Azure Policy检测AKS中Keyvault驱动时报错:属性不存在求助
自定义Azure Policy检测AKS Keyvault Driver报错排查
问题背景
开发自定义Azure Policy用于检测AKS集群是否已安装Azure Keyvault Secrets Provider驱动,编写的策略执行时始终报错,提示Microsoft.ContainerService资源中不存在azureKeyvaultSecretsProvider属性,但已确认测试AKS资源的JSON结构中包含该属性。
错误原因
策略中嵌套属性的字段路径写法错误。使用field运算符时,不需要重复资源类型前缀Microsoft.ContainerService/ManagedClusters/,直接从嵌套属性层级开始即可。原策略中重复添加了资源类型前缀,导致Azure Policy无法正确识别属性路径。
修正后的策略代码
{ "mode": "All", "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.ContainerService/ManagedClusters" }, { "field": "addonProfiles/azureKeyvaultSecretsProvider", "exists": true }, { "field": "addonProfiles/azureKeyvaultSecretsProvider/enabled", "equals": true } ] }, "then": { "effect": "[parameters('effect')]" } }, "parameters": { "effect": { "type": "String", "metadata": { "displayName": "Effect", "description": "Deny, Audit or Disabled the execution of the Policy", "portalReview": true }, "allowedValues": [ "AuditIfNotExists", "Audit", "Disabled" ], "defaultValue": "Audit" } } }
关键说明
- 字段路径简化:删除了嵌套属性前重复的
Microsoft.ContainerService/ManagedClusters/前缀,确保Policy能正确定位到addonProfiles下的目标属性。 - 逻辑保持一致:仍保留原有的三个验证条件:资源类型为AKS集群、
azureKeyvaultSecretsProvider扩展存在、扩展处于启用状态。 - 效果调整建议:如果实际需求是审计未安装该驱动的AKS集群,建议将默认效果改为
AuditIfNotExists,并调整策略逻辑结构以匹配该效果的要求(需在details中定义目标资源检查)。
内容的提问来源于stack exchange,提问作者Héctor Torres-Calderón
相关产品推荐
相关产品推荐

