
    vtpm_enabled           = true
  }
}

额外注意事项:

  • 需确保使用的azurerm provider版本在3.0及以上
  • 所选VM规格必须支持Trusted Launch(如Dv5、Ev5系列等)
  • 镜像本身需兼容Trusted Launch(例如Windows Server 2022 G2镜像、Ubuntu 22.04 LTS等)

若当前provider版本过低,建议优先升级到支持该特性的版本,无需切换到az_api资源。

内容的提问来源于stack exchange,提问作者Agyss

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 08:42:04