You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform部署Azure资源时订阅ID错误的问题排查

问题描述

我正在学习Terraform,尝试在Azure中创建Kubernetes集群(AKS)和容器注册表(ACR),并为AKS配置ACR的拉取权限。已手动创建带有自定义角色的服务主体,该角色包含所有Contributor权限及以下额外权限:

Microsoft.Authorization/roleAssignments/read
Microsoft.Authorization/roleAssignments/write
Microsoft.Authorization/roleAssignments/delete
Microsoft.ContainerService/managedClusters/read
Microsoft.ContainerService/managedClusters/write
Microsoft.ContainerService/managedClusters/delete

已按Terraform Azure教程完成认证并正确设置环境变量,但执行terraform apply部署以下配置文件时:

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "~> 3.104.2"
    }
  }

  required_version = ">= 1.1.0"
}

provider "azurerm" {
  features {

  }
}

resource "azurerm_resource_group" "rg" {
  name     = "myRG"
  location = "North Europe"
}

resource "azurerm_container_registry" "acr" {
  name                = "mycr"
  resource_group_name = azurerm_resource_group.rg.name
  location            = azurerm_resource_group.rg.location
  sku                 = "Basic"
}

resource "azurerm_kubernetes_cluster" "aks" {
  name                = "myAKS"
  location            = azurerm_resource_group.rg.location
  resource_group_name = azurerm_resource_group.rg.name
  dns_prefix          = "myAKS"

  default_node_pool {
    name       = "default"
    node_count = 1
    vm_size    = "Standard_D2_v2"
  }

  identity {
    type = "SystemAssigned"
  }
}

# Attach the container registry to the kubernetes cluster
resource "azurerm_role_assignment" "aksPullFromAcr" {
  principal_id         = azurerm_kubernetes_cluster.aks.kubelet_identity[0].object_id
  role_definition_name = "AcrPull"
  scope                = azurerm_container_registry.acr.id
}

出现如下错误,且错误信息中指向了错误的订阅ID:

Error: retrieving Kubernetes Cluster (Subscription: "<wrong_subscription_id>"
│ Resource Group Name: "myRG"
│ Kubernetes Cluster Name: "myAKS"): unexpected status 403 (403 Forbidden) with error: AuthorizationFailed: The client '<client_id>' with object id '<client_id>' does not have authorization to perform action 'Microsoft.ContainerService/managedClusters/read' over scope '/subscriptions/<wrong_subscription_id>/resourceGroups/myRG/providers/Microsoft.ContainerService/managedClusters/myAKS' or the scope is invalid. If access was recently granted, please refresh your credentials.

已尝试重新创建服务主体,但问题仍未解决,请问哪里操作有误?

问题排查与解决

从错误信息里的错误订阅ID可以看出,核心问题是Terraform使用的订阅上下文和你预期的不一致,以下是具体排查和解决步骤:

  • 检查环境变量中的订阅ID
    确认你设置的ARM_SUBSCRIPTION_ID环境变量是否为目标订阅的正确ID,错误的订阅ID会导致Terraform尝试访问不属于当前服务主体权限范围的订阅资源。

  • 验证Azure CLI的当前订阅上下文
    如果你是通过Azure CLI认证Terraform(即使设置了环境变量,CLI上下文可能会覆盖),执行以下命令检查并切换到正确订阅:

    az account show
    az account set --subscription <correct_subscription_id>
    

    之后重新执行terraform apply,确保Terraform使用的是正确的订阅上下文。

  • 在Terraform Provider中显式指定订阅ID
    为了避免环境变量或CLI上下文的干扰,直接在azurerm provider块中指定目标订阅ID:

    provider "azurerm" {
      features {}
      subscription_id = "<correct_subscription_id>"
    }
    

    这样可以强制Terraform使用指定的订阅,避免上下文混淆。

  • 检查服务主体的订阅权限范围
    确认你创建的服务主体是在目标订阅下创建的,并且自定义角色是绑定到该目标订阅(或对应的资源组)上的。如果服务主体属于其他订阅,即使权限足够,也无法访问目标订阅的资源。

  • 清除Terraform状态文件(谨慎操作)
    如果之前的错误订阅信息已经写入Terraform状态文件,可能会导致后续操作持续出错。可以先执行terraform destroy(如果资源已部分创建),然后删除.terraform目录和terraform.tfstate文件,重新初始化后再部署。

内容的提问来源于stack exchange,提问作者Norse

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 07:45:10